Get in Touch

Course Outline

Foundations of VPN Sovereignty for Government

  • Examining why commercial providers retain metadata and respond to legal compulsion.
  • OpenVPN: A mature, comprehensive solution with TAP/TUN flexibility.
  • WireGuard: A modern, streamlined approach leveraging high-performance cryptography.
  • Selecting the appropriate protocol based on specific threat models.

OpenVPN Implementation

  • Installing OpenVPN with Easy-RSA public key infrastructure.
  • Configuring server parameters: cipher, HMAC, TLS-auth, and topology.
  • Generating and distributing client configurations.
  • Managing certificate revocation and CRL updates.

WireGuard Implementation

  • Installing kernel modules and WireGuard tools.
  • Generating keys and configuring peer connections.
  • Managing wg-quick and systemd service units.
  • Implementing road warrior and site-to-site mesh topologies.

Authentication and Authorization

  • Implementing certificate-based authentication with OpenVPN.
  • Integrating LDAP and RADIUS backend services.
  • Enabling two-factor authentication using TOTP plugins.
  • Defining access control lists and allocating per-user IPs.

Routing and Network Architecture

  • Comparing full tunnel versus split tunnel routing strategies.
  • Configuring push routes, DNS, and WINS settings.
  • Implementing NAT and masquerading for egress traffic.
  • Designing multi-WAN and policy-based routing solutions.

Performance and Scalability

  • Comparing WireGuard and OpenVPN throughput benchmarks.
  • Optimizing multi-core performance and kernel bypass techniques.
  • Load balancing across multiple VPN servers.
  • Implementing DDoS protection and connection rate limiting.

Monitoring and Maintenance

  • Recording connection logs and tracking bandwidth usage.
  • Integrating Syslog and Prometheus exporters.
  • Automating certificate renewal and expiration alerts.
  • Establishing disaster recovery and configuration backup protocols.

Requirements

  • Intermediate knowledge of Linux networking and firewall administration.
  • Proficiency with public key infrastructure, certificates, and encryption protocols.
  • Familiarity with routing, NAT, and IP forwarding mechanisms.

Target Audience

  • Network administrators transitioning from commercial VPN services.
  • Remote work teams requiring sovereign secure access.
  • Organizations operating in regions with restricted or monitored connectivity.
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories