Get in Touch

Course Outline

Fundamentals of VPN Sovereignty

  • Reasons commercial VPNs log metadata and comply with legal requests.
  • OpenVPN: a mature, feature-rich protocol offering TAP/TUN flexibility.
  • WireGuard: a modern, minimal protocol with high-performance cryptography.
  • Selecting the appropriate protocol based on your threat model.

OpenVPN Deployment for Government

  • Installing OpenVPN using Easy-RSA PKI.
  • Configuring the server: cipher, HMAC, TLS-authentication, and topology settings.
  • Generating and distributing client configurations.
  • Managing revocation and CRL (Certificate Revocation List).

WireGuard Deployment for Government

  • Installing the kernel module and WireGuard-tools.
  • Generating keys and configuring peers.
  • Using wg-quick and systemd unit management.
  • Configuring road warrior and site-to-site mesh topologies.

Authentication and Authorization for Government

  • Certificate-based authentication with OpenVPN.
  • Integrating LDAP and RADIUS backends.
  • Implementing two-factor authentication using TOTP plugins.
  • Configuring access control lists and per-user IP allocation.

Routing and Network Design for Government

  • Full tunnel versus split tunnel routing.
  • Pushing routes, DNS, and WINS configurations.
  • Configuring NAT and masquerading for egress traffic.
  • Multi-WAN and policy-based routing strategies.

Performance and Scaling for Government

  • Comparing WireGuard and OpenVPN throughput benchmarks.
  • Optimizing multi-core performance and kernel bypass techniques.
  • Implementing load balancing across multiple VPN servers.
  • DDoS protection and connection rate limiting measures.

Monitoring and Maintenance for Government

  • Connection logging and bandwidth accounting practices.
  • Integrating syslog and Prometheus exporter for monitoring.
  • Automating certificate renewal and expiration alerts.
  • Developing disaster recovery plans and configuration backups.

Requirements

  • Intermediate knowledge of Linux networking and firewall administration.
  • Understanding of Public Key Infrastructure (PKI), certificates, and encryption protocols.
  • Familiarity with routing, Network Address Translation (NAT), and IP forwarding.

Audience

  • Network administrators transitioning from commercial VPN services to more secure solutions for government operations.
  • Remote work teams requiring sovereign and secure access to internal resources.
  • Organizations operating in regions with restrictions or surveillance on VPN usage.
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories