Get in Touch

Course Outline

Vpn Sovereignty Fundamentals

  • Analysis of commercial vpn logging practices, metadata retention, and compliance with legal directives.
  • Evaluation of openvpn: an established protocol offering comprehensive features and tun/tap interface flexibility.
  • Assessment of wireguard: a contemporary framework characterized by minimalism and efficient cryptographic performance.
  • Protocol selection criteria aligned with specific threat models and security requirements for government use.

Openvpn Deployment

  • Implementation of openvpn utilizing easy-rsa for public key infrastructure management.
  • Server-side configuration parameters including encryption ciphers, hmac integrity checks, tls authentication, and network topology settings.
  • Generation and secure distribution of client-specific configuration files.
  • Procedures for credential revocation and certificate revocation list management.

Wireguard Deployment

  • Installation of kernel modules and wireguard utilities.
  • Generation of cryptographic keys and peer-to-peer configuration.
  • Management of network interfaces via wg-quick and systemd service units.
  • Deployment scenarios including remote access ("road warrior") and site-to-site mesh architectures.

Authentication and Authorization

  • Identity verification using digital certificates within openvpn environments.
  • Integration with ldap and radius directories for centralized identity management.
  • Implementation of two-factor authentication mechanisms using time-based one-time password plugins.
  • Configuration of access control lists and assignment of ip addresses on a per-user basis.

Routing and Network Design

  • Comparison of full tunnel versus split tunnel routing strategies.
  • Configuration of pushed routes, dns servers, and wins settings for client devices.
  • Implementation of network address translation and masquerading for outbound traffic.
  • Deployment of multi-wan configurations and policy-based routing mechanisms.

Performance and Scaling

  • Benchmarking throughput capabilities comparing wireguard to openvpn.
  • Optimization techniques for multi-core processors and kernel-level bypass implementations.
  • Distribution of traffic load across multiple vpn gateway servers.
  • Mitigation strategies including distributed denial-of-service protection and connection rate limiting.

Monitoring and Maintenance

  • Logging of session connections and accounting of bandwidth usage.
  • Integration with syslog services and prometheus exporters for metrics collection.
  • Automation of certificate renewal processes and monitoring for expiration events.
  • Development of disaster recovery plans and regular backup procedures for system configurations.

Requirements

  • Proficiency in intermediate Linux networking configurations and firewall management.
  • Comprehensive knowledge of Public Key Infrastructure (PKI), digital certificates, and encryption standards.
  • Familiarity with routing protocols, Network Address Translation (NAT), and IP forwarding mechanisms.

Intended Audience

  • Network administrators transitioning from commercial VPN solutions to in-house infrastructure.
  • Remote workforce units requiring sovereign-compliant and secure access channels for government operations.
  • Institutions operating within jurisdictions characterized by restrictive internet policies or surveillance requirements, seeking robust connectivity options tailored for government use.
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories