Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Fundamentals of VPN Sovereignty
- Why commercial VPNs log metadata and comply with legal requests.
- OpenVPN: mature, feature-rich, offering TAP/TUN flexibility.
- WireGuard: modern, minimal design, with high-performance cryptography.
- Selecting the appropriate protocol for your specific threat model.
OpenVPN Deployment
- Installing OpenVPN using Easy-RSA PKI.
- Server configuration: cipher, HMAC, TLS-auth, and topology.
- Generating and distributing client configurations.
- Managing revocation and CRL.
WireGuard Deployment
- Installing the kernel module and WireGuard-tools.
- Key generation and peer configuration.
- Utilizing wg-quick and systemd unit management.
- Implementing road warrior and site-to-site mesh topologies.
Authentication and Authorization
- Certificate-based authentication with OpenVPN.
- Integration of LDAP and RADIUS backends.
- Two-factor authentication via TOTP plugins.
- Access control lists and per-user IP allocation.
Routing and Network Design
- Differentiating between full tunnel and split tunnel routing.
- Configuring push routes, DNS, and WINS.
- Implementing NAT and masquerading for egress traffic.
- Setting up Multi-WAN and policy-based routing.
Performance and Scaling
- Benchmarking throughput of WireGuard versus OpenVPN.
- Optimizing multi-core performance and kernel bypass.
- Load balancing across multiple VPN servers.
- Implementing DDoS protection and connection rate limiting.
Monitoring and Maintenance
- Logging connections and accounting for bandwidth usage.
- Integrating Syslog and Prometheus exporters.
- Automating certificate renewal and expiration alerts.
- Planning for disaster recovery and configuration backups.
Requirements
- Intermediate knowledge of Linux networking and firewall administration.
- Understanding of PKI, certificates, and encryption protocols.
- Familiarity with routing, NAT, and IP forwarding.
Audience
- Network administrators replacing commercial VPN services.
- Remote work teams requiring sovereign and secure access.
- Organizations operating in regions subject to VPN blocking or surveillance.
14 Hours