What's new

Need advice on VPN routers

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

I found an open source vpn server that runs on Windows and does IPSec and L2TP. https://www.softether.org/

That should work fine for my needs. If I add more cameras in the future, I'll consider buying a purpose built device.

I never tested it personally, but what I've read about Softether sounded positive.
 
Interesting - some very bad advice though on their WWW site...

"You can setup your own VPN server behind the firewall or NAT in your company, and you can reach to that VPN server in the corporate private network from your home or mobile place, without any modification of firewall settings. Any deep-packet inspection firewalls cannot detect SoftEther VPN's transport packets as a VPN tunnel, because SoftEther VPN uses Ethernet over HTTPS for camouflage."
If you believe that, then you do deserve to lose your job... unauthorized and/or undocumented encrypted pipes these days are totally observed considering all the high profile data exfiltrations... and Deep Packet Inspection is the norm these days, not the exception on Corporate Firewalls...
 
Interesting - some very bad advice though on their WWW site...

"You can setup your own VPN server behind the firewall or NAT in your company, and you can reach to that VPN server in the corporate private network from your home or mobile place, without any modification of firewall settings. Any deep-packet inspection firewalls cannot detect SoftEther VPN's transport packets as a VPN tunnel, because SoftEther VPN uses Ethernet over HTTPS for camouflage."
If you believe that, then you do deserve to lose your job... unauthorized and/or undocumented encrypted pipes these days are totally observed considering all the high profile data exfiltrations... and Deep Packet Inspection is the norm these days, not the exception on Corporate Firewalls...
I read that and thought, really? Of course it wouldn't apply to what I'm doing, but I'd be interested to read the technical details that proves that their claims are true.
 
I read that and thought, really? Of course it wouldn't apply to what I'm doing, but I'd be interested to read the technical details that proves that their claims are true.

that is not a tech issue - it's a business policy issue - and this is what get's folks in trouble, lol...
 
that is not a tech issue - it's a business policy issue - and this is what get's folks in trouble, lol...
Well, of course, but I'd like to know how they can get around NAT and a firewall without the security guys knowing about it. I doubt you could have done that where I worked and gone undetected.
 
Well, of course, but I'd like to know how they can get around NAT and a firewall without the security guys knowing about it. I doubt you could have done that where I worked and gone undetected.

Behind a firewall - they still need a network admin to open a port, perhaps - if I read their docs correctly... and then it's also a discussion about the need there...
 
You should just check places that clear out and close out stuff. Sometimes you'll find $500 pieces of equipment for <$100. I'm actually using a thin client laptop I picked up for <$100. In fact, if I sold the Wyse thin clients we picked up for <$100, we'd easily double and triple our money since even refurbed they're in the hundreds.

It always amazes me the type of electronics you can find for cheap if you dig enough...
 
This one's not that much more and can do 800Mbps according to Cisco:
https://www.cdw.com/shop/products/Cisco-RV130-VPN-Router-4-Ports/3515740.aspx?pfm=srh#PO
800Mbps.... of what though? NAT? Perhaps. VPN? I don't think so. Turn a few CPU-based services on (VPN included) and most of these Cavium-based architectures get brought to their knees after a few tens of Mb/s (at the most). That said, those metrics may actually suffice in a majority of use-cases, but for any time where 100+ Mb/s of crypto is desirable, you're going to need beefier compute power, for sure. :)
 
800Mbps.... of what though? NAT? Perhaps. VPN? I don't think so. Turn a few CPU-based services on (VPN included) and most of these Cavium-based architectures get brought to their knees after a few tens of Mb/s (at the most). That said, those metrics may actually suffice in a majority of use-cases, but for any time where 100+ Mb/s of crypto is desirable, you're going to need beefier compute power, for sure. :)
But OP's connection is 200Mbps, so it should be fine even if it does only 1/4 of that. Besides for remote access, the ISP's upload bandwidth is going to be the limiting factor. Even my v1 rv016 does 20Mbps Ipsec tunnels, which is still higher than most of today's upload bandwidth on residential accounts. No need to have a cannon when a shotgun will do...
 
Good point. As sad as it is, looking across most of the U.S., we're still in the 5-20Mb/s range for upload on most residential and run-of-the-mill business-class ISP offerings. :confused:
 
Good point. As sad as it is, looking across most of the U.S., we're still in the 5-20Mb/s range for upload on most residential and run-of-the-mill business-class ISP offerings. :confused:
Yep, and that's sad too. I remember when I had 25/5 and that was a good dl/ul ratio. But now with 100/7 as the fastest we can get in this area, that's pitiful. In 10 years it's moved from 5 to 7 while file sizes of everything has gone up by almost 10x.
 
I have 236.48 down and 24.04 up on my ethernet connection and 106.04 down and 23.89 up on my 5 GHz wireless connection. So upload speeds are about 10% of upload speed at the router and 25% on the wireless network.
 
I have 236.48 down and 24.04 up on my ethernet connection and 106.04 down and 23.89 up on my 5 GHz wireless connection. So upload speeds are about 10% of upload speed at the router and 25% on the wireless network.
I so envy you!
 
My 2 cents, If you have an old PC laying around, add a 2nd NIC and load PFsense one it. Its a FreeBSD based router software for x86 which is very powerful and configurable. has openvpn and IPsec and will basically cost you nothing.
 
My 2 cents, If you have an old PC laying around, add a 2nd NIC and load PFsense one it. Its a FreeBSD based router software for x86 which is very powerful and configurable. has openvpn and IPsec and will basically cost you nothing.
There's even a live cd version of 2.26 (2.3+ dropped live cd support), so you can even try it out on any computer that boots from a cd.
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top