What's new

Secure VPN server setup?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Diveblaster

Regular Contributor
Hi
Ty again for ur wonderful work with Merlins FW :D I've been a fan for years.
To my question then:
What is the most secure VPN setup u can do regarding protocol/hash/crypto...etc
I use my Asus router as VPN server for clients to use.

Merlin 380.65 on a RT-AC66U,
 
Most secure or most reasonable? What is the "purpose" of the VPN? What are you trying to secure? Is it just for remote access? Security while clients on on public hotspots? What are your performance expectations? Are you trying to protect from random prying eyes or nation state?

Protocol/Hash/CipherSuite -- All just one part of "security". Even if you run AES-256/SHA-256, it is encrypted well, but if the authentication and/or key exchange is weak...what's the point?

For most, just using the basic AES-128/SHA-256 will be plenty. If using Diffie-Hellman, use a 2048-bit key or longer. Focus your time/energy on making sure you are using unique accounts per user with strong passwords. Attempt to get certificate authentication functional.
 

Similar threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top