Lowell Higley on 4 Jul 2017 08:53:30 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Firewall choices for a small software development business


>> I have one. The only issue I have with it is that it only supports IPSec for VPN

That depends.  If you want to setup a VPN client, such as to PIA, then the controller UI only supports PTPP.  However, you can ssh in and setup openvpn, etc. Site to site supports openvpn and IPsec in the controller UI. Remote user supports L2TP in the UI. (screenshots below.) As they build out the UI you will see more options added. Again, you can go to the cli today and setup other VPN protocols if you wish.
Inline image 1

Inline image 2

>>  if I recaKk correctly, you need a separate RADIUS server to make it work.

You can configure a radius server for remote clients, I think, but I've never done that. Haven't needed the functionality yet. Depends on the type of VPN tunnel you setup. I have a PTPP VPN setup to PIA and don't need/have a radius server.  I've been experimenting with openvpn as well and it also does not require radius.

Also, full disclosure I am running the beta version of the controller software, v5.6.7, so all these features/options may not be available in the GA software.


On Tue, Jul 4, 2017 at 8:28 AM, Matt Mossholder <matt@mossholder.com> wrote:

On Tue, Jul 4, 2017 at 10:18 AM Lowell Higley <higleylh@gmail.com> wrote:
This isn't open source but I found the solution to be pretty good. 

Unifi Security Gateway [Amazon] [Ubiquiti]


I have one. The only issue I have with it is that it only supports IPSec for VPN, and if I recaKk correctly, you need a separate RADIUS server to make it work.

Well, that, and adding rules is a bit clunky, and not as flexible as some of the other solutions.  In the end, though, it is still the solution I am actually using.
--
     --Matt

___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug


___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug