Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of VPN Sovereignty
- How commercial VPNs handle metadata logging and legal compliance.
- OpenVPN: A mature, feature-rich solution with TAP/TUN flexibility.
- WireGuard: A modern, minimal approach with high-performance cryptography.
- Selecting the optimal protocol based on your specific threat model.
Implementing OpenVPN
- Installing OpenVPN utilizing Easy-RSA PKI.
- Server setup: configuring ciphers, HMAC, TLS-auth, and topology.
- Generating and distributing client configurations.
- Managing revocation and CRLs.
Implementing WireGuard
- Installing the kernel module and WireGuard-tools.
- Generating keys and configuring peers.
- Managing wg-quick and systemd units.
- Establishing road warrior and site-to-site mesh topologies.
Authentication and Authorization
- Certificate-based authentication with OpenVPN.
- Integration with LDAP and RADIUS backends.
- Implementing two-factor authentication via TOTP plugins.
- Defining access control lists and allocating IPs per user.
Routing and Network Architecture
- Distinguishing between full tunnel and split tunnel routing.
- Configuring push routes, DNS, and WINS.
- Applying NAT and masquerading for egress traffic.
- Implementing Multi-WAN and policy-based routing.
Performance and Scalability
- Comparing WireGuard and OpenVPN throughput benchmarks.
- Optimizing for multi-core performance and kernel bypass.
- Load balancing across multiple VPN servers.
- Applying DDoS protection and connection rate limiting.
Monitoring and Maintenance
- Logging connections and accounting for bandwidth usage.
- Integrating with Syslog and Prometheus exporters.
- Automating certificate renewal and setting expiration alerts.
- Planning for disaster recovery and configuration backups.
Requirements
- Intermediate knowledge of Linux networking and firewall administration.
- A solid grasp of PKI, certificates, and encryption protocols.
- Competence in routing, NAT, and IP forwarding.
Target Audience
- Network administrators seeking to transition away from commercial VPN services.
- Remote work teams requiring sovereign and secure access solutions.
- Organizations operating in regions where VPN blocking or surveillance is common.
14 Hours