聯繫我們

課程簡介

VPN Sovereignty Fundamentals

  • Why commercial VPNs log metadata and comply with legal requests.
  • OpenVPN: mature, feature-rich, TAP/TUN flexibility.
  • WireGuard: modern, minimal, high-performance cryptography.
  • Choosing the right protocol for your threat model.

OpenVPN Deployment

  • Installing OpenVPN with Easy-RSA PKI.
  • Server configuration: cipher, HMAC, TLS-auth, and topology.
  • Client configuration generation and distribution.
  • Revocation and CRL management.

WireGuard Deployment

  • Kernel module installation and WireGuard-tools.
  • Key generation and peer configuration.
  • wg-quick and systemd unit management.
  • Road warrior and site-to-site mesh topologies.

Authentication and Authorization

  • Certificate-based auth with OpenVPN.
  • LDAP and RADIUS backend integration.
  • Two-factor authentication with TOTP plugins.
  • Access control lists and per-user IP allocation.

Routing and Network Design

  • Full tunnel vs split tunnel routing.
  • Push routes, DNS, and WINS configuration.
  • NAT and masquerading for egress traffic.
  • Multi-WAN and policy-based routing.

Performance and Scaling

  • WireGuard vs OpenVPN throughput benchmarks.
  • Multi-core optimization and kernel bypass.
  • Load balancing across multiple VPN servers.
  • DDoS protection and connection rate limiting.

Monitoring and Maintenance

  • Connection logging and bandwidth accounting.
  • Syslog and Prometheus exporter integration.
  • Automated certificate renewal and expiration alerts.
  • Disaster recovery and config backup.

最低要求

  • Intermediate Linux networking and firewall administration.
  • Understanding of PKI, certificates, and encryption protocols.
  • Familiarity with routing, NAT, and IP forwarding.

Audience

  • Network administrators replacing commercial VPN services.
  • Remote work teams needing sovereign secure access.
  • Organizations in regions with VPN blocking or surveillance.
 14 小時

客戶評論 (2)

課程分類