Live data from Hacker News

Selecting and Hardening Remote Access VPN Solutions [pdf]

media.defense.gov

1–10 of 41 posts

Re: Selecting and Hardening Remote Access VPN Solutions [pdf]

#2
A lot of warnings against TLS based VPN solutions. I imagine these solutions are popular because they are more likely to function through corporate firewalls, where IPsec might be blocked.

Unsurprisingly no mention of wireguard, as it's not FIPS. However, unless you need FIPS compliance, it seems like the way to go these days.

Re: Selecting and Hardening Remote Access VPN Solutions [pdf]

#5
post #3

Strange how this implies that the end-all-be-all of VPNs is IPsec. I would've loved to hear their opinion on wireguard and this generation of mesh VPNs

That's because wireguard uses non FIPS 140 compliant algorithms. What would be really interesting is if the NSA told us their thoughts on the wireguard algos.

Re: Selecting and Hardening Remote Access VPN Solutions [pdf]

#8
post #4

I'm saddened that the answer isn't "Just use BeyondCorp". Layer 7 solutions provide so much more capacity for granular AuthZ, and thereby eliminate the "soft underbelly" of corporate networks.

You're expecting the NSA to recommend BeyondCorp?

Re: Selecting and Hardening Remote Access VPN Solutions [pdf]

#9
post #2

A lot of warnings against TLS based VPN solutions. I imagine these solutions are popular because they are more likely to function through corporate firewalls, where IPsec might be blocked. Unsurprisingly no mention of wireguard, as it's not FIPS. However, unless you need FIPS compliance, it seems like the way to go these days.

With something like OpenVPN, they seem to have strong issues with some exploitable parts of the startup/bring-up process. There are two ways to look at this:

It's either too good for them or it's bad. :)

Re: Selecting and Hardening Remote Access VPN Solutions [pdf]

#10
post #4

I'm saddened that the answer isn't "Just use BeyondCorp". Layer 7 solutions provide so much more capacity for granular AuthZ, and thereby eliminate the "soft underbelly" of corporate networks.

You're expecting the NSA to recommend BeyondCorp?

Why wouldn't they?
Post reply on HN