A lot of warnings against TLS based VPN solutions. I imagine these solutions are popular because they are more likely to function through corporate firewalls, where IPsec might be blocked. Unsurprisingly no mention of wireguard, as it's not FIPS. However, unless you need FIPS compliance, it seems like the way to go these days.
> Unsurprisingly no mention of wireguard The hard part of a VPN, the part that everybody makes money at, isn't the IP-level encapsulation. Yes, Wireguard is both conceptually and in implementation simpler and more elegant in this regard. But IPSec per se isn't actually a real pain point in real world corporate road warrior deployments, at least not any more than with Wireguard, which can have very similar issues with…
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#41Whilst I think IKEv2 is the best non-wireguard protocol, I've found the seamless roaming/no reconnects of WireGuard to be magical. It is never like that with IKEv2.