61
Users / Re: Why VPN (was: setup qorbiter to be used from ouside internal network i.e. across town)
« on: November 27, 2013, 03:33:47 am »
@Langston: no problem! My pleasure!
@Matt,
How it works will depend a bit on what you're using as a "client". The wiki page I linked describes LMCE's VPN implementation, which uses IPSEC or a Layer 2 Tunnelling protocol (L2TP). Those are pretty common, and there are clients in, or available for, most mobile devices and computers. The solution I use implements IPSEC, and uses certificates for two-factor authentication (something you have, the certificate, and something you know, the password). It works on my iDevices, and I can install the VPN profile quite easily. When I want to access the house, I click the VPN setting on, enter my password, and then I'm in. I can then launch RoamingOrb or whatever app to access internal services. I could make it easier using iOS7's new VPN on demand features, but I'd have to create some Mobile Device Management (MDM) profiles; right now, it'd be too much work in order to be lazy
VPN's have other nice features, depending on the product. Most give you seperate address spaces, so you can route, filter, and firewall to your hearts content. Most enterprise Wi-Fi implementations require a VPN connection over Wi-Fi in order to access corporate services. There are other fancier features, but you get the idea...
HTH!
/Mike
DOH! Link in other thread, now here for reference: http://wiki.linuxmce.org/index.php/VPN
@Matt,
How it works will depend a bit on what you're using as a "client". The wiki page I linked describes LMCE's VPN implementation, which uses IPSEC or a Layer 2 Tunnelling protocol (L2TP). Those are pretty common, and there are clients in, or available for, most mobile devices and computers. The solution I use implements IPSEC, and uses certificates for two-factor authentication (something you have, the certificate, and something you know, the password). It works on my iDevices, and I can install the VPN profile quite easily. When I want to access the house, I click the VPN setting on, enter my password, and then I'm in. I can then launch RoamingOrb or whatever app to access internal services. I could make it easier using iOS7's new VPN on demand features, but I'd have to create some Mobile Device Management (MDM) profiles; right now, it'd be too much work in order to be lazy
VPN's have other nice features, depending on the product. Most give you seperate address spaces, so you can route, filter, and firewall to your hearts content. Most enterprise Wi-Fi implementations require a VPN connection over Wi-Fi in order to access corporate services. There are other fancier features, but you get the idea...
HTH!
/Mike
DOH! Link in other thread, now here for reference: http://wiki.linuxmce.org/index.php/VPN