OpenVPN vs IPSec
    Muenz, Michael 
    m.muenz at spam-fetish.org
       
    Sun Nov 19 12:32:32 UTC 2017
    
    
  
Am 19.11.2017 um 13:08 schrieb Victor Sudakov:
> Muenz, Michael wrote:
>>> Is there any reason to prefer IPSec over OpenVPN for building VPNs
>>> between FreeBSD hosts and routers (and others compatible with OpenVPN
>>> like pfSense, OpenWRT etc)?
>>>
>>> I can see only advantages of OpenVPN (a single UDP port, a single
>>> userland daemon, no kernel rebuild required, a standard PKI, an easy
>>> way to push settings and routes to remote clients, nice monitoring
>>> feature etc). But maybe there is some huge advantage of IPSec I've
>>> skipped?
>>>
>> Hi,
>>
>> partners/customers with Cisco IOS or ASA wont be able to partner up
>> without IPSEC.
> Sure, that's why I wrote "and others compatible with OpenVPN
> like pfSense, OpenWRT etc" in the first paragraph.
>
Are you just searching for arguments against IPSec or real life cases?
IMHO when you have both ends under control OpenVPN is just fine.
If you are planning to interconnect with many customers/vendors IPSec 
fits best.
In the last 15 years I was never asked about a Site2Site VPN with OpenVPN
from any customer or partner of the firewalls I managed.
Michael
    
    
More information about the freebsd-net
mailing list