On 11/19/2017 07:33, Miroslav Lachman wrote:
> Muenz, Michael wrote on 2017/11/19 13:32:
>> Am 19.11.2017 um 13:08 schrieb Victor Sudakov:
>>> Muenz, Michael wrote:
>>>>> Is there any reason to prefer IPSec over OpenVPN for building VPNs
>>>>> between FreeBSD hosts and routers (and others compatible with OpenVPN
>>>>> like pfSense, OpenWRT etc)?
>>>>>
>>>>> I can see only advantages of OpenVPN (a single UDP port, a single
>>>>> userland daemon, no kernel rebuild required, a standard PKI, an easy
>>>>> way to push settings and routes to remote clients, nice monitoring
>>>>> feature etc). But maybe there is some huge advantage of IPSec I've
>>>>> skipped?
>>>>>
>>>> Hi,
>>>>
>>>> partners/customers with Cisco IOS or ASA wont be able to partner up
>>>> without IPSEC.
>>> Sure, that's why I wrote "and others compatible with OpenVPN
>>> like pfSense, OpenWRT etc" in the first paragraph.
>>>
>>
>> Are you just searching for arguments against IPSec or real life cases?
>> IMHO when you have both ends under control OpenVPN is just fine.
>> If you are planning to interconnect with many customers/vendors IPSec
>> fits best.
>>
>> In the last 15 years I was never asked about a Site2Site VPN with
>> OpenVPN
>> from any customer or partner of the firewalls I managed.
>
> I have opposite experience. One customer needs IPSec and setting and
> debugging was a pain because we don't have access to the other end.
> On the other hand customers with OpenVPN works in a minute. Just send
> or receive openvpn.conf, set some variables in rc.conf and VPN is up
> and running. So I prefer OpenVPN whenever possible.
>
> Miroslav Lachman

I run both here and at some client sites, but not really by choice.

The reason is Windows.  Microslug hasn't updated their client since at
least Windows 7 release (we're talking about over a decade now) and
their IKEv2 implementation doesn't support IKE fragmentation.  In
today's world this usually means IPSEC/IKEv2 won't connect at all
because someone in the middle drops UDP fragments on purpose.

I'd like to ram that up someone's chute out at Microslug, never mind
that their default proposals are intentionally insecure (gee, I wonder
if someone in the government "asked nicely" for that?)  That's fixable
with a bit of registry editing, but the lack of IKEv2 frag support is a
killer and has basically forced me to support OpenVPN when there are
windows clients around and you have no control (at all) over the
networks in the middle between the client and server.

-- 
Karl Denninger
k...@denninger.net <mailto:k...@denninger.net>
/The Market Ticker/
/[S/MIME encrypted email preferred]/

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to