2 ms·
Thanks for the feedback! The reason I chose Libreswan [1] (over Openswan) is that it is more actively developed with recent patches [2]. I have not tried stron
by hwdsl2 11y ago
Thanks for the feedback!
The reason I chose Libreswan [1] (over Openswan) is that it is more actively developed with recent patches [2]. I have not tried strongSwan as of yet.
Regarding the firewall rules: The VPN scripts are intended to be run on a freshly installed Linux system. By adding those IPTables rules, the OS would be better protected from network attacks. For example, the L2TP port UDP 1701 is closed for traffic other than those via IPsec.
[1] https://libreswan.org https://libreswan.org
[2] https://nohats.ca/wordpress/blog/2014/02/16/development-of-libreswan-vs-openswan/ https://nohats.ca/wordpress/blog/2014/02/16/development-of-l...