3 ms·
So I've caught flack for choosing an OpenSSH "native" VPN (where it sets up TUN/TAP for you on both ends, etc..) over IPSec before. While I'm sure it's probabl
by drvdevd 10y ago
So I've caught flack for choosing an OpenSSH "native" VPN (where it sets up TUN/TAP for you on both ends, etc..) over IPSec before.
While I'm sure it's probably lower performance, if you've ever done more than just plug and play some Cisco IPSec stuff (e.g. manually implement IPsec on Linux), it is terrifying in its complexity, IMO, for something you depend upon so critcially.
- crest 10y agoIt's not just a performance problem. OpenSSH's VPN works by encapsulating either IP packets (tun) or Ethernet frames (tap) in TCP. Now you suffer from head of line blocking and nested congestion control. If you want an easy to use userspace VPN use OpenVPN. It may be bloated, but it works a lot better than IP over TCP can ever work.
- j_s 10y agoHasn anyone implemented IP over QUIC in any VPN product yet?