5 ms·
I use IPsec in addition to OpenVPN, primarily because that's all iOS used to support. Since iOS 5 or 6 (I think; maybe even as late as version 7?), Apple has al
by dhess 11y ago
I use IPsec in addition to OpenVPN, primarily because that's all iOS used to support. Since iOS 5 or 6 (I think; maybe even as late as version 7?), Apple has allowed third-party VPN apps, so with an "official" OpenVPN client now available in the iOS App Store, it's not as important as it was. However, I've left it running as a fallback solution to OpenVPN (some hotel firewalls, for example, permit IPsec but actively block UDP-based OpenVPN).
I use ipsec-tools, as circa 2012 when I was originally setting this up, it was the only free software IPsec solution I could get to work with iOS clients, but based on this vulnerability I've now disabled it and will try StrongSWAN again.
- brunoqc 11y agoYou can also use OpenVPN on port 443 as a last resort (only as a last resort since TCP over TCP is a bad idea[1]) 1- https://news.ycombinator.com/item?id=2409090 https://news.ycombinator.com/item?id=2409090
- dhess 11y agoYes, I do that as well, but I think that IPsec is a better backup solution.
- 616c 11y agoIn addition, tunneling TCP in TCP to hide OpenVPN behind a HTTP proxy, lest it look out of place and be easily fingerprinted as OpenVPN on packet analysis is why I wanted to avoid it this time around. https://www.bestvpn.com/blog/5919/how-to-hide-openvpn-traffic-an-introduction/ https://www.bestvpn.com/blog/5919/how-to-hide-openvpn-traffi... Plus, I wanted to better secure my home network AND make it accessible remotely (in a dorm-like accomodation with enterprise-grade NAT with Cisco gear), I thought an IPSec tunnel would be optimal as well.