Re: [Openvpn-users] VPN without encryption and auth

2017-08-06 Thread Steffan Karger
Hi, On 06-08-17 10:35, Yevgeny Kosarzhevsky wrote: > OpenVPN without encryption or with weak encryption using '--auth none > --no-iv --no-replay' is still great tool for tunneling traffic over UDP > protocol. IPIP, L2TP or other known tunneling solutions may be blocked > in certain countries. This

Re: [Openvpn-users] HA between two server on different sites.

2017-08-06 Thread David Sommerseth
On 25/07/17 19:24, Marcelo Moraes wrote: > Hi everybody. > > First of all, I'm sorry. This may be a very simple matter, but I'm not > succeeding in solving it. > > Ineed to make a high availability between two openvpn servers that are > in two different physical locations. I thought first of maki

Re: [Openvpn-users] VPN without encryption and auth

2017-08-06 Thread David Sommerseth
On 06/08/17 10:35, Yevgeny Kosarzhevsky wrote: > OpenVPN without encryption or with weak encryption using '--auth none > --no-iv --no-replay' is still great tool for tunneling traffic over UDP > protocol. Fair enough, I've learnt that there are some scenarios which can benefit from this. > IPIP,

Re: [Openvpn-users] HA between two server on different sites.

2017-08-06 Thread Abi Askushi
There are several ways that pass to my mind though it depends from the exact requirements which would be the best approach: 1. Simple failover with multiple remote servers on the client side config. You can even put weights here. 2. Have the servers on a cloud provider that provides virtual ip fa

Re: [Openvpn-users] VPN without encryption and auth

2017-08-06 Thread Abi Askushi
I would suggest to keep auth enabled, while having cipher none, to avoid DoS attacks. On Aug 6, 2017 11:35, "Yevgeny Kosarzhevsky" wrote: > > > On 2 August 2017 at 20:37, David Sommerseth topphemmelig.net> wrote: > >> >> Configuring OpenVPN without encryption is a peculiar use case I've >> seld

Re: [Openvpn-users] VPN without encryption and auth

2017-08-06 Thread Yevgeny Kosarzhevsky
On 2 August 2017 at 20:37, David Sommerseth < open...@sf.lists.topphemmelig.net> wrote: > > Configuring OpenVPN without encryption is a peculiar use case I've > seldom quite understood, except if you're doing some research on various > crypto or network related scenarios. OpenVPN without encrypt