VPNs have become a core part of IT infrastructure, especially with the rise of remote work.
VPN protocols
OpenVPN
Open source, secure and flexible. Recommended for most deployments.
WireGuard
Newer, faster, and increasingly popular.
IPSec
Built into many devices, ideal for site-to-site connections.
Security best practices
- Strong authentication: use MFA for VPN access
- Modern encryption: AES-256 minimum
- Split tunneling: limit VPN traffic to what's necessary
- Monitoring: watch for unusual connections
Recommended configuration
A solid configuration relies notably on cipher AES-256-GCM, auth SHA256, and tls-version-min 1.2.
A poorly configured VPN can create a false sense of security. Rigor in configuration is essential.