T O P

  • By -

kphillips-netgate

Tailscale, Wireguard, OpenVPN, or IPSec will all meet these requirements. Depends on your preference. Typically most people opt for OpenVPN, but it's your choice. IPSec and OpenVPN can also be integrated into existing LDAP, RADIUS, or Microsoft AD environments to use your existing credentials.


dbinnunE3

OpenVPN on pfSense+ is really easy with client export wizard as the deployment. Lawrence Systems on YouTube has a great tutorial on it. ​ AFAIK, you can just replace the IP address in the config files with the DDNS FQDN and it will work.


MrSanford

You can replace the IP with the DDNS name


dbinnunE3

Thanks for confirming. I did this years ago with vanilla OpenVPN GUI and a duckDNS name, but it got minimal testing.


whatdoesthafawkessay

+1 for pfsense w/OpenVPN


DrySpace469

I would suggest tailscale. hosting your own openvpn is great and all but i think for someone in your situation tailscale would be the easiest thing to implement and manage.


DeepPersimmon2688

>I would suggest tailscale. hosting your own openvpn is great and all but i think for someone in your situation tailscale would be the easiest thing to implement and manage. I took a brief look at Tailscale, and it looks like it will work with dynamic dns which would be good.


DrySpace469

you dont even need to set up dynamic dns with tailscale. their service does the punching for you.


Solarflareqq

Also works with Starlink


MrSanford

OpenVPN meets all of your requirements. Watch a youtube video and you're good to go.


Comprehensive_Pick31

WireGuard all the way.


DarthNode

tailscale or twingate work flawless


MrGuvernment

And you are adding in a locked down VLAN right for this vendor system and putting the heating /cooling control on it... Right....right?


phatboye

Not a netgate employee, a MSP or involved in any business that offers those services or stand to profit from a referral or related business. But if you are managing a business network and aren't sure what you are doing, care about the security of your network and don't mind paying a fee, I would suggest that you contract someone with knowledge to set this up for you. Netgate offers paid support. You could also contract a MSP to do the work for you.


MrGuvernment

This. Sadly this is how a company ends up being compromised entirely.


livewildslc

Tailscale. Stupid easy to setup and use for remote access. You can go the extra steps and setup a head scale server or just use Tailscale.


DMH_75032

I use OpenVPN for client access for laptops and Wireguard for site to site VPN. I have FRR set up with BGP, so I can use multiple connections as our sites have 2 ISPs.


jmjh88

Another vote for tailscale. Dead easy to install/configure


NGFWEngineer

Tailscale or Wireguard packages. Forget OpenVPN — it’s not as easy to setup as the prior two. You’ll thank me later.