sara-sabr / poc-network-vpn-split-tunnel

Proof of Concept for VPN Split Tunnel using Docker Containers
MIT License
4 stars 0 forks source link

Tracking findings #11

Closed e-wu closed 5 years ago

e-wu commented 5 years ago

This ticket is used to track findings for easier to reference.

e-wu commented 5 years ago

9

Fortinet solution got held up on trial licensing after figuring out how to run a BYOL model through IaaS.

e-wu commented 5 years ago

12

SoftEther with IP based split tunnel is not maintainable. 50 ranges to add just to allow youtube through.
Inverse split tunnel would help, however unable to get it working in SoftEther.

e-wu commented 5 years ago

13

Trying Microsoft Always On VPN (Client side) which allows split tunnel based on domain names and process ID. This requires IKEv2 which SoftEther does not support, so moving to OpenSwan or equivalent.

e-wu commented 5 years ago

17

Can't seem to get the domain name routing to work. Continue investigating. Inverse tunnel was done though.

e-wu commented 5 years ago

Findings summarized in reports presentation.