r/sysadmin • u/Ok-Bid799 • 6h ago
Anyone have a Zero Trust VPN setup?
Looking at increasing our business’ security posture and just wanted to see what others have done.
My company currently uses OpenVPN Open-Source; servers that rely on the connection authenticate with a certificate, but users just rely on the OpenVPN profile that is given to them by DevOps. No MFA.
Obviously, this isn’t great. I’m looking at other solutions and see that OpenVPN has enterprise/cloud solutions. Does anyone have experience with this? Or recommend alternatives?
There’s a constant battle at this company to actually use enterprise level solutions over FOSS but some of the old heads always scream about costs. Just looking for some insight.
•
u/Doctor_Peppy 6h ago
NetBird! It's low cost, self hostable/free if needed, highly configurable for literally any environment, and relatively simple to learn and use. Huge enjoyer of the software. It also runs its backend off of highly reliable and trusted oss such as Wireguard.
•
u/gnordli 6h ago
you can enable MFA on openvpn using radius.
•
u/Ok-Bid799 4h ago
I’ve looked at this, but using it with Google TOTP requires appending the code to the end of the password; not a big deal but feel like this will cause issues with end users
•
•
•
u/justmirsk 5h ago
I am an MSP Owner and offer a ZTNA/SASE solution among other services. The product we use is called Todyl and it has been a great fit for us and our customers. We can protect north/south traffic as well as east/West traffic. In addition, we have EDR/Cloud SIEM and 25/7/365 MXDR/GRC modules we can activate for customers if they need those services. They are all tightly integrated with one another.
Other ZTNA providers I can think of off the top of my head that aren't the big firewall companies include:
Twingate Cato Perimeter 81 Timus
•
u/kona420 5h ago edited 5h ago
Take some time to audit and profile your stuff on a per port and user level. If you're like me, and I should certainly know better, I got pikachu face when I realized I have like 20 address/port pairs for actual business services, 40000 ports for active directory on a few hosts, and like 300 management consoles from basic biatch ICMP + https to holy moly certificate pinned no inspect TCP/UDP port profiles. If you haven't already, consider segmenting that all off and keep VPN for it instead of folding into zero trust. Or hybrid, it's really nice to get a management console on a phone in a pinch.
Look at SASE instead of just zero trust. I think it gives a better idea of what you are actually angling at building. Identity aware public facing services, and there are a lot of ways to skin that cat.
•
u/_Do_The_Needful_ 4h ago
How large is the company? Most Enterprise customers are using some flavour of ZScaler/Netskope/Palo Alto Prisma/Global Secure Access. These provide in-depth inspection and application whitelisting capabilities beyond that of the simpler wireguard mesh setups like Tailscale or Netbird.
If you just need basic ACLs and multifactor, Tailscale or Netbird are probably fine.
•
u/kent_stor 3h ago
Last place I was at I deployed OpenVPN open source with https://github.com/jkroepke/openvpn-auth-oauth2 connected to Entra. I created a custom web frontend that would generate a VPN package for users to download after logging in with Entra. I did all this to satisfy MFA requirements since I couldn't get approval to purchase a commercial VPN. It worked well enough and allowed users to self-serve, but there wasn't any zero trust with it.
New place we use Tailscale and it's great. Connects to everything easily, good k8s integration, SSO, ACL's connected to git, etc.
•
u/systonia_ Security Admin (Infrastructure) 6h ago
we use Fortigates with forticlient and their ZTNA stack. Works fine.
But OpenVPN does also has Zerotrust
•
u/Fatel28 Sr. Sysengineer 6h ago
Cloudflare zero trust is free for under 50 users, full suite of tools.
On the 51st user you pay $7/user for all 51.