Most secure authentication method for vpn clients

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
allaboutthebase
Posts: 19
Joined: Thu Apr 09, 2020 3:53 pm

Most secure authentication method for vpn clients

Post by allaboutthebase » Wed Apr 15, 2020 7:20 am

Hi just implemented softehter and its going well.

We have individual certificate authentication setup and its going fine.

Just wondering what is the most secure method for protecting against hacking either at the client side, crossing the web or at the server side ?

We have active directory, is NT Domain authentication any better or is there an option for NT auth with individual certificate ?

The only downside of the individual certificate is that anyone sits at computer and can open connection to office without any password required.

I have blocked IPs of stuff they dont need to access and blocked things like RDP and SAMBA etc but every bit more helps.

OliverTejada
Posts: 46
Joined: Mon Apr 13, 2020 8:08 pm

Re: Most secure authentication method for vpn clients

Post by OliverTejada » Wed Apr 15, 2020 2:08 pm

If all of your clients are using L2TP/IPSec as the protocol to establish communication, a strong pre-shared key will circumvent any intrusion attempts. As for the safest authentication method for this particular protocol, I highly recommend NT Domain Authentication and setting logon hours for those users in your active directory settings the way I showed you in another of your threads.

Unfortunately certificate authentication is not working with L2TP/IPSec

Post Reply