Would Ubuntu make a good secure server for VPN server?

BirdDad

Golden Member
Nov 25, 2004
1,131
0
71
I have PIA and made a small ITX PC that I want to use for VPN for my families entire network. I had built it for pfSense but it did not work out well, I could not follow the instructions as they no longer applied to the newer version that I had. I could not get pfSense to work with anything other than Blowfish128 and what I want is AES256. It can run Windows 8.1 and PIA's proprietary client without any noticeable slowdown, however I consider Windows insecure and was wondering if Ubuntu with PIA's proprietary client for Linux would be hard to set up, also I wanted to know if Ubuntu has drivers for my board as I had to download drivers to get the encryption engine to work on windows.
Here is the board that I have:
http://www.newegg.com/Product/Product.aspx?Item=N82E16813157626
I am a Linux newbie and find it difficult to work in terminal-I prefer a GUI.
Thanks
 

gus6464

Golden Member
Nov 10, 2005
1,848
32
91
We use OpenVPN virtual appliance at work for VPN and it's nothing but a barebones Ubuntu install. No complaints in the entire time we've had it.

The initial config of the box has to be done via CLI but the config of the actual VPN is done via GUI through the web interface.
 

Fallen Kell

Diamond Member
Oct 9, 1999
6,063
437
126
Out of the box, no. In fact I wouldn't run really any linux distro out of the box connected directly to the internet (too many known security vulnerabilities due to insecure default configurations. So unless you know every piece of software that is open and running on the box and know how to secure it properly, I would pass on this).

Some of the BSD's would be a much better choice as they tend to have proper secure default settings out of the box. Someone already mentioned pfsense, which would be the one I recommend as well for this type of thing as it was specifically designed to act as a firewall and vpn server with an extremely good out of the box configuration due to it being a well known security device used as a first line of defence for protecting networks.
 
Last edited:

hasu

Senior member
Apr 5, 2001
993
10
81
Out of the box, no. In fact I wouldn't run really any linux distro out of the box connected directly to the internet (too many known security vulnerabilities due to insecure default configurations. So unless you know every piece of software that is open and running on the box and know how to secure it properly, I would pass on this).

Some of the BSD's would be a much better choice as they tend to have proper secure default settings out of the box. Someone already mentioned pfsense, which would be the one I recommend as well for this type of thing as it was specifically designed to act as a firewall and vpn server with an extremely good out of the box configuration due to it being a well known security device used as a first line of defence for protecting networks.

Is there a place to find a list of all the known vulnerabilities and its remedies?
 

A5

Diamond Member
Jun 9, 2000
4,902
5
81
Is there a place to find a list of all the known vulnerabilities and its remedies?

There's the NIST NVD, but it isn't really necessary for home users to monitor: https://nvd.nist.gov/

AFAIK, Ubuntu will install most current security updates as part of the installer (if it's online).

We're not talking about a Windows 98 "get owned in 5 minutes on the public internet" style issue here. Like any other OS, just make sure to check for updates regularly and don't install any server daemons that you don't need.
 

Fallen Kell

Diamond Member
Oct 9, 1999
6,063
437
126
Is there a place to find a list of all the known vulnerabilities and its remedies?

Not a single place. In terms of hardening an out of the box config, I would start with STIGs (https://www.stigviewer.com/stigs). You then should look at CVEs (https://cve.mitre.org/cve/). After that you should also be looking at the different vulnerability releases, zero-days, etc...

But that is only the tip of the surface. The STIGs are mainly designed to limit your exposure and log everything needed to attempt to discover a breach, but that only works if you are then actively reading those logs and following up on questionable activity found in the logs. Telling you how to identify questionable activity would take about 2 years of training.... And even then, a really good breach is very difficult to detect as they would attempt to cover their tracks (which is one of the reasons why the STIGs recommend having a remote log system so that a bot/person who breaches the machine can't cleanup the logs behind it to remove the offending activity as they would need to also breach the remote log server, which is hopefully firewalled off with only the syslog and similar ports open through the firewall).
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |