VPN - Explain to a dummy
#16
FlyerTalk Evangelist

Join Date: Mar 2005
Location: 60137
Posts: 10,499
#17
Join Date: Aug 2005
Location: SNA Rwy 20L
Programs: QF Silver
Posts: 703
1. When sending out emails while VPN is on, some recipient email networks will not accept it and/or consider it spam. So, while you'll be able to send out, the recipient might not be able to receive it. I use witopia.net, they are excellent. But at least two networks, mindspring and bellsouth.net bounce them back.
2. Many websites can detect you using vpn and will block access. Hulu is one example.
2. Many websites can detect you using vpn and will block access. Hulu is one example.
I set up the home server because outbound e-mails are blocked by my work VPN. My reply-to personal email addy is: [email protected] and our work server only allows [email protected] mails to go out.
It's also pretty easy these days to pick up a $30 dd-wrt wireless router and reflash the firmware to give you a very cheap home VPN server.
#18




Join Date: Sep 2008
Location: Dayton, OH
Programs: Delta SkyMiles, Marriott Platinum
Posts: 415
After creating the connection, all your network traffic - web browsing, email, IM, everything - is routed through your encrypted VPN connection. It's like your computer is plugged into your office network or your home network, but you can be across the street or across the world.
If you're using a full tunnel VPN connection, then yes, the above statement is accurate. All traffic is routed through the VPN connection.
If you're using a split tunnel VPN connection, then no, the above statement is not accurate. Only traffic destined for the VPN network will travel through the VPN connection, while all other traffic ignores the VPN connection completely and goes straight out to the Internet.
#19
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
I use a Trendnet router that supports both IPSEC and SSH. I think it cost around $100. There are lots of inexpensive routers around that support only IPSEC.
#20
FlyerTalk Evangelist



Join Date: Nov 2002
Location: ORD
Posts: 14,773
I've seen this mentioned a few times within this thread so just wanted to clarify that the above statement is not necessarily accurate.
If you're using a full tunnel VPN connection, then yes, the above statement is accurate. All traffic is routed through the VPN connection.
If you're using a split tunnel VPN connection, then no, the above statement is not accurate. Only traffic destined for the VPN network will travel through the VPN connection, while all other traffic ignores the VPN connection completely and goes straight out to the Internet.
If you're using a full tunnel VPN connection, then yes, the above statement is accurate. All traffic is routed through the VPN connection.
If you're using a split tunnel VPN connection, then no, the above statement is not accurate. Only traffic destined for the VPN network will travel through the VPN connection, while all other traffic ignores the VPN connection completely and goes straight out to the Internet.
#21

Join Date: Feb 2009
Posts: 3,774
Gizmodo.com article on VPN:
http://gizmodo.com/5713626/how-to-wa...ramming-abroad
http://gizmodo.com/5713626/how-to-wa...ramming-abroad
#22
Join Date: Apr 2006
Location: on the Llano Estacado
Posts: 2,652
If you have DD-WRT on a router, you can setup the VPN client on any Win pc anywhere quite easily - they even have wizards to walk you through it. Not so with IPSEC - this can take considerable technical acumen.
OTOH, if you are able to install DD-WRT, you can probably handle either.
#23
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Looks like a good place to mention the novice VPN configuration dilemma:
If you have DD-WRT on a router, you can setup the VPN client on any Win pc anywhere quite easily - they even have wizards to walk you through it. Not so with IPSEC - this can take considerable technical acumen.
OTOH, if you are able to install DD-WRT, you can probably handle either.
If you have DD-WRT on a router, you can setup the VPN client on any Win pc anywhere quite easily - they even have wizards to walk you through it. Not so with IPSEC - this can take considerable technical acumen.
OTOH, if you are able to install DD-WRT, you can probably handle either.

#24
FlyerTalk Evangelist


Join Date: Jun 2002
Location: n.y.c.
Posts: 14,059
The basic idea of a VPN is that your computer creates an encrypted connection, over the internet, to a computer network that you trust. This could be, say, the network at your office, your home, or a third party VPN service provider.
After creating the connection, all your network traffic - web browsing, email, IM, everything - is routed through your encrypted VPN connection. It's like your computer is plugged into your office network or your home network, but you can be across the street or across the world.
The "tunnel" mentioned is simply the idea that any outsider trying to snoop on you would only see an encrypted connection between you and your trusted computer network. Within that encrypted connection, you are sending all kinds of information.
After creating the connection, all your network traffic - web browsing, email, IM, everything - is routed through your encrypted VPN connection. It's like your computer is plugged into your office network or your home network, but you can be across the street or across the world.
The "tunnel" mentioned is simply the idea that any outsider trying to snoop on you would only see an encrypted connection between you and your trusted computer network. Within that encrypted connection, you are sending all kinds of information.
It's always funny watching technical people try to explain concepts to non-techies, and being completely unable to avoid terms (certificate, protocol, tunnel, client, LAN) the non-techie won't understand.
#25


Join Date: Apr 2006
Location: New York City/NY22
Programs: AA Platinum 2.3MM (Lifetime PLT)
Posts: 5,291
To dumb it down even a bit more...
. . .
SECURITY
When you connect to the internet at a Holiday Inn or Starbucks most of your web browsing can be intercepted by: a) other users close enough to hear your wireless connection and b) nefarious folks between the hotel router and the final www address you're linking up to. Sites starting with https:// (as opposed to http://) are relatively secure but not 100%. Since your traffic is encrypted all anyone in the middle will see will be unintelligible.
. . .
. . .
SECURITY
When you connect to the internet at a Holiday Inn or Starbucks most of your web browsing can be intercepted by: a) other users close enough to hear your wireless connection and b) nefarious folks between the hotel router and the final www address you're linking up to. Sites starting with https:// (as opposed to http://) are relatively secure but not 100%. Since your traffic is encrypted all anyone in the middle will see will be unintelligible.
. . .
Should I get VPN?
How about if I want to use something like www.aa.com to make and check reservations?
#26

Join Date: Jun 2006
Location: KIX, ITM, UKB, YVR
Programs: Star Alliance - AC
Posts: 2,356
I use Starbucks wifi but the only (at least the only one of which I am aware) security issue for me is using Outlook to get email from my ISP.
Should I get VPN?
How about if I want to use something like www.aa.com to make and check reservations?
Should I get VPN?
How about if I want to use something like www.aa.com to make and check reservations?
#27
Join Date: Oct 2006
Location: YYZ/DLC
Programs: AP, HHonours Diamond
Posts: 3,724
I suspect that some services may be aware of some of the commercial VPN IPs and are blocking them. I run an OpenVPN Linux server at home so my traffic appears to originate there and haven't had any problems with e-mail or accessing Hulu overseas.
I set up the home server because outbound e-mails are blocked by my work VPN. My reply-to personal email addy is: [email protected] and our work server only allows [email protected] mails to go out.
It's also pretty easy these days to pick up a $30 dd-wrt wireless router and reflash the firmware to give you a very cheap home VPN server.
I set up the home server because outbound e-mails are blocked by my work VPN. My reply-to personal email addy is: [email protected] and our work server only allows [email protected] mails to go out.
It's also pretty easy these days to pick up a $30 dd-wrt wireless router and reflash the firmware to give you a very cheap home VPN server.
I'm in a similar boat as you and don't want to get a commercial VPN service where my data would end up at someone else's server needlessly if I can route it through home.
What are the Pros/Cons to this approach?
#28
FlyerTalk Evangelist
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Do you have a link to a tutorial to set up a DD-WRT OpenVPN server?
I'm in a similar boat as you and don't want to get a commercial VPN service where my data would end up at someone else's server needlessly if I can route it through home.
What are the Pros/Cons to this approach?
I'm in a similar boat as you and don't want to get a commercial VPN service where my data would end up at someone else's server needlessly if I can route it through home.
What are the Pros/Cons to this approach?
Why not just get something like this?

http://www.buy.com/prod/trendnet-4-p...207552331.html
#29
Join Date: Oct 2006
Location: YYZ/DLC
Programs: AP, HHonours Diamond
Posts: 3,724
With all due respect, information on DD-WRT is readily available, and a couple of minutes of googling around would find it. Though it doesn't require a lot of technical expertise to mod a router, if you do it wrong you can wind up with a useless brick.
Why not just get something like this?

http://www.buy.com/prod/trendnet-4-p...207552331.html
Why not just get something like this?

http://www.buy.com/prod/trendnet-4-p...207552331.html
A) Keep the current role of the router as a repeater.
B) Be able to enable/access the OpenVPN on it even though it's behind my main network router.
Thanks anyway.
#30


Join Date: Apr 2006
Location: New York City/NY22
Programs: AA Platinum 2.3MM (Lifetime PLT)
Posts: 5,291

