VPN options/best practice for public WiFi

nry

Limp Gawd
Joined
Jul 10, 2008
Messages
409
Figured I'd ask this here as there is some brilliant advice on just about everything!

I'm currently investigating securing my connections and making my home lab available for when I'm on the road, I was thinking of using OpenVPN on my pfSense box for this. Any pointers/articles which would help me to understand any of the below concerns I am having would be great :)

My first concern is with some public WiFi connections I noticed that some offer a free service for 24 hours which blocks VPN connections then offer a paid service for £5-10 per day which allows them. :mad:
I'm not sure if they block https connections too, but in theory providing they don't, if my OpenVPN server ran on port 443 would I be able to access my VPN for free?
Assuming it may come down to deep packet inspection, but this is well out of my field here

My second concern is the period between selecting the free wifi connection and actually connecting to the VPN. How much traffic will be sent unencrypted?
I have noticed with many connections you need to enter a simple password on a captive portal, assuming at this point you can't be connected to the VPN or you wouldn't be able to access this portal?
As I never actually turn my mac off nor close the applications on it, I am assuming most of these applications would start attempting to connect to their servers before the VPN is connected?

Thanks
 
SSL VPN can tunnel over port 443 and get around most of those blocks.

OpenVPN installed on your PFsense box should allow you to do this.

I couldnt tell you how a MAC would behave, each application may very well behave differently when you wake your machine.
 
Thanks, will have a go at setting it up.

At the end of the day most things such as email/important sites/ssh are encrypted in one way or another so I can't see it being a major issue. Just trying to grasp the standard practices for VPN use as it's something I haven't really had to use before.
 
Back
Top