OpenVPN fully implements IPv6
Summary
In January 2013 OpenVPN 2.3.0 appeared with full IPv6 support, as developer Gert Doering announced. A serious bug in the last beta version had delayed the release by a few days. Also new was the optional use of PolarSSL, which the Dutch government had already been using since 2011 as OpenVPN-NL.
Ideas
- VPN software has to handle both IP protocols inside and outside the tunnel.
- An alternative crypto library reduces dependence on OpenSSL.
- A bug found shortly before release postponed the publication.
Insights
- Authorities rely on free VPN software when they can review its code.
- Late postponements because of bugs are better than faulty releases.
Facts
- OpenVPN 2.3.0 also reworked the plugin API, for example for X.509 certificates as plugins.
References
Critique
- The report gives no details on the configuration or limitations of the IPv6 support.
Remarks
- PolarSSL has been called Mbed TLS since 2015.
Recommendations
- Configure VPNs dual-stack so that no IPv6 traffic bypasses the tunnel.
- For new installations, consider WireGuard as a leaner alternative to OpenVPN.
Links to the original source and the Web Archive open in a new tab.