Tuesday, May 25, 2021

SSLVPN - am I nuts, or is this inferior to IPSEC NAT-T

Help, Reddit - I don't get SSLVPN.

Why would I want to pack N TCP sessions behind a single TCP session with a single window that could close and fuck performance at any point, when I could instead run IPSEC NAT-T which punches straight through firewalls owing to it being just port 4500 UDP, and has no such performance concern?

Can someone honestly tell me the benefit of SSLVPN, generally speaking? Is it a nice marketing gimmick so every vendor can just build their own nonstandard client and charge for it?



No comments:

Post a Comment