VPN for Remote Workers - MSP Focused

Hi All

Looking for some advice.

What would everyone recommend as a “good” VPN solution. Something on the lines of NordVPN but with a good MSP focus?

We’re looking at this with security of remote users in mind who are regularly using public wifi.

Thanks in advance!

Spin your own OpenVPN, can drop a couple endpoints around the world.

Why not a VPN back to their central office based on whatever firewall / edge device they have?

If you dont have a firewall or edge device with built in vpn support I’d check out SoftEther. It’s open source and extremely easy to setup support for a wide variety of connection methods if you want to utilize an endpoint device’s native VPN without installing a client.

Tehama, born inside data msp Pythian, is a remote access solution for securing msp / customer connectivity. https://tehama.io

Disclosure: I founded Tehama (and Pythian for that matter).

What types of traffic are you trying to conceal?

Endpoint VPN with Next Gen firewall and included SEIM.

set up a few little linux instances in vultr or digital ocean instances. Charge per user. Pretty easy to manage. Or, set up OpenVPN AS in AWS/Azure.

Probably not Nord… NordVPN confirms it was hacked | TechCrunch

I’m confused to the problem you are trying to solve. Are you just looking for a “more secure way to browse the internet”?

FYI all… don’t know if this is “old news” but popped up today … NordVPN admits to 'isolated' server breach in Finland

Do they need to connect to office resources over this VPN? Or are you just trying to mask their traffic from coffee shop and airport snoopers?

Might be cheaper to give them a Hotspot or have them always surf thru their phones.

Could spin up an OpenVPN and connect back to the office FW.

I personally use PIA to mask my traffic. But that’s a personal choice. I use SonicWall to connect to the office.

might always want to look at OpenDNS agents to see if that helps funnel queries without so much VPN overhead.

Ordinarily I’d agree but we do have clients who are Remote/Home workers only. These guys use laptops exclusively and are constantly on/off free wifi networks and we’re looking at ways we can secure that traffic.

Essentially it’s anything and everything.

We work with remote-only customers who are constantly using their laptops on free wifi in hotels and coffee shops etc. That includes the accounts guys who are online banking.

I think PIA has had some issues, not major ones but if it is only privacy in mind I’d say go with NordVPN or review how much security you need by checking out That One’s VPN comparison chart https://thatoneprivacysite.net/ I don’t think PIA comes in the top 20 as far as privacy goes. If you exclude 14 eyes jurisdiction it is ranked 15th I think.

Edit: Actually Nord is a bit below PIA because they do not specify if they log DNS. I think black VPN is the best one for privacy all things considered.

Sonicwalls, I use Global VPN Client, or NetExtender for the remote home users. In some cases additional licenses to extend the concurrent connections might be needed, however I found… The use of SSL VPN for remote billing users, and VPN, for the boss’s office manager wants to work remote is sufficient.

OpenVPN is a free alternative and with plenty of home end-point devices you can pre-configure.

I use a portable mini-wifi-router with OpenVPN to VPN into my home office, for when I’m on trips. So makes having a “mobile office” possible.

Online banking, for example, is HTTPS so for this use case, free Wi-Fi is ok as long as you can force HTTPS.

We enforce only sonicwall’s VPN otherwise we don’t support it.

That’s true.

What I want to avoid is a man in the middle situation where they’re connecting to a free wireless that isn’t what it appears to be.