ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What are your thoughts on Using Zerotier as VPN to highly secure networks.

    IT Discussion
    7
    15
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JasGot @ElecEng
      last edited by

      @eleceng said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

      What are your thoughts on Using Zerotier as a VPN to highly secure networks?

      How will you be configuring access to the network assets and resources? Devices at the other end of a VPN are only as secure as their environment. Be sure to consider all protections before making your decision.

      Sometime HR problems with employees are your biggest security risk. For example, an employee who leave their laptop unattended in a Panera and their password is on a sticky note. Sounds silly, but it happens. When this happens, your very Secure VPN is not so secure! 🙂

      JaredBuschJ 1 Reply Last reply Reply Quote 1
      • dafyreD
        dafyre
        last edited by

        I'll echo @JasGot here. Make sure the endpoints are as secured as corporate devices.

        The short answer is yes, ZT can be configured to do that.

        The slightly longer answer is:

        If you don't have routers that support ZT (Ubiquiti is the only one I'm aware of that does this), then you will need a VM on each network to act as a router between the ZT subnet and the other networks it is connected to.

        scottalanmillerS S 2 Replies Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @ElecEng
          last edited by

          @eleceng said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

          What are your thoughts on Using Zerotier as a VPN to highly secure networks?

          It cannot do it. Because ZeroTier is not a VPN.

          scottalanmillerS 1 Reply Last reply Reply Quote 1
          • JaredBuschJ
            JaredBusch @JasGot
            last edited by

            @jasgot said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

            How will you be configuring access to the network assets and resources? Devices at the other end of a VPN are only as secure as their environment. Be sure to consider all protections before making your decision.

            While 100% true and important to consider, ZeroTier has a very flexible rules engine that will let you be very specific as to what traffic flows over it.

            When COVID lockdowns hit, I simply added a new group and let that group only get RDP over ZeroTier, while others with company controlled laptops still got file sharing.

            Emailed instructions on how to install ZT on their home shit, I installed it on the work desktop, and hten sent them instructions on how to RDP.

            1 Reply Last reply Reply Quote 1
            • scottalanmillerS
              scottalanmiller @ElecEng
              last edited by

              @eleceng said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

              What are your thoughts on Using Zerotier as a VPN to highly secure networks?

              ZeroTier isn't the issue. VPN is the issue. As VPNs go ZeroTier is great. But that's as VPNs go. VPNs are just a tool, like a hammer. They can be used to build a house, but was more often they break things.

              VPNs are super high risk and should be used with extreme caution.

              1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller @JaredBusch
                last edited by

                @jaredbusch said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                @eleceng said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                What are your thoughts on Using Zerotier as a VPN to highly secure networks?

                It cannot do it. Because ZeroTier is not a VPN.

                What do you mean? It's definitely a VPN.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @dafyre
                  last edited by

                  @dafyre said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                  If you don't have routers that support ZT (Ubiquiti is the only one I'm aware of that does this), then you will need a VM on each network to act as a router between the ZT subnet and the other networks it is connected to.

                  Only if you want a gateway style situation. There are other ways to do it.

                  DashrenderD 1 Reply Last reply Reply Quote 1
                  • DashrenderD
                    Dashrender @scottalanmiller
                    last edited by

                    @scottalanmiller said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                    @dafyre said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                    If you don't have routers that support ZT (Ubiquiti is the only one I'm aware of that does this), then you will need a VM on each network to act as a router between the ZT subnet and the other networks it is connected to.

                    Only if you want a gateway style situation. There are other ways to do it.

                    right, isn't the point of ZT to talk directly to other clients on the ZT network?

                    Devices like printers are where you run into issues, so setting up a gateway to handle them might be easiest.

                    scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • E
                      ElecEng
                      last edited by

                      Can zerotier work as a gateway so that all devices on a lan can be accessed? Much like Logmein hamachi in gateway mode?

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Dashrender
                        last edited by

                        @dashrender said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                        right, isn't the point of ZT to talk directly to other clients on the ZT network?

                        Not the point, exactly, but more the "base design" that they started from.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @ElecEng
                          last edited by

                          @eleceng said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                          Can zerotier work as a gateway so that all devices on a lan can be accessed? Much like Logmein hamachi in gateway mode?

                          Yes, exactly.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Dashrender
                            last edited by

                            @dashrender said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                            Devices like printers are where you run into issues, so setting up a gateway to handle them might be easiest.

                            Yes, completely.

                            1 Reply Last reply Reply Quote 0
                            • S
                              scotth @dafyre
                              last edited by scotth

                              @dafyre OPNSense has a plugin for Zerotier. Since OPNSense is a fork of PFSense, I'm guessing that PFSense might have a plugin as well.

                              dafyreD 1 Reply Last reply Reply Quote 1
                              • dafyreD
                                dafyre @scotth
                                last edited by

                                @scotth said in What are your thoughts on Using Zerotier as VPN to highly secure networks.:

                                @dafyre OPNSense has a plugin for Zerotier. Since OPNSense is a fork of PFSense, I'm guessing that PFSense might have a plugin as well.

                                I've used the ZT Plugin for OPNSense, it seemed to work well enough for what I used it for.

                                1 Reply Last reply Reply Quote 1
                                • 1 / 1
                                • First post
                                  Last post