Jump to content

[QUESTION] Which VPN is best?


CBers

Recommended Posts

Swynol

Thanks @@Crestj.

 

Just signed up to TorGuard for a year using that code and I got it for £18.41 ($23.47).

 

Gives me plenty of time to play :)

 

thats just for the proxy. or did you get the VPN option?

Link to comment
Share on other sites

Swynol

mmm tempting. not sure if it will be much use to me. But thats a very good price for a year

Link to comment
Share on other sites

Guest asrequested

BTW that code still works.

 

tglifetime50

 

Just tried it and now a yearly VPN service with TorGuard is only $29.99 which is only £22 ish! Not bad!

 

I've just availed myself of that :)

  • Like 1
Link to comment
Share on other sites

  • 10 months later...
rosschesser

Updated list for best VPN in 2018:

 

PIA

Purevpn

Torguard

 

Personally, I would choose PIA coz that's what I've been using up to now. Purevpn is also great but there is a recent scandal about them keeping logs. So many users are also pissed about them, but some are still doing great with purevpn. Torguard also rocks. I haven't used it though. Might try it.

Link to comment
Share on other sites

Guest asrequested

I've now got Torguard running on my pfsense box. And I get higher bandwidth than I did when running the client on the PC.

 

5b1da991437ec_Snapshot_126.jpg

Link to comment
Share on other sites

Sammy

I think it also depends on what it is you want the VPN for.

 

I use one when I'm out and about for public WiFi. I rolled my own OpenVPN server and it works great for that.

 

What did you roll it with?

Link to comment
Share on other sites

Sammy

For anyone considering a VPN provider take this into consideration: https://restoreprivacy.com/vpn-server-locations/. It may or may not matter to you depending on your intended use case. I use Newhosting - it's fast, doesn't use virtual locations from the tests I ran (although I didn't do 100% coverage), and they don't log. I pay $89/yr which likely is not the cheapest solution, but I've been happy with it so far.

 

For those asking questions about setting up openvpn on your router you can update the routing tables to have specific traffic exit out the vpn and the remaining traffic exit normally. For my setup I have a managed switch with many vlans. I added routing rules so any traffic on this vlan exits through the vpn interface and also added a kill switch in the event the vpn is down the packets will be dropped. I have 1 wifi network along with specific ports on my switch that are associated with that vlan. From my knowledge it's not as easy as using a FQDN because when/if the ip changes it will no longer work. You would need some service to automatically update the routing tables if you wanted it to work consistently assuming you are connecting to the vpn for long periods of time during which the ip might change. 

 

Edit: The $89/yr also includes unlimited usenet access and is capable of saturating my bandwidth (150/25mbps).

 

So you set up a routing table and certain outgoing ports get VPN and the rest on the normal ISP?

 

 

Its worth mentioning that the hardware running the VPN client needs to be powerful enough to not impact the speed. This isn't an issue with modern x86 CPUs but is an issue with ARM CPUs found in most routers and Android devices. My Asus RT-AC68U router is not powerful enough to process the OpenVPN encryption fast enough to keep up with my 25 Mbps connection. If I run the client on my PC my bandwidth is not limited by my VPN. You can use less intensive encryption algorithms at the cost of overall security however I would not recommend going as far as using the compromised PPTP VPN over OpenVPN.

 

 

I have an Asus RT-AC3100 that I'm contemplating OpenVPN on. Do you think it'll handle it? I have between 50 and 6 devices but not all need to go through the VPN.

Link to comment
Share on other sites

BAlGaInTl

What did you roll it with?

 

I put it on my same server that is running Emby for me.

 

My fileserver is OpenMediaVault with Emby Running in Docker.  There is an OpenVPN plugin for OMV, but it's pretty easy to set up on any Linux box.

 

I'm not trying to hide anything that I do, just encrypt all traffic when I'm using public WiFi.  Basically, I'm using my home internet when I'm connected to WiFi.

 

I've also used it so that I don't have to open a lot of ports on my server.  Instead, I VPN in to do anything that I need to remotely.  The only ports that are open are for VPN and Emby.  If I need to, I can open ports remotely to do something (FTP, LetsEncrypt, etc) and then close them again.

  • Like 1
Link to comment
Share on other sites

Sammy

I run Emby Server on my Win7Pro HTPC. So it would be better there than on my Asus RT-AC3100 Router? Can it be run on multiple PC's? I have another that does all my media gathering and organizing so I'd need it there.

 

I want to do a couple of things with it..

 

  • Protect Open Ports on my router from VPNFilter malware
  • Run a Connection to YoutubeTV, Netflix and Hulu from out of the country through it (not sure how to do this with, say a Roku or FireTV on a hotel ISP in Mexico for example)
  • Run Emby Server to clients

Any help is appreciated and thank you.

Link to comment
Share on other sites

mwongjay

So you set up a routing table and certain outgoing ports get VPN and the rest on the normal ISP?

 

I created a routing table and routed traffic from a specific subnet through the vpn which made it easy to add/remove clients. It was then simple to create a wifi network for a specific vlan on that subnet and allow any clients connected to that wifi network to exit the vpn. Any traffic not originating from that subnet would exit to my ISP.

 

My main reasons for doing this was to consolidate the number of simultaneous connections. I used to run docker containers and each established a connection to a vpn server so each container experienced overhead for encrypting/decrypting. Additionally, some vpn providers limit the number of simultaneous connections. I created a macvlan network and was able to assign containers an ip from a subnet and have the router handle the processing and consolidated the number of connections.

 

Back when I posted I was running OpenWrt on a tp-link router, but the hardware couldn't keep up so I moved my routing to one of my racked servers running pfsense. My network is still similar though. In pfsense I have 2 simultaneous connections to different vpn servers for redundancy, but still have a subnet that exits through the vpn. 

 

Below are up/down scripts from a backup from awhile ago using openvpn on openwrt. Hopefully that helps.

 

Up script

#!/bin/sh
table=101
subnet=10.0.100.0/24

# log commands for debugging with logread:
logger ip route add default via $ifconfig_local dev $dev table $table
logger ip rule add from $subnet table $table
ip route add default via $ifconfig_local dev $dev table $table
ip rule add from $subnet table $table

iptables -I FORWARD ! -o $dev -s $subnet -j DROP
iptables -I FORWARD -o $dev -j ACCEPT
iptables -t nat -I POSTROUTING -o $dev -j MASQUERADE

ip route flush cache

Down script 

#!/bin/sh
table=101
subnet=10.0.100.0/24

# log commands for debugging with logread:
logger ip route del default via $ifconfig_local dev $dev table $table
logger ip rule del from $subnet table $table
ip route del default via $ifconfig_local dev $dev table $table
ip rule del from $subnet table $table

iptables -D FORWARD -o $dev -j ACCEPT
iptables -t nat -D POSTROUTING -o $dev -j MASQUERADE

ip route flush cache

Link to comment
Share on other sites

  • 2 months later...

It's actually helpful to understand the NEED for the VPN.

 

Do you want this to protect devices you use like your mobile device or do you want it for home use to hide certain types of activity from your ISP or from being tracked back to you?  In this latter case your "origin" client will show up on other servers as having the IP address of the VPN provider vs your real ISP IP address.

 

Keep in mind with either solution only part of the traffic is actually run through the VPN.  It's encrypted up to the point of the VPN server then from there it goes out on the Internet as any other traffic.  The return packets are in the clear back from the destination to the VPN server where it again becomes encrypted.

 

So if your need is the first instance (WIFI protection) then many people can do this for free by running OpenVPN either on their router or on a computer in their house. Since this is mostly web traffic and not download traffic speed isn't normally much of an issue.

 

There are things called seed boxes that can be used off site to do things of questionable intent that people use.  There is also the onion network, Ip2 and other similar networks that are useful to know about and not to just think VPN is some wonderful "security".  Keep in mind a sketchy VPN provider (or employee) has access to everything you run through it.

  • Like 1
Link to comment
Share on other sites

Looking at getting a VPN, so wondered which one people use/prefer.

 

I've been looking at IPVANISH and PRIVATE INTERNET ACCESS (PIA).

 

I'm in the UK, so perhaps UK based VPNs are better?

 

Also, I use DDNS (configured on my router) to access my home services, so are VPNs and DDNS compatible ??

 

All comments are appreciated.

 

Thanks.

A lot of this is going to depend on why you wish to run a vpn. Also yes a vpn and dyna dns will work. 

If you want to simply have access to your home network setting up your own vpn server is a great low / no cost solution.

Myself I run openvpn on my buffalo router which has dd-wrt firmware. I also use no-ip.com for my dynadns. I have openvpn clients set up on all the mobile and semi mobile devices ( mi boxes, ipad, phones and such ). If you want to access the internet and cover your tracks you want to make sure the vpn you subscribe to does not keep logs. No sense in covering your tracks if they can be subpoenaed.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...