Page MenuHomeMiraheze

Look at deploying strongswan (IPSec)
Open, LowPublic


Will require a vm to act as the strongswan server in our US dc. The cps would then use the client functionality to connect. This would allow them to use the private network we have and won't need to use https to connect to the backend and we can look at getting rid of the hostname and using ips direct. We also won't need to use nginx to connect securely to the backend rather varnish will connect directly.

I'm not entirely sure if this will work for us but we should look and see. Strongswan is more performant than https.

Event Timeline

Paladox triaged this task as Low priority.Feb 1 2024, 16:43
Paladox created this task.