mirror of
https://git.FreeBSD.org/ports.git
synced 2025-01-04 06:15:24 +00:00
eba97ed57a
PR: 239577 Submitted by: Mikael Urankar <mikael.urankar@gmail.com>
21 lines
1.0 KiB
Plaintext
21 lines
1.0 KiB
Plaintext
OpenConnect server (ocserv) is an SSL VPN server. Its purpose is
|
|
to be a secure, small, fast and configurable VPN server. It implements
|
|
the OpenConnect SSL VPN protocol, and has also (currently experimental)
|
|
compatibility with clients using the AnyConnect SSL VPN protocol.
|
|
The OpenConnect protocol provides a dual TCP/UDP VPN channel, and
|
|
uses the standard IETF security protocols to secure it. Both IPv4
|
|
and IPv6 are supported.
|
|
|
|
Ocserv's main features are security through privilege separation
|
|
and sandboxing, accounting, and resilience due to a combined use
|
|
of TCP and UDP. Authentication occurs in an isolated security
|
|
module process, and each user is assigned an unprivileged worker
|
|
process, and a networking (tun) device. That not only eases the
|
|
control of the resources of each user or group of users, but also
|
|
prevents data leak (e.g., heartbleed-style attacks), and privilege
|
|
escalation due to any bug on the VPN handling (worker) process. A
|
|
management interface allows for viewing and querying logged-in
|
|
users.
|
|
|
|
WWW: https://ocserv.gitlab.io/www/index.html
|