PPTP/OpenVPN/L2TP - which one do you prefer?

I am going to need to deploy a VPN service on a machine. There is no big need for security and overall I am thinking of using PPTP as it supports most systems and is easy to setup. However, many sites recommend OpenVPN. What’s your choice?

EDIT: thanks everyone for the replies! I will use OpenVPN both for the security issues with PPTP, speed/security ratio and the fact that it works under 1 port, 1 protocol, not like PPTP or IPSec…

OpenVPN works best for me. Speed, ease of use, and broad platform support. Bypasses most public wifi/networks where they will block PPTP/L2TP.

Pptp in many implementations has security issues, fairly big ones. You’d only use it if you didn’t have time or skill to implement IPSec/L2TP and if you wanted a vpn that used the built in client in most OSs rather than downloading a client tool. If you’re happy with a client tool (and it’s real easy these days), I’d use openvpn in a flash.

OpenVPN.

Very easy to setup and use, very easy to make secure, exceedingly good performance.

openvpn.

from wikipedia: “PPTP is considered cryptographically broken and its use is no longer recommended by Microsoft.”

i’m not saying you shouldn’t use pptp. but what will your answer be when “some dude from the office” asks you why you chose an insecure, outdated, non-recommended solution for your client?

I wish OpenVPN was supported by iOS. I have dd-wrt on my router and setup a pptp VPN. I use it rarely because I know it’s not secure. I also don’t have a machine at home that’s always on so setting up a VPN like L2TP isn’t really an option.

My vote is for OpenVPN.

OpenVPN has great multi-platform clients.

I’m curious if anyone has tried SSTP VPN server/client such as SoftEther VPN.

PPTP because I work with… less-than-skilled users. Many compromises are made, this is but one.

OpenVPN for mobile users, l2tp\IPSec for site to site

Did you use a guide to get it set up? I’ve tried twice and failed both times.

Great point. PPTP should be avoided if you care about security. I have run PPTP with no encryption for more of a tunnel in situations where firewall and proxies are issues.

It’s not as convenient as being part of the OS natively, but have you seen/used the OpenVPN iOS app? It works pretty well.

I’ve just tried OpenVPN. I have to say - it’s super easy to use. All your users need to do (on Windows) is to install OpenVPN client, get the ovpn file from you, double click it and connect! You can distribute login certificates in one file with the whole configuration, which makes it super easy to maintain :slight_smile: .

What OS? Hardest part is the easy_rsa for certs. Ubutnu has a decent guide if memory serves for general guidance

have run PPTP with no encryption for more of a tunnel in situations where firewall and proxies are issues.

I have vpn on my phone to connect to home network and when I am on my work’s wifi the only vpn that I can get to work is the pptp no encryption. Why is that? Its a cisco based wireless system/controller and goes through a sonicwall with minimal filtering. I talked to the sonic wall guy but he didn’t know. The public wireless AP we send out pretty much unfiltered. I was suggested to go through the internal network AP but I am trying to avoid that for personal reasons.

I just don’t understand why only a non-encrypted vpn would pass. *puts on tinfoil hat.

Second this. The app works great.

I just downloaded it. Does it actually send all iPhone traffic through the VPN?

What instructions did you use to setup OpenVPN?

Using window or linux vm for setup but installing vpn server on dd-wrt modded net gear wndr3700

Depends on the vpn config but it is possible.