Swimminginthought

A place for all things technical and my mind..

Menu
  • About Me / Hire Me
Menu

Encryption type Matters with Deep Packet Inspection – solved

Posted on July 4, 2012 by Percy Kwong

I was helping a client yesterday set up a VPN tunnel only to have it constantly disconnected.  The client was located outside of the country.  For the sake of avoiding throttling and saving on CPU, we were using the Blowfish cipher and it kept on getting disconnected.

I found this rather strange as I’ve never had this problem before.  We’d literally get the client up and running only to find that it was immediately disconnected. This went on for a while (about 15 min.) when the lightbulb went off in my head to try something different. (Lateral Thinking has always been my forte).   I switched the encryption from Blowfish to AES-128.  Surprisingly, it changed everything, the tunnel stayed up and didn’t disconnect.

So apparently some Deep Packet inspection technology has the ability to decrypt on the fly very quickly Blowfish and determine what the contents of the tunnel are.

It didn’t matter what port we were running on.  We tried several different ports prior to this.

So If you’re noticing many random disconnects for no apparent reason (and I’ve set up enough VPN servers in my day to definitely know I didn’t do anything wrong.  Consider changing your encryption to a stronger cipher.  Apparently, it does make a difference.

Total time to figure it out? About 1 hour Tops.

The good thing about the AES cipher is that it’s still considered pretty much unbreakable.  Even by the NSA and their supercomputer at building 5300.

So my recommendation is switch the cipher before switching ports around to see if it makes a difference.

I’m not naming the country or the ISP, but clearly privacy is not high on their list.

It’s two simple changes.

On the OpenVPN server if that’s what you’re using, just uncomment the AES line in /etc/openvpn/server.conf

and on the client, just change the Cipher to  AES-128.  All done.

Obviously issue an openvpn and dnsmasq restart.

For good measure, I always restart the iptables as well.

This should help many people if you’re having constant disconnects with OpenVPN.

Cheers.

 

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • Kubernetes install gotcha on CentOS-7.x
  • Infrastructure as Code using AWS Cloudformation
  • Does SSL matter? It does and it’s not just web encryption.
  • Apache can’t serve the .well-known directory
  • Cloudy with a chance of Meatballs
  • Resurrection of the Blog
  • Encryption type Matters with Deep Packet Inspection – solved
  • Completely off topic.. Just a personal note.

Recent Posts

  • Kubernetes install gotcha on CentOS-7.x
  • Infrastructure as Code using AWS Cloudformation
  • Does SSL matter? It does and it’s not just web encryption.
  • Apache can’t serve the .well-known directory
  • Cloudy with a chance of Meatballs

Recent Comments

  • Percy Kwong on Boosting Octane Yourself. I did the research, made it, and proved it.
  • Nick Doelman on Boosting Octane Yourself. I did the research, made it, and proved it.
  • Percy Kwong on International Text solutions – A solution
  • Muzahid Ul Islam on The Browser Wars; Which One is Best?
  • Muzahid Ul Islam on International Text solutions – A solution

Archives

  • September 2019
  • August 2019
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • August 2011
  • June 2011
  • March 2011
  • February 2011
  • November 2010
  • October 2010
  • September 2010
  • July 2010
  • January 2010
  • November 2009
  • October 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008

Categories

  • Activism
  • All
  • Amazon S3
  • Announcements
  • Apache
  • Apple
  • Applications
  • Automation
  • AWS
  • Azure
  • Backups
  • Blogging
  • Books
  • Bootcamp
  • CentOS – RHEL
  • Cloud Computing
  • Cloudformation
  • Consulting Advice
  • Craigslist
  • Databases
  • Deep Packet Inspection
  • Doing the right thing
  • e-Book Readers
  • E-Mail
  • EC2
  • energy-efficiency
  • environment
  • Expose
  • firewalls
  • General Observations
  • Hardware
  • Hope
  • Hosting
  • IaC
  • Important things to do in life
  • Infrastructure as Code
  • Kubernetes
  • Linux
  • Media and Encoding
  • Miscellany
  • Mobile Phones
  • MySql
  • Networking
  • Performance
  • Personal
  • pfsense
  • Politics
  • Privacy
  • Redundancy
  • Routers
  • security
  • SPAM
  • Tech that doesn't work like it should
  • Tips and Tricks
  • Tools that work
  • Tout
  • Video
  • Virtual Computing
  • VOIP-Voice Over IP
  • VPN
  • Web Browsers
  • Web Hosting
  • Websites
  • Windows
  • Wordpress

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
©2026 Swimminginthought | Built using WordPress and Responsive Blogily theme by Superb