Slashdot Mirror


Ask Slashdot: VPN Service For a Deployed US Navy Ship?

shinjikun34 writes "I am currently stationed on a U.S. Navy ship deployed in a country with restrictive internet policies. We are currently in the process of setting up an entertainment internet connection for the crew to use in their downtime. I suggested (and was thereby tasked with finding) a VPN service that would support 100 to 500 devices, have an end point inside the continental United States, be reasonably priced, and secure/trustworthy. Something that is safe to use for banking and other financial affairs. Ideally, it would be fast enough to support several VoIP calls (Skype, Google Voice, etc) along side online gaming, with possible movie/music streaming. It will need an end point in the U.S. to allow for use of Google Books, Netflix, Hulu, and other services that restrict access based on region. I, in all honesty, have no idea where to begin searching, and I ask the good folks of Slashdot to aid me in my quest. One of the main requirements I was given is that the company has to be trustworthy. And it has to be a company — computer in someone's closet hosting a VPN isn't acceptable to the Navy. What services would Slashdot recommend? (I understand that our connection without a VN probably won't be able to handle the described load, but I would prefer a VN service that offers capacity above our need. That way when T/S'ing the connection, the VPN can be at least partially ruled out.)"

5 of 349 comments (clear)

  1. The end point should be run by the military by mrmeval · · Score: 5, Informative

    The NSA is tasked with securing such communication and you should regardless of classification of data be using their equipment or at least an approved system. In that way you know that you at least are protected from your provider.

    Your users shouldn't even know you'd doing jack to their connection except to show as a US IP address. There should be no identifying information that points that IP to any military activity.

    --
    I'd go on a Vegan diet but the delivery time from Vega is too long. --brownkitty
    1. Re:The end point should be run by the military by jittles · · Score: 5, Insightful

      If you read between the lines, the poster is saying that this is an entirely separate network where the crew can bring their personal (non work) systems, and it will have no access or visibility to any of the ships systems or network. As such, those requirements go away.

      I just escaped from the world of contracting for the DoD and I can tell you that there is no such network on any military facility. Trust me. No boat, no ship, not even a storage shed. How do I know? Because I used to work on training simulations, and we wanted to set up things like a private WiFI network, to allow instructors to monitor simulations from a tablet device. Could we do so? No. It's against DoD rules. You can set up a private network, but only if it is wired, and only if it does not go out onto the net. Further, any machine on that network must comply with DoD Information Assurance (IA) rules. Those rules don't let you have USB enabled, you can't even have a USB port accessible on the device, without special authorization and hardening of the OS to disable the port, but allow charging.

      The poster above is absolutely correct. You do not want to be caught setting up this kind of network. You will get in huge trouble if the DoD finds out. All internet access should be going from the ship, to their home port and onto the internet from there. If I were in charge of this boat, I would not do this without an order in writing authorizing me to do so because he's going to get burned if he goes thru with this.

  2. Re:When in Rome ... by ShanghaiBill · · Score: 5, Interesting

    Then respect the laws of that country and don't try to bypass their Internet policies.

    Foreign laws don't apply on an American warship, which are considered US territory. I learned this in a very practical sense many decades ago, when I was on an LPH in the South China Sea. We picked up a load of Vietnamese boat people, including a pregnant women. During the stress of the transfer she went into labor, and the baby was born on the deck of our ship. When we returned to Subic Bay, all the refugees were transferred to a refugee camp. Except the woman and her baby. They were taken to the US Naval Hospital, and then flown to the USA. Since the baby had been born on the deck of an American warship (US Territory) it was an American citizen, not a refugee.

  3. Login, Inc. Tucson AZ by gavron · · Score: 5, Interesting

    We are happy to provide you free VPN termination for your needs. You're welcome to have us
    checked out. US owned, operated, our CEO is the son of a service person, and we support our
    armed forces. Contact sales@login.com and we'll set up whatever GRE/IPSEC/other VPN you
    want.

    Thank you for your service.

    Ehud Gavron
    Login, Inc.
    Tucson AZ US

  4. What an AWESOME TROLL by utkonos · · Score: 5, Insightful

    This article has to be one of the best trolls to have even been done here on Slashdot. Not only did it get the editors to put it on the front page, but it also has most everyone actually taking it seriously.