I like openVPN, it is a cool piece of software :)
For years I've been reading this list. Always a good source for great info, thanks!

Today I am asking for your advice.
I need to grant access to one machine to an user who is able to use a terminal. The whole net is a small one without the need for openvpn to manage it since now. I am thinking about giving this single use the possibility to connect to the machine (running in DMZ) via ssh access, dnatted over the public internet. The sshd will be kept updated (arch linux as os). Auth will be made using public/private cert.

What do you think?


