How do I configure the server side of a Linux Debian Openswan VPN?

What are the advantages and disadvantages of different VPN configuration options?

How can I prevent attacks against data in transit using a properly configured VPN?

