Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Secure VPN server in Homenet and access

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 411 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      paoloest
      last edited by

      Hey all,

      i Have a pfsense that is my wan Gateway and connected via modem (pppoe) to the isp. In my homenet their are two Sophos firewalls managing my subnets with a separate openvpn server in every subnet.

      Basically I have a bad feeling opening ports and forward it to my protected homenet. So is there a more secure way to establish a vpn connection to my homenet from the outside? (Maybe a question regarding the basic security concept)

      I am currently thinking in getting rid of the openvpn servers and directly connect to the Sophos firewalls creating an own dmz and just routing very basic stuff like home automation

      Thanks a lot for sharing your thought

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        More secure than opening a port to an OpenVPN server? That server is using certs and a TLS key I assume? And forwarding from a non-standard port?

        Then not really!

        Steve

        1 Reply Last reply Reply Quote 0
        • P
          paoloest
          last edited by

          Cert, Tls and non standard port is configured.

          I thought the the machine (in my case a raspberry pi until I have faster internet) is attachable as has more weak points then a firewall for example (unattended updates are activated)

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            You are only opening one port so you're exposing only the service listening on that port. The RasPi could have everything open but nothing is going to reach it except what you're forwarding.

            Steve

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.