Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    help with forwarding for home assistant

    Scheduled Pinned Locked Moved Firewalling
    51 Posts 6 Posters 11.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tman904 @johnpoz
      last edited by

      @johnpoz I agree.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Its not the "encryption" so much as the more secure auth... To auth to vpn - you would need a cert, issues by you.. Same with ssh - you can require public key auth..

        These are almost impossible to "brute force" auth.. And way less likely to have some other form of exploit that could allow some user to gain access do some other exploit.

        If I can access the http/https service - while it might ask for a username password, those could "guessed" or possible some sort of exploit that could be used to bypassed this auth in the service. This is highly unlikely in something like a vpn or ssh.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • wgstarksW
          wgstarks
          last edited by

          I’m testing using OpenVPN. It works fairly well. I’ve only found one app that’s fails to connect when vpn is activated on my phone. Currently I can only connect to the OpenVPN server over WAN which causes some extra battery drain when I’m connected to my LAN network but not really enough to be an issue.

          Box: SG-4200

          T 1 Reply Last reply Reply Quote 0
          • T
            tman904
            last edited by tman904

            @Johnpoz Very good point, encryption just hides information doesn't mean that machine is authorized to connect and freely access the servers information just because its using an encrypted connection.

            1 Reply Last reply Reply Quote 0
            • T
              tman904 @wgstarks
              last edited by

              @wgstarks That's great news glad to hear you got it to working.

              1 Reply Last reply Reply Quote 0
              • wgstarksW
                wgstarks
                last edited by

                Is it possible to allow the OpenVPN client on my phone to connect to the OpenVPN server running on my pfsense appliance when connecting from LAN? I don’t know enough about this to know if that would even be a good idea?

                Box: SG-4200

                1 Reply Last reply Reply Quote 0
                • T
                  tman904
                  last edited by

                  Your LAN or some other LAN?

                  wgstarksW 1 Reply Last reply Reply Quote 0
                  • wgstarksW
                    wgstarks @tman904
                    last edited by

                    @tman904 said in help with forwarding for home assistant:

                    Your LAN or some other LAN?

                    My LAN network.

                    Box: SG-4200

                    T 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      While you can do that - it can be problematic.. Because your on the same network as what your trying to access via the vpn, etc. There is little advantage to doing such a thing.. Just click the vpn on when your remote and you need to do something with your automation system... To be honest - how often would that even be?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      wgstarksW 1 Reply Last reply Reply Quote 1
                      • T
                        tman904 @wgstarks
                        last edited by

                        @wgstarks I would only connect to the VPN when somewhere outside my LAN. Reason being is when your inside of your LAN you already have access to every route/network. When outside of it the VPN creates a virtual tunnel network that allows your device to route to the networks inside your LAN even though your not physical there.

                        1 Reply Last reply Reply Quote 1
                        • wgstarksW
                          wgstarks @johnpoz
                          last edited by

                          @johnpoz said in help with forwarding for home assistant:

                          While you can do that - it can be problematic.. Because your on the same network as what your trying to access via the vpn, etc. There is little advantage to doing such a thing.. Just click the vpn on when your remote and you need to do something with your automation system... To be honest - how often would that even be?

                          I haven’t been able to get an exact time schedule for this but it’s every few minutes (and push notifications can happen at any time). I just leave the OpenVPN activated. The settings for the OpenVPN client on my iPhone warn that setting the app to continuously attempt to re-connect may cause increased battery drain but honestly it doesn’t seem to be enough to notice.

                          Box: SG-4200

                          1 Reply Last reply Reply Quote 0
                          • JeGrJ
                            JeGr LAYER 8 Moderator
                            last edited by

                            Are you using OpenVPN Connect on iOS by any chance?

                            Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                            wgstarksW 1 Reply Last reply Reply Quote 0
                            • wgstarksW
                              wgstarks @JeGr
                              last edited by

                              @JeGr said in help with forwarding for home assistant:

                              Are you using OpenVPN Connect on iOS by any chance?

                              Yes

                              Box: SG-4200

                              1 Reply Last reply Reply Quote 0
                              • JeGrJ
                                JeGr LAYER 8 Moderator
                                last edited by

                                Perhaps take a look at https://passepartoutvpn.app/

                                As I don't use apple devices myself I got the hint from one of the more tech-affine people of my german speaking section, that hinted, it can selectively activate the VPN only if you're not at home e.g. you define trusted wifi networks etc.

                                So if you really do like/need to have VPN always on when NOT at home, you could take a look at that client and try it out as it should have more features that could come in handy.

                                Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                                If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                                1 Reply Last reply Reply Quote 1
                                • wgstarksW
                                  wgstarks
                                  last edited by

                                  Thanks

                                  Box: SG-4200

                                  1 Reply Last reply Reply Quote 0
                                  • wgstarksW
                                    wgstarks
                                    last edited by

                                    I installed the Passeportout VPN app. Seems to work fairly well (really too soon to be sure). The app is free but some features (including trusted networks and pre-configured VPN providers) require a small one-time fee.

                                    Box: SG-4200

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      @wgstarks said in help with forwarding for home assistant:

                                      Passeportout VPN app

                                      Why? Just use the FREE app from openvpn
                                      https://apps.apple.com/us/app/openvpn-connect/id590379981

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      wgstarksW 1 Reply Last reply Reply Quote 0
                                      • wgstarksW
                                        wgstarks @johnpoz
                                        last edited by

                                        @johnpoz said in help with forwarding for home assistant:

                                        @wgstarks said in help with forwarding for home assistant:

                                        Passeportout VPN app

                                        Why? Just use the FREE app from openvpn
                                        https://apps.apple.com/us/app/openvpn-connect/id590379981

                                        No support for trusted networks. That was the primary reason for the switch.

                                        Box: SG-4200

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          Trusted networks does what exactly? Clicking connect or not seems pretty much like a FREE option to me.. But if you want to pay $ for that - ok..

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          wgstarksW 1 Reply Last reply Reply Quote 0
                                          • wgstarksW
                                            wgstarks @johnpoz
                                            last edited by

                                            @johnpoz said in help with forwarding for home assistant:

                                            Trusted networks does what exactly? Clicking connect or not seems pretty much like a FREE option to me.. But if you want to pay $ for that - ok..

                                            That doesnt fit my particular use case though. I’m sure I would forget to click connect when leaving my house or forget to click disconnect when I got home. That’s why Passepartout was recommended.

                                            Box: SG-4200

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.