Open Port to pfSense XG-1541 (Separate Router)
-
I use a UniFi Dream Machine Pro as my primary router and have a pfSense/Netgate XG-1541 serving as an OpenVPN server. I'm forwarding a UDP port to the IPv4 address of the XG-1541.
It's worked flawlessly over the past few years (except for being able to do OpenVPN over IPv6, but that's another story).
Recently, I've become concerned about security. I currently do not run the built-in firewall of the pfSense box since the UDMP is my router. The XG-1541 is connected via a static IP address on one of its LAN ports.
What is the best way to keep someone from hacking into the XG-1541 and access other devices on my home network?
If someone were to type my VPN hostname or IP address with the port number added on, what features can they access on the XG-1541?