Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Newbie question re security

    General pfSense Questions
    2
    3
    927
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zippy2016
      last edited by

      Hi all!

      I am thinking about installing pfSense on an extra computer I have here, to use as my router/firewall. at home.  I would like to run an open VPN server, and the LAN will also have a VOIP device for the home.  So I am guessing that I will have to forward ports for the open VPN server and for VOIP.  The open VPN server would use certificates as well as a user password, and if possible, I would restrict traffic to the VOIP device to only allow the server address of the VOIP provider I use.

      I am pretty new to networking, and I wanted to find out what people thought about the realistic security risk of opening these ports in the router. By forwarding these ports, is it possible for someone to get into my LAN and wreak havoc?  What would they have to do to do that?  Are there any other protections I should add on?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Are you currently using voip??

        How are they getting into your lan, through your voip phone?  If your worried put your voip device on its own network segment.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • Z
          zippy2016
          last edited by

          I am currently using VOIP.  It is set up on my LAN behind my (off the shelf) D-link router.  As far as I know, nobody has has invaded my network - this was more of a theoretical question, as I pondered whether there might be a security vulnerability in my network (i.e. could someone take over my VOIP device and use it to launch an attack on other devices in my LAN?).  Would it be considered best practice to run the VOIP on its own vlan or is that overkill?

          And also for open VPN - this was also theoretical - how difficult would it be for someone to penetrate through that hole if I used 2048 or 4096 bit keys, and combined it with user authentication?

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.