• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Secure VPN server in Homenet and access

Scheduled Pinned Locked Moved General pfSense Questions
4 Posts 2 Posters 409 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    paoloest
    last edited by Mar 7, 2019, 10:11 PM

    Hey all,

    i Have a pfsense that is my wan Gateway and connected via modem (pppoe) to the isp. In my homenet their are two Sophos firewalls managing my subnets with a separate openvpn server in every subnet.

    Basically I have a bad feeling opening ports and forward it to my protected homenet. So is there a more secure way to establish a vpn connection to my homenet from the outside? (Maybe a question regarding the basic security concept)

    I am currently thinking in getting rid of the openvpn servers and directly connect to the Sophos firewalls creating an own dmz and just routing very basic stuff like home automation

    Thanks a lot for sharing your thought

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Mar 9, 2019, 12:56 AM

      More secure than opening a port to an OpenVPN server? That server is using certs and a TLS key I assume? And forwarding from a non-standard port?

      Then not really!

      Steve

      1 Reply Last reply Reply Quote 0
      • P
        paoloest
        last edited by Mar 9, 2019, 6:32 AM

        Cert, Tls and non standard port is configured.

        I thought the the machine (in my case a raspberry pi until I have faster internet) is attachable as has more weak points then a firewall for example (unattended updates are activated)

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Mar 9, 2019, 12:44 PM

          You are only opening one port so you're exposing only the service listening on that port. The RasPi could have everything open but nothing is going to reach it except what you're forwarding.

          Steve

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received