• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Port forwarding with vpn

Scheduled Pinned Locked Moved OpenVPN
15 Posts 4 Posters 1.6k Views 4 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    spospo
    last edited by Sep 25, 2019, 12:40 PM

    Thanks for your quick answer,

    yes I'd like to access outside my home to my server which has nordvpn connected 24/7

    So what you advise me to do if it's not possible ?

    1 Reply Last reply Reply Quote 0
    • R Offline
      Rico LAYER 8 Rebel Alliance
      last edited by Rico Sep 25, 2019, 12:44 PM Sep 25, 2019, 12:44 PM

      You don't need any VPN provider for this, just run your own OpenVPN RAS with pfSense.
      Check out https://docs.netgate.com/pfsense/en/latest/book/openvpn/using-the-openvpn-server-wizard-for-remote-access.html

      -Rico

      1 Reply Last reply Reply Quote 1
      • S Offline
        spospo
        last edited by Sep 25, 2019, 12:48 PM

        ok I'll try it, but can I have nordvpn and my own openvpn at the same time ?

        1 Reply Last reply Reply Quote 0
        • J Offline
          JeGr LAYER 8 Moderator
          last edited by Sep 25, 2019, 12:50 PM

          @spospo said in Port forwarding with vpn:

          ok I'll try it, but can I have nordvpn and my own openvpn at the same time ?

          Why would they meddle with each other? If you dial in to your Home IP to access your LAN just make sure you don't force all exiting traffic to NordVPN but let the RAS tunnel network out via default GW and you should be good.

          Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

          If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

          1 Reply Last reply Reply Quote 0
          • S Offline
            spospo
            last edited by Sep 25, 2019, 12:56 PM

            I'm not familiar with that. I wan't the best security that's it.
            So I don't want to connect without a vpn.

            if I'm right
            at home when I use internet It's through nord vpn,
            outside if I connect to my server I use my own openvpn, which give me the same network address, so I can connect to my server ? without any change on pfsense ?

            1 Reply Last reply Reply Quote 0
            • J Offline
              JeGr LAYER 8 Moderator
              last edited by JeGr Sep 25, 2019, 1:02 PM Sep 25, 2019, 1:02 PM

              @spospo said in Port forwarding with vpn:

              I wan't the best security that's it.

              So why do you route all your traffic through some shady VPN company? I'd not call that secure per se.

              So I don't want to connect without a vpn

              You would be using your own VPN? What's the problem with that?

              outside if I connect to my server I use my own openvpn, which give me the same network address, so I can connect to my server ? without any change on pfsense ?

              No you won't connect to your server but start your OVPN client, dial-in to your home and then start a connection to your server's LAN IP. Only thing to that is that the dial-in IP space you define in the OVPN setup should be excluded from routing through your NordVPN thingy so the answer-traffic from your server will flow back through your own VPN connection instead of be routed to some NordVPN server anywhere.

              Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

              If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

              S 2 Replies Last reply Sep 25, 2019, 1:11 PM Reply Quote 0
              • S Offline
                spospo @JeGr
                last edited by Sep 25, 2019, 1:11 PM

                @JeGr said in Port forwarding with vpn:

                So why do you route all your traffic through some shady VPN company? I'd not call that secure per se.

                You advise what ? my own vpn on a dedicated server/vps ?

                @JeGr said in Port forwarding with vpn:

                So I don't want to connect without a vpn

                I mean for seeing website.....

                1 Reply Last reply Reply Quote 0
                • J Offline
                  JeGr LAYER 8 Moderator
                  last edited by Sep 25, 2019, 1:21 PM

                  @spospo said in Port forwarding with vpn:

                  You advise what ? my own vpn on a dedicated server/vps ?

                  Depends on the circumstances. But security? Really? What for exactly? Watching Netflix in other countries etc. -> OK VPN is useful. Sitting in some open WiFi without even the slightest security? Hell yeah VPN (but normally my own). But what do I need a VPN for in terms of "security"? Privacy I'd get - at least partially - but even then, of you want privacy TOR is the better alternative than decrypting your whole traffic an send it to some marketing bullshit company that then decrypts your traffic and send it on it's way. So they know the same/more then your ISP from you. Potentially more, because you would also send DNS over that tunnel, so that company knows what (DNS) you are looking for and when/how you call it and how long. If you ran DNS over pfSense and the DNS resolver it would then resolve every domain at its server (e.g. the server that is authoritative). And if you're curious about your ISP sniffing DNS you could also use an external DNS forwarding via DoT to some other provider which then would only know your DNS queries. Not your complete ISP traffic. It comes down to trust and if you don't trust your ISP at least with something, then why do you trust a strange company that plays marketing bullshit bingo with buzzwords and wants money from you to route your complete traffic? What makes them the "good guys" that will definetly fight for your right for security and privacy?

                  But yeah we discussed that in quite some topics already. Don't want to go off-topic, but if I read security with some low cost super-duper VPN providers that advertise "military grade security"... ;) Was just curious.

                  Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                  If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    spospo @JeGr
                    last edited by Sep 25, 2019, 1:35 PM

                    @JeGr said in Port forwarding with vpn:

                    No you won't connect to your server but start your OVPN client, dial-in to your home and then start a connection to your server's LAN IP. Only thing to that is that the dial-in IP space you define in the OVPN setup should be excluded from routing through your NordVPN thingy so the answer-traffic from your server will flow back through your own VPN connection instead of be routed to some NordVPN server anywhere.

                    That's it ! I'll try this

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      spospo
                      last edited by Sep 25, 2019, 1:49 PM

                      I use dns from 9.9.9.9

                      J 1 Reply Last reply Sep 25, 2019, 3:13 PM Reply Quote 0
                      • J Offline
                        JeGr LAYER 8 Moderator @spospo
                        last edited by Sep 25, 2019, 3:13 PM

                        @spospo Ah so you even let your domains be read-out and blocked by blocklists not managed by you but another agency? For security? ;)

                        @spospo said in Port forwarding with vpn:

                        That's it ! I'll try this

                        Just try to setup a RAS/road warrior style OVPN setup either via wizard or docs.netgate.com - should work pretty smooth :)

                        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          spospo
                          last edited by Sep 26, 2019, 1:00 PM

                          Thx, I'm working on it ☺

                          1 Reply Last reply Reply Quote 0
                          • W Offline
                            william333
                            last edited by Sep 30, 2019, 11:18 AM

                            VPNs utilize port sending administrations too. Much the same as your switch turns into the interface between your PC and the web and doesn't give the PC a chance to contact the web legitimately, VPN servers additionally utilize port sending to ensure a customer doesn't cooperate straightforwardly with the web.

                            1 Reply Last reply Reply Quote 0
                            15 out of 15
                            • First post
                              15/15
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received