• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Best secure way to allow remote access to your home in 2023 without getting hacked

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 4 Posters 490 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    Mux 0
    last edited by Mux 0 Aug 2, 2023, 12:21 PM Aug 2, 2023, 12:20 PM

    Sorry for the long topic title but it says it all.

    Whats in 2023 a good and secure practice allowing access to your own home from elsewhere on the internet without getting hacked?

    In the past I have used ssh running on a different non default port with keys and ssh tunnels to my VPN server or just used port forwarding over ssh to access my home stuff.

    But now in 2023 it seems that this is not a good security practice anymore and VPN servers should be used to get into your own LAN/DMZ?

    If a VPN is a better approach these days, should one use Wireguard now instead of OpenVPN?

    Is running Wireguard or OpenVPN on your home pfsense CE router/firewall box a safe and secure option to keep hackers out of your network/pfsense CE box?

    I have been using on and off pfsense for a long time now. A big thank you to all who make pfsense!

    J 1 Reply Last reply Aug 2, 2023, 12:59 PM Reply Quote 0
    • A
      AndyRH
      last edited by Aug 2, 2023, 12:56 PM

      IMO a VPN is the best option. I happen to use WG to an internal server because it can create a QR code which makes client setup easy. There are other ways do do this.

      SSH on any port will be found. If you choose this route be sure you use a key to make it more difficult to hack.

      o||||o
      7100-1u

      J 1 Reply Last reply Aug 2, 2023, 1:01 PM Reply Quote 1
      • J
        JKnott @Mux 0
        last edited by Aug 2, 2023, 12:59 PM

        @Mux-0 I've been running OpenVPN for years. I recently ran Packet Capture over night and saw only 5 attempts. Each had only a single packet, which means they tried and saw nothing. I wouldn't be surprised if I'd seen similar without having OpenVPN available. This indicates OpenVPN is indistinguishable from nothing there. The attacker will try, get no result and then move on.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 1
        • J
          JKnott @AndyRH
          last edited by Aug 2, 2023, 1:01 PM

          @AndyRH said in Best secure way to allow remote access to your home in 2023 without getting hacked:

          SSH on any port will be found

          Yep, a TCP port will respond, even if you can't get past it. A VPN that does not respond to attacks will not reveal itself.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Aug 2, 2023, 2:04 PM

            Yes, use a VPN: https://docs.netgate.com/pfsense/en/latest/recipes/remote-firewall-administration.html#use-a-vpn

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received