Announcement

Collapse
No announcement yet.

Time to setup a VPN

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Time to setup a VPN

    So I'm thinking that it might be time to setup VPN access to my network. I'm starting to migrate my business server to linux and I find myself poking an awful lot of holes in my firewall to access files and such on the go. I also recently dumped windows phone for a galaxy so 10200 is yet another port I have to open for hstouch.

    Current network infrastructure: TP-link TL-ER6120 router primary domain controller sbs-2011, backup domain controller Zentyal server. Trying to replace sharepoint with alfresco. sbs-2011 is running on a dedicated hp microserver (under powered). Zentyal, alfresco, freenas all running as virtual machines (virtualbox on ubuntu on a HP ml350G6 24 cores, 48Gig memory). Homeseer is running on a dedicated quad core which also runs blueiris with a blue cherry capture card.

    It looks like I can setup vpn either in the router, the sbs2011, or zentyal. Or I could ditch the router and use the dual nics available to zentyal. Not sure which way would be better/more secure. Other than the exchange server, I'm the only one that currently needs access to my network resources when mobile and then really only from my phone.

    Any advice would be appreciated.
    https://forums.homeseer.com/forum/de...plifier-plugin

    #2
    I'd go with the router and use a ddns client so that no matter what you can always call home..unless the router is unreliable...

    Comment


      #3
      Teamviewer?
      Mike____________________________________________________________ __________________
      HS3 Pro Edition 3.0.0.548, NUC i3

      HW: Stargate | NX8e | CAV6.6 | Squeezebox | PCS | WGL 800RF | RFXCOM | Vantage Pro | Green-Eye | Edgeport/8 | Way2Call | Ecobee3 | EtherRain | Ubiquiti

      Comment


        #4
        Here utilize PFSense (free) / IPSec with multiple Intel Gb WAN and LAN interfaces these days.

        PFSense does also support openVPN (SSL) such that you can do that too.

        You can do one of these for free (this was a project many years ago and it is still utilized today).

        SSL Network Extender
        Attached Files
        Last edited by Pete; March 30, 2016, 09:24 AM.
        - Pete

        Auto mator
        Homeseer 3 Pro - 3.0.0.548 (Linux) - Ubuntu 18.04/W7e 64 bit Intel Haswell CPU 16Gb

        HS4 Pro - Ubuntu 22.04 / Lenova Tiny M900 / 32Gb Ram
        HSTouch on Intel tabletop tablets (Jogglers) - Asus AIO - Windows 11

        X10, UPB, Zigbee, ZWave and Wifi MQTT automation-Tasmota-Espurna. OmniPro 2, Russound zoned audio, Alexa, Cheaper RFID, W800 and Home Assistant

        Comment


          #5
          For extreme security and all that above consider using VLANs. Check out this guy's videos for inspiration: https://www.youtube.com/watch?v=xI2c3G3vMOs
          You don't have to do all what he did but throw in a VLAN capable switch and or router and play his game. Your router already seems to be VLAN capable. Consult your manual.
          For more on set up tips check out more videos from this guy: https://www.youtube.com/watch?v=Rdw46zhn17E


          Eman.
          TinkerLand : Life's Choices,"No One Size Fits All"

          Comment


            #6
            Thank you for all your responses and suggestions, I setup a pptp vpn on my tp-link router and I'm able to connect from my new android phone when I'm out and about to local addresses on my network such as HSTouch. However the problem I am having is that sometimes I find I am unable to connect to internet web sites, such as the this forum, until I disconnect from the vpn.

            Is this typical of a vpn? do you guys connect to your vpn, run hstouch, then disconnect from your vpn?
            https://forums.homeseer.com/forum/de...plifier-plugin

            Comment


              #7
              Just a short paragraph relating to using PPTP VPN.

              PPTP is no longer considered a secure VPN technology because it relies upon MS-CHAPv2 which has been compromised. If you continue to use PPTP be aware that intercepted traffic can be decrypted by a third party, so it should be considered unencrypted. We advise migrating to another VPN type such as OpenVPN or IPsec.
              - Pete

              Auto mator
              Homeseer 3 Pro - 3.0.0.548 (Linux) - Ubuntu 18.04/W7e 64 bit Intel Haswell CPU 16Gb

              HS4 Pro - Ubuntu 22.04 / Lenova Tiny M900 / 32Gb Ram
              HSTouch on Intel tabletop tablets (Jogglers) - Asus AIO - Windows 11

              X10, UPB, Zigbee, ZWave and Wifi MQTT automation-Tasmota-Espurna. OmniPro 2, Russound zoned audio, Alexa, Cheaper RFID, W800 and Home Assistant

              Comment


                #8
                Thanks Pete,

                I tried pptp first because it is supposed to be faster, but I'll try ipsec and see if I get the same results.
                https://forums.homeseer.com/forum/de...plifier-plugin

                Comment


                  #9
                  So it looks like I have the option of setting up a greenbow ipsec vpn or a shrew soft ipsec vpn according to my router manual. Whats the difference?

                  And my question remains, under normal usage do you have to connect to your vpn, then run hstouch, then disconnect from your vpn?

                  Thanks in advance for everyones help with this.
                  https://forums.homeseer.com/forum/de...plifier-plugin

                  Comment


                    #10
                    I have only utilized shrew soft ipsec.

                    That said it is up to you what you want to use. Try them both and see which fits the best.

                    do you have to connect to your vpn, then run hstouch, then disconnect from your vpn?

                    Yes.

                    Here when travelling now only use my at home PFSense firewall. That is me.
                    - Pete

                    Auto mator
                    Homeseer 3 Pro - 3.0.0.548 (Linux) - Ubuntu 18.04/W7e 64 bit Intel Haswell CPU 16Gb

                    HS4 Pro - Ubuntu 22.04 / Lenova Tiny M900 / 32Gb Ram
                    HSTouch on Intel tabletop tablets (Jogglers) - Asus AIO - Windows 11

                    X10, UPB, Zigbee, ZWave and Wifi MQTT automation-Tasmota-Espurna. OmniPro 2, Russound zoned audio, Alexa, Cheaper RFID, W800 and Home Assistant

                    Comment


                      #11
                      Originally posted by Pete View Post
                      I have only utilized shrew soft ipsec.



                      do you have to connect to your vpn, then run hstouch, then disconnect from your vpn?

                      Yes.
                      Thanks again Pete, this being the case I think I need to re-think my approach, that's just too many presses on my phone to set the house to away mode.
                      https://forums.homeseer.com/forum/de...plifier-plugin

                      Comment


                        #12
                        Yeah that seems a little cumbersome. Also if you use some type of ping sensor for occupancy it would fall over in the VPN scenario I'm imagining.
                        Originally posted by rprade
                        There is no rhyme or reason to the anarchy a defective Z-Wave device can cause

                        Comment


                          #13
                          If you just turned on VPN mode to your home network then your phone internet/data connection would only utilize your home internet and firewall.

                          You can leave the VPN tunnel up or enabled.

                          I have not noticed much speed differences. Try it yourself. VPN to your home network.

                          VPN ON = Phone ==VPN==> home firewall ==> home network (direct connect to HS mothership) ==> firewall-gateway => internet ==> do a speedtest
                          VPN OFF = Phone ==> internet ==> do a speedtest


                          Do a speed test on the telephone browser and compare the difference between the VPN connection on or off.

                          Check your email, facebook, twitter, et al. You shouldn't notice much of a difference.

                          The bottleneck is just your GSM or LTE data connection and home internet connection (up or down).
                          - Pete

                          Auto mator
                          Homeseer 3 Pro - 3.0.0.548 (Linux) - Ubuntu 18.04/W7e 64 bit Intel Haswell CPU 16Gb

                          HS4 Pro - Ubuntu 22.04 / Lenova Tiny M900 / 32Gb Ram
                          HSTouch on Intel tabletop tablets (Jogglers) - Asus AIO - Windows 11

                          X10, UPB, Zigbee, ZWave and Wifi MQTT automation-Tasmota-Espurna. OmniPro 2, Russound zoned audio, Alexa, Cheaper RFID, W800 and Home Assistant

                          Comment

                          Working...
                          X