What's new

Inbound OpenVPN Server IP address range filter

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

pkcouch

Occasional Visitor
Hello,

I have RT-AX3000 w/Merlin 388.2_2. My use case is a single VPN for a child at college. At one time, I had an old Synology NAS (behind the router) that served as the OpenVPN server. I could restrict the port forwarding to only the IP address range of the college, for security purposes (better than opening it up to the entire world). The Synology NAS has gone away, and I'm configuring the OpenVPN server built into the router.

Question- Is there a way to restrict use of the VPN server to a specified IP address range (like my old Synology setup)? I setup the router's OpenVPN server to require a connection with a certificate and username/password combo. Given that, do I need the inbound IP address range filter, or is it a "don't care" (due to cert/username/password requirement)? Thanks in advance to all the experts here!
 
If you're using certificates for your VPN there's no need to have a firewall filter as well. Just use a non-common port (i.e. not 1194, 443, 8080, etc.) to reduce the "noise" in your syslog from port scanners.
 
To further mitigate the impact of incoming "noise" from scanners or probes trying to figure out who's listening in the opened port, make sure to set the "TLS control channel security" option to either "Bi-directional Auth" or "Encrypt channel" (recommended).

OVPN_Server_TLS_ControlChannelSecurity.jpg


This way, every TLS control channel packet is signed with an HMAC signature (and encrypted if using the recommended setting), even during the initial multi-packet handshake that happens before client authentication can be established. Any incoming packets that don't have the correct signature are dropped immediately.
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Staff online

Top