So if it works fine without DMZ, something is doing the port forwarding for you and you don't know what.
@elorimer you're saying to NOT have OpenVpn run on default port 1194?
Oh no no.. I was just saying I think the UpnP may be used for that purpose.. I have smart bulbs and fans, power outlets... all work great.. makes us very lazy by controlling everything with our smartphones instead of just walking to the device and turning it offModems only don't have firewalls. They are bridges, the router gets the external IP from ISP DHCP. I don't have any "smart" bulbs. I can't help you with this technology.
Below 1024 is assigned by IANA and you can't use. 1024 up to 65535 is available unless something else is using it, in which case the VPN server won't start.can I make up my own set of numbers and if so, how long can they be?
Set up a guest network for those IoT things so they don't have access to your LAN, period.I have smart bulbs and fans, power outlets... all work great.. makes us very lazy by controlling everything with our smartphones instead of just walking to the device and turning it off
And looking at the log every morning.
if an attacker can just go in once they find an open port
Here is my old logs, this happen when I use standard port 1194. During that time I keep getting this errors from different source IP, whether they are just do port scanning or trying to break in. Following the forum advice, I have change to other ports and don't see such logs anymore. By the way, I don't see the logs every morning.I know this post has been very long.. just last question on this...if an attacker can just go in once they find an open port.. what's the point of having a username and password on the vpn?
Dec 6 05:45:21 openvpn[2588]: 185.200.118.83:38289 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Dec 6 05:45:21 openvpn[2588]: 185.200.118.83:38289 TLS Error: TLS handshake failed
Dec 6 07:28:48 openvpn[2588]: 167.248.133.22:53448 TLS: Initial packet from [AF_INET]167.248.133.22:53448, sid=4d658221 07fcfd52
Dec 6 07:29:04 openvpn[2588]: 167.248.133.39:50915 TLS: Initial packet from [AF_INET]167.248.133.39:50915, sid=00136074 dae9ce00
Dec 6 07:29:48 openvpn[2588]: 167.248.133.22:53448 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Dec 6 07:29:48 openvpn[2588]: 167.248.133.22:53448 TLS Error: TLS handshake failed
Dec 6 07:30:04 openvpn[2588]: 167.248.133.39:50915 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Dec 6 07:30:04 openvpn[2588]: 167.248.133.39:50915 TLS Error: TLS handshake failed
Dec 6 11:17:37 openvpn[2588]: 146.88.240.4:53722 TLS: Initial packet from [AF_INET]146.88.240.4:53722, sid=12121212 12121212
Dec 6 11:18:37 openvpn[2588]: 146.88.240.4:53722 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Dec 6 11:18:37 openvpn[2588]: 146.88.240.4:53722 TLS Error: TLS handshake failed
I dust it and straighten its antennas every morning too. Make sure its power is nice and clean.By the way, I don't see the logs every morning.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!