Today I thought of my lack of knowledge. I now wonder whether my system is sufficiently secure.
Openvpn, domoticz and pihole run on the same raspberrypi. It works as desired but I don't know if this setup is safe. In my router only port 1194 (openvpn) to the raspberrypi is open. Fail2ban is also installed on the same raspberrypi with prisons for openvpn and ssh. Fail2ban is working properly.
However, I am now worried about potential risks caused by pihole. My internet traffic now runs through the joint raspberrypi (pihole). I use a strong password for the pihole web interface.
Who can take away my worries?
Thanks in advance
1 rpi + openvpn + Domoticz + pihole > secure???
Moderators: leecollings, remb0
-
Jan Jansen
- Posts: 229
- Joined: Wednesday 30 April 2014 20:27
- Target OS: Raspberry Pi / ODroid
- Domoticz version: Stable
- Location: The Netherlands
- Contact:
-
jake
- Posts: 751
- Joined: Saturday 30 May 2015 22:40
- Target OS: Raspberry Pi / ODroid
- Domoticz version: beta
- Contact:
Re: 1 rpi + openvpn + Domoticz + pihole > secure???
I've exactly the same setup. Pihole is none of your worries, since it's only the middle man retrieving DNS requests. The only real worry is the OpenVPN port, because that one is exposed to the world. A brute force attack on the poor RPI will bring it down, I suppose.Jan Jansen wrote:Today I thought of my lack of knowledge. I now wonder whether my system is sufficiently secure.
Openvpn, domoticz and pihole run on the same raspberrypi. It works as desired but I don't know if this setup is safe. In my router only port 1194 (openvpn) to the raspberrypi is open. Fail2ban is also installed on the same raspberrypi with prisons for openvpn and ssh. Fail2ban is working properly.
However, I am now worried about potential risks caused by pihole. My internet traffic now runs through the joint raspberrypi (pihole). I use a strong password for the pihole web interface.
Who can take away my worries?
Thanks in advance
- gizmocuz
- Posts: 2712
- Joined: Thursday 11 July 2013 18:59
- Target OS: Raspberry Pi / ODroid
- Domoticz version: beta
- Location: Top of the world
- Contact:
Re: 1 rpi + openvpn + Domoticz + pihole > secure???
Hmmm ain't a Synolog nas running openvpn even worse ? (CPU wise ?)
If you keep your system up2date (via unattended-upgrades) I it should be very secure.
But you can also forward a different port then 1194 to openvpn to make it harder to scan
If you keep your system up2date (via unattended-upgrades) I it should be very secure.
But you can also forward a different port then 1194 to openvpn to make it harder to scan
Quality outlives Quantity!
-
Jan Jansen
- Posts: 229
- Joined: Wednesday 30 April 2014 20:27
- Target OS: Raspberry Pi / ODroid
- Domoticz version: Stable
- Location: The Netherlands
- Contact:
Re: 1 rpi + openvpn + Domoticz + pihole > secure???
@ Jake, @ Gizmocuz,
Thanks for the replys.
I conclude that changing the port to a 5-digit number should be sufficient.
Thanks for the replys.
I conclude that changing the port to a 5-digit number should be sufficient.
Who is online
Users browsing this forum: No registered users and 1 guest