1 rpi + openvpn + Domoticz + pihole > secure???

Topics (not sure which fora)
when not sure where to post, post here and mods will move it to right forum.

Moderators: leecollings, remb0

Post Reply
Jan Jansen
Posts: 229
Joined: Wednesday 30 April 2014 20:27
Target OS: Raspberry Pi / ODroid
Domoticz version: Stable
Location: The Netherlands
Contact:

1 rpi + openvpn + Domoticz + pihole > secure???

Post by Jan Jansen »

Today I thought of my lack of knowledge. I now wonder whether my system is sufficiently secure.

Openvpn, domoticz and pihole run on the same raspberrypi. It works as desired but I don't know if this setup is safe. In my router only port 1194 (openvpn) to the raspberrypi is open. Fail2ban is also installed on the same raspberrypi with prisons for openvpn and ssh. Fail2ban is working properly.

However, I am now worried about potential risks caused by pihole. My internet traffic now runs through the joint raspberrypi (pihole). I use a strong password for the pihole web interface.

Who can take away my worries?

Thanks in advance
jake
Posts: 751
Joined: Saturday 30 May 2015 22:40
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Contact:

Re: 1 rpi + openvpn + Domoticz + pihole > secure???

Post by jake »

Jan Jansen wrote:Today I thought of my lack of knowledge. I now wonder whether my system is sufficiently secure.

Openvpn, domoticz and pihole run on the same raspberrypi. It works as desired but I don't know if this setup is safe. In my router only port 1194 (openvpn) to the raspberrypi is open. Fail2ban is also installed on the same raspberrypi with prisons for openvpn and ssh. Fail2ban is working properly.

However, I am now worried about potential risks caused by pihole. My internet traffic now runs through the joint raspberrypi (pihole). I use a strong password for the pihole web interface.

Who can take away my worries?

Thanks in advance
I've exactly the same setup. Pihole is none of your worries, since it's only the middle man retrieving DNS requests. The only real worry is the OpenVPN port, because that one is exposed to the world. A brute force attack on the poor RPI will bring it down, I suppose.
User avatar
gizmocuz
Posts: 2712
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: 1 rpi + openvpn + Domoticz + pihole > secure???

Post by gizmocuz »

Hmmm ain't a Synolog nas running openvpn even worse ? (CPU wise ?)
If you keep your system up2date (via unattended-upgrades) I it should be very secure.
But you can also forward a different port then 1194 to openvpn to make it harder to scan
Quality outlives Quantity!
Jan Jansen
Posts: 229
Joined: Wednesday 30 April 2014 20:27
Target OS: Raspberry Pi / ODroid
Domoticz version: Stable
Location: The Netherlands
Contact:

Re: 1 rpi + openvpn + Domoticz + pihole > secure???

Post by Jan Jansen »

@ Jake, @ Gizmocuz,

Thanks for the replys.

I conclude that changing the port to a 5-digit number should be sufficient.
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest