Technical Discussion
  >> Home Networking, Internet Connection Sharing, etc.


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | (show all)   Print Thread
Standard User Pheasant
(experienced) Mon 29-Mar-21 11:15:46
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: ft247] [link to this post]
 
Between sites, MT to MT I'm running IPSec (AES-256) which works a treat and throughput is very good - although I think ultimately bandwidth wise it may be single thread-bound on the MT's.

L2TP also has good throughput for mobile to MT connections. L2TP seeing around double the throughput on TCP compared to OpenVPN on the same device over a 5G connection.

I haven't run OpenVPN site to site, as MT as far as I'm aware still only support TCP on their OVPN implementation and I need UDP connectivity.

My Broadband Speed Test
Standard User nofappingway
(newbie) Tue 30-Mar-21 11:01:30
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: deleted] [link to this post]
 
Why not use your Draytek 2860 as 'the' Router on your LAN and dispense with BT Smarthub? It would make your VPN challenge (and more) a lot simpler to manage.
Standard User CarlTSpeak
(committed) Fri 09-Apr-21 14:42:02
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: caffn8me] [link to this post]
 
+1 to this. RDP has no business being exposed on the public Internet. Stick it behind a firewall and spin up a VPN on the edge device.

Bare minimum to provide public-facing services exposed to the public, not much more in a DMZ exposed to the public but no access to internal network, VPN for everything else.

Building better networks, not just faster ones.


Register (or login) on our website and you will not see this ad.

Standard User Pheasant
(experienced) Fri 09-Apr-21 14:50:32
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: CarlTSpeak] [link to this post]
 
Carl it’s still shocking to find large corporates in this country that expect you to open firewall ports and port forward so that they can administer devices that sit inside your network.

I shan’t name and shame here, suffice to say I found out last week they were hacked themselves...

My Broadband Speed Test
Standard User jchamier
(eat-sleep-adslguide) Fri 09-Apr-21 19:07:02
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: Pheasant] [link to this post]
 
In reply to a post by Pheasant:
Carl it’s still shocking to find large corporates in this country that expect you to open firewall ports and port forward so that they can administer devices that sit inside your network.
surely this is the sign of a tin-pot company that has no "clue" and best avoided? you can spin up an OpenVPN on a Linux VPS in only a few minutes, and then spent a few hours understanding it. Routers with built in OpenVPN server are now common (e.g. Asus).

sigh....

21 years of broadband connectivity since 1999 trial - Live BQM
Standard User Pheasant
(experienced) Fri 09-Apr-21 19:17:36
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: jchamier] [link to this post]
 
Let's just say large quite well known UK-based EV charging system manufacturer with ten's of thousands of charge points out there...that happens to come under the umbrella of an even larger British Petroleum company. Tinpot nuff?

My Broadband Speed Test
Standard User jchamier
(eat-sleep-adslguide) Fri 09-Apr-21 21:30:55
Print Post

Re: Setting up port redirection to Draytek on LAN for VPN ac


[re: Pheasant] [link to this post]
 
In reply to a post by Pheasant:
Tinpot nuff?
Pretty scary! smile

21 years of broadband connectivity since 1999 trial - Live BQM
Pages in this thread: 1 | [2] | (show all)   Print Thread

Jump to