What's new

Access your VPN from outside to browse only...

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

BigApple

Occasional Visitor
Is there a way to protect your network and let anyone just access your VPN to Browse through it but not have access to shared drives within the VPN. basically just like a VPN service but through your own VPN connection.
I use a VPN service but I depend on the bandwidth they have available.
I would like to allow someone else to access my VPN at home but only for Browsing. I have a 75/75MBit that should do just fine to handle 1-2 browsers that need to go online.
If yes how would I exclude my network for them or Protect it from them to only access browsing. like Ports 80, 443 and 25 and such ... Thank you
 
If you mean your using the openvpn client of your router, and don't want to share your lan shares with guests/friends, just enable the guest network and change the settings in there to not allow it. I am not sure how easy it is to bypass it (arp table spoofing/hacking) but I use it and feel alright. When on the guest network testing it out I can not even access the router config page, so I very much like it. The guest network goes through the vpn client if its on unless your also using selective routing scripts in which case you can specify what ip address goes through the vpn, or the your wan ip, or gets dropped, etc. If your using Ethernet cable instead of wifi to share with your friend then I am sure it can still be accomplished, however its over my head. I think that the link from martinr above will help you with that.

If you mean using the openvpn server of your router, and you want to share your isp internet connection, and not allow your guests to access your shares, it can be done, I think you change a setting when you configure the openvpn server in the gui of router. Look for a setting about LAN and clients.
 
thanks for your replies.
All I want to do is block intranet access on the vpn side ... through any vpn connection pptp or openvpn

so far I had no luck ...
 
There' doesn't seem to be a simple answer to this, as a read of the following topic shows:

http://www.snbforums.com/threads/bl...drive-for-specific-clients.23453/#post-174350

And I'm sure that, unless you really know what you are doing, messing around with iptables could invoke the law of unintended consequences. Nevertheless, I came across post on Google (someone using Tomato OpenVPN firmware on a Linksys) and it appears they achieved what you wanted through entries in iptables.

http://serverfault.com/questions/250927/how-do-i-block-access-to-lan-through-openvpn

To be honest, I think there's a case for re-evaluating the requirement to "let anyone just access your VPN to Browse through it", such as suggesting they use a service like Cloak https://www.getcloak.com/

That way, you sleep easy at night. (Just because you can give friends access to vpn browsing thanks to Asuswrt-Merlin, it doesn't follow that you should.)
 
Last edited:
thank you ... it is actually myself that will use this "feature". Using other vpn services does not guaranty me bandwidth availability. but having my own 75/75 VPN to browse only does. I need to have its intranet blocked just in case someone gets on my computer temporarily to use it.
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top