What's new

Split tunneling question, and security

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

snowatom

Occasional Visitor
I have created a strict policy rule for a VPN connection against one device (my Apple TV for streaming).

Should one disconnect this VPN connection when not in use, or is it safe to keep it connected?

What I’m really asking, is there some way that the VPN connection provider, can gain access to my network using the open connection?

edit: VPV typo corrected.

/snowatom
 
Last edited:
Of course, they can. Even if they state otherwise.

RMerlin firmware (I believe) disables that access by default on the 386.1 firmware and later.

Btw, VPV=VPN?
 
Of course, they can. Even if they state otherwise.

RMerlin firmware (I believe) disables that access by default on the 386.1 firmware and later.

Btw, VPV=VPN?
I saw that access is disabled by default “Inbound Firewall: block”. But does this prevent the VPN provider from getting in through the “open door”?
 
It's supposed to. I can't take an oath to that though. (not a scripter). :)
 
I saw that access is disabled by default “Inbound Firewall: block”. But does this prevent the VPN provider from getting in through the “open door”?

Yes. When enabled (blocked), that option prevents *anyone* from initiating connections inbound on the tunnel. It was added about a year ago at my request because most users are using commercial OpenVPN providers and only need *unidirectional* tunnels (i.e.. where only you need to initiate connections). Before this option was added, all tunnels were *bidirectional*, meaning it was possible for some rogue element at the VPN provider (user or malware) to potentially gain access into your network.
 
Last edited:

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top