Jump to content

Recommended Posts

Posted

We have darkfibre from Exa Networks, but use our own Unifi USG Pro v4 as the gateway - not an Exa supplied router. All has been fine for many months. I now need to setup a VPN for two of our admin staff to allow them to work from home.

 

I've followed several online guides, from the unifi forum to Willie Howe but I'm getting nowhere fast. I've tried Win 10 laptops, and iPhone and iPad but none of them are able to connect with the typical error "The L2TP-VPN server did not respond. Try reconnecting..."

 

Exa aren't able to help as they only know how to setup VPN on their own hardware although they have confirmed our usable IP addr info is correct.

 

Does anyone have any experience setting up a VPN on Unifi hardware, ideally with Exa networks?

Any ideas what I'm doing wrong?

Posted
Firewall ports, NAT. Have you tried accessing from inside your network as well, depending on how your network is setup i.e. where the USG is, is it on your LAN on an internal non-public IP?
  • Thanks 1
Posted
Have you created an inbound firewall rule to allow it to access from external?

No I hadn't.

I was so focussed on following the guides I didn't even stop to think about about firewall rules. :doh:

 

I have it working now - thank you @MatthewL and @Davit2005

 

I've created a group called 'VPN Users' and given it the Public IPv4 addr I want to use.

Then created a LAN OUT rule with the Source address group set to 'VPN Users' and the Destination set to Any.

 

This feels a bit too open to me - is there a more secure way to do this or is this acceptable?

Posted

I would always ask why they NEED a VPN, and why a TS or similar is not suitable.

 

VPNs, unless you lock down ports, are very open and can be fairly relaxed at most times. A VPN in with all ports... I'm sorta not keen on that unless you know what you are doing and you know the machine is clean.

 

For clients I look after at least, they have access to the 'curriculum LAN' VLAN and at that point they only have RDP ports enabled on the VPN, so they must RDP via name to their desktop, that is it. The desktops are locked down to the user that uses it, not really useful for hot desking staff, but lets face it, people use the same machine day in day out.

 

Do you really need a hole into your network right now?

 

But thats just cynical me;)

  • Thanks 1
Posted

All valid points. I wasn't keen on it either. It is to allow access to SIMS and FMS for our Finance team.

 

There's only two users and I've restricted them to one VLAN.

 

Their laptops have Sophos intercept X installed and I've enabled logging on the VPN so I can keep an eye on how they are being used.

 

I will be monitoring the situation regularly...

Posted (edited)

I don't see a problem with a VPN as long as lateral movement limitation and other security practices are in place including necessary patches on services etc.

 

Also you may be looking at a scenarios where there is specific software that someone needs to run as a fat client on a workstation. Both RDP and VPN have uses. Tightening down with MFA either way on top of other security mitigations is important.

Edited by Davit2005
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...