Page 1 of 1

How to limit access of managment sessions?

Posted: Thu Jun 11, 2015 2:16 pm
by vavy
Hello!
I've installed SoftEther VPN server. It works.
It's listening on port 443 for Softether VPN clients what going from internet.
How can I limit managment admin sessions access by Managment Console to my 443 port what's opened for incoming connections?
May be it is possible to configure allowed only ip-addresses ranges for admin connections?
Or may be it is possible to create special listener on different port for admin connections only and disable admin connections at other listening standard VPN ports?
Or may be it is possible to authenticate admin not only on passwords basis, but instead of that - on certificates and on usb token basis?
Thank you.
I think it is nearly compulsory to have some seperated way for "out-of-band" administration of SoftEther VPN Server.

Re: How to limit access of managment sessions?

Posted: Thu Jun 11, 2015 6:59 pm
by exciter0
Refer to the manual: https://www.softether.org/4-docs/1-manu ... Source_IPs


vavy wrote:
> Hello!
> I've installed SoftEther VPN server. It works.
> It's listening on port 443 for Softether VPN clients what going from
> internet.
> How can I limit managment admin sessions access by Managment Console to my
> 443 port what's opened for incoming connections?
> May be it is possible to configure allowed only ip-addresses ranges for
> admin connections?
> Or may be it is possible to create special listener on different port for
> admin connections only and disable admin connections at other listening
> standard VPN ports?
> Or may be it is possible to authenticate admin not only on passwords basis,
> but instead of that - on certificates and on usb token basis?
> Thank you.
> I think it is nearly compulsory to have some seperated way for
> "out-of-band" administration of SoftEther VPN Server.

Re: How to limit access of managment sessions?

Posted: Sat Jun 13, 2015 2:22 pm
by vavy
Thank you very much! It works.
And is it possible to set up permitted ip ranges for every single VPN client?

Re: How to limit access of managment sessions?

Posted: Sat Jun 13, 2015 4:09 pm
by kh_tsang
Whitelisting IP can be done on the Virtual Hub but no idea for specific user.

Re: How to limit access of managment sessions?

Posted: Sat Jun 13, 2015 5:51 pm
by vavy
Well, how to do it on HUB basis ?

Re: How to limit access of managment sessions?

Posted: Sat Jun 13, 2015 11:27 pm
by kh_tsang
You can configure rules after entering that menu.

Re: How to limit access of managment sessions?

Posted: Tue Jun 16, 2015 7:15 am
by vavy
Thank you!

Re: How to limit access of managment sessions?

Posted: Sat Aug 22, 2015 6:15 am
by dissoft
Suggestions:

1. Enabling use of partial wildcards, e.g. 192.168.1.*

2. Enable the configuration of ports
A. Use for both VPN & management
B. Use only for VPN
C. Use only for management

Thanks.

Re: How to limit access of managment sessions?

Posted: Sun Aug 23, 2015 4:47 am
by kh_tsang
I forget one thing. The admin IP and virtual hub admin IP should be defined in adminip.txt.

Re: How to limit access of managment sessions?

Posted: Sat Aug 29, 2015 5:28 am
by dissoft
yes, but if use the same port for both vpn + admin interface, it expose the port to outside and you are forced to use a very strong passowrd or limit the ip address. but on an internal network sometimes the ip is asssign by dhcp, so this should be changed.

Re: How to limit access of managment sessions?

Posted: Sat Aug 29, 2015 12:39 pm
by kh_tsang
dissoft wrote:
> yes, but if use the same port for both vpn + admin interface, it expose the
> port to outside and you are forced to use a very strong passowrd or limit
> the ip address. but on an internal network sometimes the ip is asssign by
> dhcp, so this should be changed.

A temporary workaround is to use DHCP reservation.

Re: How to limit access of managment sessions?

Posted: Sat Aug 29, 2015 12:44 pm
by dissoft
thanks.

knowing there are workarounds. could you suggest to the softadmin team to implement a better function in future versions?

Re: How to limit access of managment sessions?

Posted: Sat Aug 29, 2015 4:47 pm
by kh_tsang
We have to wait the administrator to see this topic.

Re: How to limit access of managment sessions?

Posted: Sat Aug 29, 2015 5:16 pm
by dissoft
is there a bug tracker or something like that?

edit: okay done

https://github.com/SoftEtherVPN/SoftEtherVPN/issues/173

Re: How to limit access of managment sessions?

Posted: Sun Nov 29, 2015 4:03 pm
by dissoft
Issue is being ignored by the developer... : (

Re: How to limit access of managment sessions?

Posted: Mon Dec 28, 2015 8:18 am
by dissoft
Is there any way to get into contact with the dev and voice this concern?

Opening the port to world doesn't sound like a very brilliant idea. People will bruteforce the admin password, no?

Re: How to limit access of managment sessions?

Posted: Sat Aug 27, 2016 7:24 pm
by dissoft
......................

Re: How to limit access of managment sessions?

Posted: Sun Aug 28, 2016 11:47 am
by fenice
dissoft wrote:
> ......................

Now you've decided to post the same rubbish in the forums as in the issues section on github? The developer(s) will see your reports on github and make comments as and when necessaryn You've already had a reasonable answer from meganerd on github and you do nobody any favours by posting the same stuff in these forums, give it a rest and wait for an answer instead of filling the forums with useless posts.