4 ms·
I've had the same static ipv4 address for just over 19 months, and have been running an exposed OpenVPN server on an alternative port on that IP for the entire
by developer2 6y ago
I've had the same static ipv4 address for just over 19 months, and have been running an exposed OpenVPN server on an alternative port on that IP for the entire duration. I get no results.
Color me unimpressed that "an army of bots that crawl the entire Internet and stores what it finds along the way" hasn't port scanned every ipv4 address at least once in the span of 19+ months. That is a very long time for a limited address space.
tldr; There is no "army", or that army is armed with pool noodles.
- jessaustin 6y agoWell, they've found a port 22 that I have open. Oh noes! Actually, this seems to undercut the whole "don't use standard ports" argument. They would have found it as well if ssh were at 22222 instead.
- achillean 6y agoIt also depends how you've configured OpenVPN. If you've properly configured to drop connections that didn't provide a valid certificate then even running it on a regular port would make it invisible to scanners.
- lipnitsk 6y agoWon't the server need to accept a TCP connection to receive the cert? If so, the port will show as open. I suppose with UDP it is possible.
- xorcist 6y agoIt does, but what you see is not a portscan, it is a lookup from the Shodan database and they store information about known services on the public Internet.
- achillean 6y agoShodan does something like a portscan of the entire Internet, albeit fewer ports than if you did nmap -p-
- achillean 6y agoI believe the recommended configuration is to run OpenVPN via UDP and only accept connections from trusted certificates. If you're running it on TCP then a scanner would be able to see that you have an open port but still can't see what's running on it.