Jump to content

Access VPN remotely with PrivateVPN enabled


AndrewDub622

Recommended Posts

AndrewDub622

Hey guys

I recently got PrivateVPN and got a vpn running on my NAS (OpenVPN) and can access my Server when I'm home and the VPN is on but when its on and I'm away from home I cant. Any advice. I'm a rookie

Screen Shot 2022-04-28 at 2.39.28 PM.png

Screen Shot 2022-04-28 at 2.39.48 PM.png

Link to comment
Share on other sites

AndrewDub622

Oh it's PrivateVPN I'm using. I understand they support Port Forwarding. I'm running Emby on a Synology NAS if it helps 

 

Link to comment
Share on other sites

11 minutes ago, AndrewDub622 said:

Oh it's PrivateVPN I'm using. I understand they support Port Forwarding. I'm running Emby on a Synology NAS if it helps 

 

OK I think that would be a good thing to start with. You can learn what ports to configure in our remote setup guide:

https://support.emby.media/support/solutions/articles/44002137137-remote-setup

Please let us know if this helps. Thanks.

Link to comment
Share on other sites

AndrewDub622

Cool! I'm assuming it's on the Mac or Windows PrivateVPN app. I try on the NAS with the VPN on and it doesn't let me change anything and it disables my rules. (Yes I'm a rookie) lol

Link to comment
Share on other sites

AndrewDub622

Okay Ports are Forwarded on my Router. Next up, Forward them in the VPN I think. Still have UPNP on. I read the manual and understood most of it lol 

Link to comment
Share on other sites

What I did, with exactly this problem, was to create an SSL cert for one of my sub domains, following this guide:

https://support.emby.media/support/solutions/articles/44001160086-secure-your-server

This then secured my Emby server.

I setup a VPN like you. This has all my NAs traffic going through it...except my secured Emby server, which I set up as follows:

For the same sub domain I setup a DDNS service, pointing to my public IP from my intenrnet provider (non VPN address).

1369293900_Screenshot2022-04-30083935.thumb.jpg.5e39ed34813d44f6babe1423a806914e.jpg

 

The no-ip.com setting is the 'open' IP address from my intenrnet provider, and this is used to access my Emby server, as it bypasses the VPN.

The Synology address is the VPN address, so all other traffic goes through that. 

This is what works for me. I can see, for example, that if I use the excellent website iknowwhatyoudownloaded.com, that there is zero traffic on my internet provider IP adresses, but looking at the VPN provided IP, there is tons.

This method helps me keep Emby sercure but easily accessible for remote users, and all other traffic protected by my VPN provider.

Link to comment
Share on other sites

AndrewDub622

Lol cool I uh might need a hand Kaj. Or maybe a remote connection if possible lol! But I'll see what I can do 

Link to comment
Share on other sites

Feel free to send me a DM....the most important thing is to setup the SSL cert for connections to your Emby server. Once that is done, the rest is easy :)

Link to comment
Share on other sites

  • 3 weeks later...

@AndrewDub622 when you say PrivateVPN do you mean using OpenVPN built into Synology?

What exactly is the purpose of this type of VPN used with Emby?
You really don't gain anything going this route and it will never be as secure as a directly forwarded single port using encryption.

You're potentially exposing your whole machine and your network when using VPN so you want to make sure it's locked down well. If you're giving access to your Emby Server this way to remote users you will need to have different profiles setup for them vs you/admin as well.

It depends on need and what you're trying to accomplish but if the reason for the VPN is strictly/mainly Emby related it's the wrong way to try and secure your server because of the risks involved in not getting routing/forwarding and user permissions correct.  With a direct port forward to Emby Server running encrypted ports it's pretty much foolproof as the remote person has access to one port going to one machine only with no way to divert those packets elsewhere.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...