So, I understand the whole security and VPN aspect of what I see a lot of you guys preaching. Truth be told, I'm a network engineer.
So, I have a few questions, and maybe someone can answer them?
My Setup (currently have Nest cams, but looking to replace them with a possible NVR).
Router/Firewall: PFSense
Switch: Cisco 2960X (managed 24 port switch)
VLANS: 1 (wired),2 (wireless), 5 (future PoE cams)
OpenVPN setup and configured, it drops into a different subnet than the other 3 networks, but it's considered (wired LAN) for all intents and purposes.
I've created firewall rules so that VLAN 1/2 can talk to 5.
VLAN 5 Firewall Rules:
Block traffic to management ports of FW (ports 22,80,443).
Allow NTP (UDP port 123) to any.
Block all access to internet gateway.
That being said with internet access blocked, is it still possible to get push notifications? Does that run on a specific port? My guess is that if I have the VPN client active on my phone, I can get push notifications, but without it active, can I? My co-worker says he gets push notifications, but I don't think his firewall is setup the same as mine.
So, I have a few questions, and maybe someone can answer them?
My Setup (currently have Nest cams, but looking to replace them with a possible NVR).
Router/Firewall: PFSense
Switch: Cisco 2960X (managed 24 port switch)
VLANS: 1 (wired),2 (wireless), 5 (future PoE cams)
OpenVPN setup and configured, it drops into a different subnet than the other 3 networks, but it's considered (wired LAN) for all intents and purposes.
I've created firewall rules so that VLAN 1/2 can talk to 5.
VLAN 5 Firewall Rules:
Block traffic to management ports of FW (ports 22,80,443).
Allow NTP (UDP port 123) to any.
Block all access to internet gateway.
That being said with internet access blocked, is it still possible to get push notifications? Does that run on a specific port? My guess is that if I have the VPN client active on my phone, I can get push notifications, but without it active, can I? My co-worker says he gets push notifications, but I don't think his firewall is setup the same as mine.