Netgear R6300v2: how to make ultra-secure?

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
djcaptpln880
DD-WRT Novice


Joined: 12 Jul 2022
Posts: 4

PostPosted: Wed Jul 13, 2022 20:46    Post subject: Netgear R6300v2: how to make ultra-secure? Reply with quote
Hello

I have a netgear r6300v2 in my apartment to repeat the apartment block's router (legally).

Is there anything I can do to make my traffic ultra-secure like OpenVPN or something that costs free or little per month?

Something encrypted probably just so there's no snooping in the apartment block by others?

Thx
Sponsor
Duxa
DD-WRT User


Joined: 16 Aug 2013
Posts: 191

PostPosted: Thu Jul 14, 2022 18:35    Post subject: Re: Netgear R6300v2: how to make ultra-secure? Reply with quote
djcaptpln880 wrote:
Hello

I have a netgear r6300v2 in my apartment to repeat the apartment block's router (legally).

Is there anything I can do to make my traffic ultra-secure like OpenVPN or something that costs free or little per month?

Something encrypted probably just so there's no snooping in the apartment block by others?

Thx


If you want to encrypt traffic then yes use OpenVPN.
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 2146
Location: All over YOUR webs

PostPosted: Thu Jul 14, 2022 20:36    Post subject: Reply with quote
I use SSH tunnels and configure browsers client side to use the proxy, but that's just for browser traffic and OS client traffic when configured to use the tunnel. This is 100% free. CHACHA-poly has been enabled in DD-WRT recently SSHd side, so its even better performance and security tradeoff.

Router side you and to absolutely make things hard, OpenVPN or Wireguard are both valid solutions, Wireguard being a better performant since its an in Kernel implementation so needs lesser resources vs a userspace implementation like OpenVPN.

To get those for free, no idea your mileage may vary.

You have openVPN setup guides and docs at https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327398

and WireGuard setup and docs at https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327397

Ultra secure will vary, ultimate security doesn't exist.

_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9157

PostPosted: Wed Jul 20, 2022 3:00    Post subject: Reply with quote
For free? You know what they say, when it's free, you're the product.

I'm going to assume OpenVPN for this discussion, but WireGuard may be a worthy alternative, esp. for that older router.

Given the situation, you absolutely want to use a VPN. It's no different than being at a wifi cafe or hotel. You're sharing an ethernet network w/ others, which typically has no security against arp poisoning and other MITM attacks. So even if you have to pay for the peace of mind of a VPN, it's well worth it.

Now that doesn't necessarily mean you have to use a commercial VPN provider. You *could* establish your own VPN server on a VPS (virtual private server).

FWIW, I did recently find the following, which helps you establish an OpenVPN server of your own on AWS, and at least at the time, it was FREE for the first year.

https://www.youtube.com/watch?v=m-i2JBtG4FE

Of course, like anything free, there's probably some limitations, like the amount of bandwidth per month. But it may be cheaper than using a commercial VPN provider over that same period. That's just something you'd have to check.

One of the advantages of managing your own VPS and VPN server is that you gain remote access over that same VPS+VPN! In order to gain remote access w/ the local router, you'd have to beg the landlord to allocate and manage port forwards just for you. Seems highly unlikely. Even a commercial OpenVPN provider could offer the same provided they supported port forwarding over their end of the tunnel (some do, most don't).

So regardless of the path you take, remote access is something to keep in mind when making a decision, at least if remote access is important to you.

But the idea that you're going to get all you want/need for free probably isn't reality.

_________________
ddwrt-ovpn-split-basic.sh (UPDATED!) * ddwrt-ovpn-split-advanced.sh (UPDATED!) * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-remote-access.sh * ddwrt-ovpn-client-backup.sh * ddwrt-mount-usb-drives.sh * ddwrt-blacklist-domains.sh * ddwrt-wol-port-forward.sh * ddwrt-dns-monitor.sh (NEW!)
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum