HELP! I tried VPN enabled on my AC3200 but I broke everything

Crossing the fingers and pulling the plug. . . . .

1 Like

:pray:

That did it. :grin: The HE hub got a new IP and it is showing up in the router logs and the http://portal.hubitat.com/

Now to get busy reserving the IP addresses for all my devices with the new router setup.

3 Likes

And save the router config when you're done if it allows it. I can't tell you how many times I've forgotten to do that myself :flushed:

1 Like

I am in the middle of troubleshooting after getting the new AC3200 setup. Having inconsistent behavior in HE and I thought did I name something (devices, RM, etc) poorly? I have used ( ) - . _ and didn't know if those are part of the taboo characters.

I also have two Lifx bulbs that won't work any longer in just the Lifx app and won't reset and reconnect to Lifx app, the same thing with a couple of my Sonoff switches, H801's just inconsistent behavior and operation.

I thought I read somewhere about best practices on the naming of devices or such about strange behavior could be due to strange device names? Anyway, I have searched in the documentation and the forums about naming practices and I can't find that post anywhere. I think it could have been @patrick posting it but I can't find a reference to it about NOT using special characters and he listed what those special characters are to avoid using. Anybody help me find where there that is?

I think there were a couple of posts by @patrick. Here is one...keep in mind the list of characters posted here may be incomplete.

Device Name vs Device Label in Drivers

1 Like

I remember having difficulty resetting these bulbs in the past as well. I can't remember the "trick" I used to force the reset. Are they the original A19's?
When I get my Wifi back up later today I'll try to reset one.

Yes they are. It is the the 1000 lumen output model. I am able to perform the 5 off-on reset and get the red,grn,blu,wht flashes. I go to Settings and connect to the A19 as an access point and it is says it is setting up this accessory to join "pPCp" which is y 2.4GHz WiFi but it then gets stuck and times out after several minutes with "An unexpected error occurred. Try again."

Yes that is what I thought... I used a bunch of these especially () .

:thinking: I think they changed the reset process since I last had to do it. I remember it being fairly simple and required me only to flip a tiny notch switch on the side of the bulb. I just looked up the procedure on the website and it list the above procedure instead.

Thinking this over, although I had to follow a different process, the issue was similar and all I did was use a different device to set them up after resetting. I believe I was using my phone initially (android) and tried the process with my Ipad to get it working.

You were right I was wrong. I have the newer version apparently. This is from the Lifx website support.

Reset your light

Before Starting: Please reset your LIFX light by turning it off/on 5x until it cycles - it will stop on white.

For the LIFX Original, turn the light on then use the switch on the side 1x.

For all LIFX products with plugs, please unplug/re-plug completely 5x.

1 Like

Well, I finally gave up and contacted Lifx and they are sending me out a replacement device under warranty.

1 Like

I setup a spare 2.4GHz access point that had been left over from an upgrade to 5GHz AC Wifi. I was able to connect all the wifi devices to the "new" access point so the new setup I did for either VPN or restricted IP's on the ASUS messed me up?

I took off the restrictions from the ASUS and quit playing with the openVPN for now until my system goes stable for a few days before I try it again. :flushed:

1 Like

OK I must admit that I am a totally newbie on this VPN thing and I am ready to give this a second try. Can someone point me to some kind of tutorial on how for me to setup a VPN so that I can connect to my Hubitat from remote location?

I got PrivateInternetAccess PIA as my service. I am able to use it on my laptop so that it connect to some distant server so that it secures my connection to the Internet but I don't see the step I am missing to connect to my Hubitat system?

I am confused I think on setting up the OpenVPN on my ASUS RT-AC3200 router to allow me to connect. I was doing the instruction for setting up OpenVPN client on the router but I think that is only for giving me a VPN client for all my home network devices going out to the internet so that I don't have to load or run a PIA on each of my devices at home and still be VPN protected, right?

So what do I do for setting up the ability for me to remotely connect into my Hubitat?

This is the documentation from Asus on how to enable the vpn server.
https://www.asus.com/support/FAQ/1008713

This should generate an ovpn file that use can use to configure the client. If you are connecting from an android phone, you can install the official app (there are quite a few versions out there but get the official) and then choose the import option using this file.

I have. Afew tricks I can share if you also use Tasker, but let's get you connected first.

1 Like

I tried a setup from my Synology, but found it slow and didn’t like opening ports. I ended up just using Apple Remote Desktop to remote back to a Mac laptop, which I have on the network anyway for stuff like Homebridge and Google Assistant Relay, etc

Mac or PC, any Secure VNC will accomplish the same thing. Just open a browser on the computer you’re remotely connected to and you’ve got access to Hubitat.

I could be wrong but I would think that if the vpn in on the router itself there would be no ports to open....it is already exposed to the Internet on the WAN port.

From the perspective of just accessing the web interface, yes, they both accomplish the same thing. However, there are other benefits to a vpn server. For example, I do not expose my internal ip cams to the Internet...just not comfortable with the level of security on these cameras. With the vpn I can access their video feeds using TinyCam as if I was on my local wifi.

All easily connected remotely because of Tasker.

1 Like

As I believe you have surmised, PIA is used for connecting your client devices (Laptops, Phones, Tablets, or even your router) to PIA's OpenVPN server.

When connecting back into your own home, the simplest way I have found is to use Asus' built-in OpenVPN server, along with the free Asus Dynamic DNS feature.

Once you have the OPenVPN Server and Asus Dynamic DNS working on your router, you will them configure your phone, laptop, tablet etc... as an OpenVPN Client that points back to your own router's OpenVPN server. In order to find your router, amongst all those on the Internet, you will use the Asus Synamic DNS name you created when configuring your router.

It sounds complicated, and it definitely isn't trivial if you've never done it before. However, the results are pretty fantastic.

2 Likes

There are no forwarded ports if you run the OpenVPN server on your router. However, the OpenVPN server is definitely listening on a port on the WAN adapter of your router. So, technically there is at least one open port. :slight_smile:

I still prefer this solution to versus running OpenVPN on another computer behind the router. I at least am somewhat vigilant about keeping my router's firmware up to date, which includes security patches and updated versions of OpenVPN. I know that if I had OpenVPN running on a Raspberry Pi behind my router, I would probably never touch it for fear of breaking it, or I'd simply forget about it until I really needed it (at which time I am sure it probably would be powered off or crashed for some reason! :stuck_out_tongue_winking_eye: ) At least if my router goes down, I am very aware and fix it quickly.

1 Like

Yep. My router just doesn’t allow it and this method is secure enough that I’m not concerned with someone gaining access.

I only personally have two cameras I can access via their cloud connection and I’m ok with that. But what you’re saying makes perfect sense with TinyCam. I’m fairly new to cameras in and around my home, so I’m sure I’ll need to change the way I’m doing things at some point, for one reason or another.