Jump to content

Hello everyone,

 

I have a couple of DrayTek Vigor 3900 VPN Concentrator Firewall Gateway Routers (a mouthful, I know) and I have a question about the security of PPTP VPN.

 

I know that PPTP is incredibly insecure and just overall bad, but it might be the only choice for me for a VPN protocol for my use with Windows machines. I already have IKEv2 and Cisco IPsec VPNs set up that work great with my Linux, macOS, Android and iOS devices - they are also secure protocols. But for Windows, my only choice might be PPTP. I sometimes need to get to my systems from my school and it is very complicated but at the end of the day only PPTP VPNs work on their Windows 10 machines there for some reason.

 

My question, finally, is: is PPTP insecure when not in use? Is it easy for an attacker to hack and connect to the PPTP VPN server on my router? I don't care about the security of the data passing through the tunnel when I am connected, but I do care if it is easy for attackers to brute force the password to connect to my PPTP VPN on my router when I am not connected to it. Basically, is having the PPTP VPN server enabled on my router putting me at risk when I am not connected to it? Can people brute force or crack the Username and Password for the VPN to connect to it easily?

 

Any help is appreciated! :)

PC:

AMD Ryzen 9 5900X | AMD Radeon RX 7900 GRE | 32 GB RAM | Arch Linux

Laptop:

MacBook Pro 13" (2019) | Intel Core i5 8279U | 8 GB RAM | macOS

Server:

Intel Core i7 6700K | 16 GB RAM | 2 TB HDD | Debian Linux

Link to comment
https://linustechtips.com/topic/1050206-pptp-vpn-security/
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×