[Security Issue] Separate Admin listening port from VPN listening port.
Author: pgwipeoutCreated Mar 7, 2018Updated Aug 6, 2026
Currently there is no way to separate the Administration listen port from the VPN listening ports. This allows anyone to o connect to the Admin console if the VPN is listening on any public facing TCP ports, which is required for the VPN client to connect. With the limited Admin authentication methods available, this means that anyone could eventually acquire Admin access to the VPN.
This can be mitigated by using only L2TP with IPsec with a native client, but this disables usage of the Softether client.
Granular control over what ports and address the Admin console and VPN listen on is necessary to ensure a secure environment.
Source: SoftEtherVPN/SoftEtherVPN