# Securing Node-Red

**URL:** <https://discourse.nodered.org/t/securing-node-red/3561>\
**Category:** General\
**Tags:** security\
**Created:** [29 September 2018 19:22 UTC](https://discourse.nodered.org/t/securing-node-red/3561 "2018-09-29T19:22:08Z")\
**Posts on this page:** 14\
**Page:** 2

<div class="post-metadata">

**Author:** ![hazymat](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hazymat/32/108159_2.png) [@hazymat](https://discourse.nodered.org/u/hazymat)\
**Post date:** [18 October 2018 10:00 UTC](https://discourse.nodered.org/t/securing-node-red/3561/21 "2018-10-18T10:00:43Z")

</div>

> [@TotallyInformation](#):
>
> When you create a VPN connection from a device on a local network to your remote network, you have a choice. You either isolate the device from its local network in order to place it on your remote network. Or you bridge the two networks

I'm using Untangle as my router, so I have the luxury of a nicely designed firewall and a choice between IPSec and OpenVPN (I know which choice I make!)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 October 2018 12:51 UTC](https://discourse.nodered.org/t/securing-node-red/3561/22 "2018-10-18T12:51:30Z")

</div>

> [@TotallyInformation](#):
>
> When you create a VPN connection from a device on a local network to your remote network, you have a choice. You either isolate the device from its local network in order to place it on your remote network. Or you bridge the two networks.
> 
> Bridging a local network to a remote one is certainly possible but generally discouraged unless you have permission from both network owners and have considered the possible differences in security levels. I'll admit that I assumed the situation I most commonly come across - being on a corporate network and wanting to connect to my home network. If I bridged the networks, even if I could, I would end up in a lot of trouble. It should also go without saying that bridging a coffee shop WiFi network to your home would also open you to a world of pain.

I am not with you here. Imagine I am in a coffee shop which uses addresses 192.168.1.x. When I connect to the wifi (using Ubuntu but the principles are the same with any client I think) it connects over the interface wlan0 and the PC is given an ip address such as 192.168.1.100 on the coffee shop network. If I then start up the vpn a virtual interface such as tun0 is created and the vpn gives it an address possibly 10.8.0.4 for example.  
Now I can still access devices on the 192.168.1.x network via wlan0 but I can also access devices on my home network via tun0. This does not mean that anyone on the coffee network can access my home network, or vice versa.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 October 2018 14:49 UTC](https://discourse.nodered.org/t/securing-node-red/3561/23 "2018-10-18T14:49:38Z")

</div>

> [@Colin](#):
>
> Now I can still access devices on the 192.168.1.x network via wlan0 but I can also access devices on my home network via tun0

That shouldn't happen. Because if malware gets onto your PC, it would now have access to both networks - bridging them together. Since the most likely infection would come from the WiFi network, an insecure network now leaves your home network open to attack via the malware.

When done deliberately, this is called "split tunnelling". It does have a place but is not to be undertaken lightly.

For example, we use split tunnelling corporately to give lower latency access to Skype for Business because the default traffic routing for our corporate devices when on untrusted networks is down the VPN into the datacentre, through the centralised security infrastructure then out to the Internet. However, since SfB only uses secured connections that already meet our security requirements and because it has its own security and audit infrastructure, we don't need it to go through ours. But the default route for all other traffic is down the VPN, once the VPN is active, there is NO ACCESS at all to the local, untrusted network.

It is these things that make VPN's sometimes a less than ideal solution to problems.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 October 2018 15:45 UTC](https://discourse.nodered.org/t/securing-node-red/3561/24 "2018-10-18T15:45:19Z")

</div>

> [@TotallyInformation](#):
>
> That shouldn't happen. Because if malware gets onto your PC, it would now have access to both networks - bridging them together. Since the most likely infection would come from the WiFi network, an insecure network now leaves your home network open to attack via the malware.

I don't understand the logic of that. If I am in the coffee shop and I don't have the VPN running and malware gets onto my laptop from the wifi network, then I take my laptop home the malware has access to the home network anyway.  
Similarly, even if I did not have access to the local network when the VPN is active, I might pick up the malware before activating the VPN and then again the malware would have access to the local network.  
Of course I do configure the VPN to route internet traffic through the VPN.  
I am using openvpn in 'tun' mode (a routed IP tunnel) and I can't immediately see a setting that would prevent access to the local network.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 October 2018 16:00 UTC](https://discourse.nodered.org/t/securing-node-red/3561/25 "2018-10-18T16:00:13Z")

</div>

> [@Colin](#):
>
> I am using openvpn in 'tun' mode (a routed IP tunnel) and I can't immediately see a setting that would prevent access to the local network.

Ah, found it, `redirect-gateway block-local`.  
I remain to be convinced that it fulfils a useful purpose though.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 October 2018 18:57 UTC](https://discourse.nodered.org/t/securing-node-red/3561/26 "2018-10-18T18:57:08Z")

</div>

> [@Colin](#):
>
> I remain to be convinced that it fulfils a useful purpose though.

I suspect that this forum is not the place to explain further and we may have reached a natural break point. This is all about assessing risks at the end of the day.

Happy to take this to a different forum or PM if needed.

All I'll say to finish is that if you create an unauthorised split tunnel on a corporate network and someone discovers it, you will get a serious wrist slap at best. After all the risks run both ways if you connect two networks together of differing trust and security levels. This is serious stuff at the corporate level - I know, I was deeply embroiled in dealing with the Wannacry outbreak in the NHS. The reason that Wannacry unexpectedly spread so far through the NHS was largely due to some network misconfigurations that should never have been allowed. Our own network had zero infections.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 October 2018 19:29 UTC](https://discourse.nodered.org/t/securing-node-red/3561/27 "2018-10-18T19:29:01Z")

</div>

No corporate networks are involved, I retired 12 years ago 🙂  
I am off to google Split Tunnelling to see if I can understand the risks and benefits.  
I can see I may need to adjust the settings in my vpn setup blog. One thing that does surprise me is that in all the tutorials and guides that I looked at when building mine and writing the blog I don't remember any suggesting setting block-local.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 October 2018 19:33 UTC](https://discourse.nodered.org/t/securing-node-red/3561/28 "2018-10-18T19:33:05Z")

</div>

> [@Colin](#):
>
> One thing that does surprise me is that in all the tutorials and guides that I looked at when building mine and writing the blog I don't remember any suggesting setting block-local.

And we wonder why we still get so many infected machines and networks.

---

<div class="post-metadata">

**Author:** ![arneym](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arneym/32/54_2.png) [@arneym](https://discourse.nodered.org/u/arneym)\
**Post date:** [24 October 2018 12:36 UTC](https://discourse.nodered.org/t/securing-node-red/3561/29 "2018-10-24T12:36:05Z")

</div>

I have secured node-RED in the settings.js file and changed my port number. I have my login page when I try to access node-RED, as seen here:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/b/bc945d3826f8ce497ed39a20fb4bb697dbb53d87.png)

I would like to get rid of this: ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/f/f854ebb4721c3d53a028819372353c23fe42259d.png) after I log in or visit my dashboard.

I just purchased this from my DDNS provider ([no-ip.com](http://no-ip.com)), and it is asking for me to generate a certificate signing request. It gives me server type options, but I do not know what to select and complete adding SSL to my node-RED server. Can anybody help me?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/9/9feab2cfd21e81c663d0a87867abd53632b1790a.png) ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/1/182a153870fba93fdfa05518b1a8091b6b5adbd2.png)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 October 2018 08:25 UTC](https://discourse.nodered.org/t/securing-node-red/3561/30 "2018-10-26T08:25:35Z")

</div>

Hi, this new blog post may help.

> **[How to create secure certificates](https://it.knightnet.org.uk/kb/nr-qa/https-valid-certificates/)**
>
> Generate certificates for Node-RED that are trusted by all modern browsers. This will let you access Node-RED (and other services) over an encrypted HTTPS link.

---

<div class="post-metadata">

**Author:** ![arneym](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arneym/32/54_2.png) [@arneym](https://discourse.nodered.org/u/arneym)\
**Post date:** [26 October 2018 12:58 UTC](https://discourse.nodered.org/t/securing-node-red/3561/31 "2018-10-26T12:58:57Z")

</div>

I like the post, but I am lost due to the fact that I purchased a certificate that was not in your example. I do not understand how to create a certificate signing request via my node red server.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 October 2018 17:12 UTC](https://discourse.nodered.org/t/securing-node-red/3561/32 "2018-10-26T17:12:45Z")

</div>

There are plenty of articles on this as it doesn't relate to Node-RED. Some examples:

> **[Suspended – Medium](https://medium.com/suspended)**
>
> This page is unavailable.

[https://support.rackspace.com/how-to/generate-a-csr/](https://support.rackspace.com/how-to/generate-a-csr/)

> **[How to Create CSR (Certificate Signing Request) on Linux - TecAdmin](https://tecadmin.net/simple-steps-to-generate-csr-on-centos/)**
>
> 3 Quick methods to Create CSR on CentOS, RHEL, Ubuntu, Debian and other Linux systems. How To Create SSL Certificate Signing Request (CSR) in Linux. Steps to generate CSR for your domain using Linux command line.

---

<div class="post-metadata">

**Author:** ![inayet](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/inayet/32/86377_2.png) [@inayet](https://discourse.nodered.org/u/inayet)\
**Post date:** [24 December 2023 18:14 UTC](https://discourse.nodered.org/t/securing-node-red/3561/33 "2023-12-24T18:14:14Z")

</div>

For local cert generation, I use mkcert [GitHub - FiloSottile/mkcert: A simple zero-config tool to make locally trusted development certificates with any names you'd like.](https://github.com/FiloSottile/mkcert).

The article "How to secure Node-RED" [How to secure Node-RED | Much Ado About IT](https://it.knightnet.org.uk/kb/nr-qa/securing-node-red/) is 5 years old, are there updated tutorials?

Fyi, I am a beginner, so please recommend better ways than mkcert

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [24 December 2023 19:50 UTC](https://discourse.nodered.org/t/securing-node-red/3561/34 "2023-12-24T19:50:48Z")

</div>

> [@inayet](#):
>
> The article "How to secure Node-RED" [How to secure Node-RED | Much Ado About IT](https://it.knightnet.org.uk/kb/nr-qa/securing-node-red/) is 5 years old, are there updated tutorials?

My blog not seen much love recently! Best to use the security FAQ here on the forum.

[Previous page](https://discourse.nodered.org/t/securing-node-red/3561.md?page=1)
