General suggestion:
"Joe Average" is advised
not to open OWIF (or Dream Webif), ftp, telnet, streaming (and transcoding)
by using port-forwarding at all.
Note that HTTP, ftp and telnet transfer plain passwords, unencrypted!, over the internet!
Instead you should use a VPN, many routers (e.g. AVM Fritz!Box) already offer this feature itself.
If your router doesn't offer it, your NAS might and if that doesn't, you can use OpenVPN on the E2 box itself (Which is probably the hardest variant to set up).
Once you are logged into your LAN using a VPN, you can use
any service on
any machine in your home network just as if you were at home.
If there are no other reasons (like children) for setting logins, you can then even save the hassle of logins entrirely, just keep your VPN credentials/key files safe.
Another safe variant is the ssh access of your box
using key pairs.
Execute the following commands to generate and install a key pair on your E2 box:
Code:
dropbearkey -t rsa -f ~/.ssh/id_rsa
dropbearkey -y -f ~/.ssh/id_rsa | grep "^ssh-rsa " >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/*
chmod 700 ~/.ssh
chmod 700 ~
You should now be able to login to your box using the private key file id_rsa located in /home/root/.ssh of your box (See the instructions of your ssh client on how to use key auth).
If this succeeds, make the content of /etc/default/dropbear read
This will disallow password logins for ssh entirely (let alone logins with empty passwords, which is the default for all oe-a images) (The only way to recover from ssh login problems would then be telnet).
You can transfer the file /home/root/authorized_keys to other boxes too, to use the same key file for multiple boxes, but make sure to adjust the file rights after copy:
Code:
chmod 600 ~/.ssh/*
chmod 700 ~/.ssh
chmod 700 ~
With ssh, you have everything you need:
- ssh gives you shell access, just like telnet but secure (when using key auth)
- ssh gives you file access, either using scp (secure copy) or sftp (FileZilla supports sftp, you can access your box' files just like you could using ftp).
- ssh allows to tunnel ports from the remote machine (= your E2 box) to your local machine.
You can for example tunnel port 80 of your E2 box to port 80 of your smartphone and port 8001 of your E2 box to port 8001 of your smartphone.
As long as the tunnel is established, you can login to your E2 webif using address "http://localhost" on your smartphone and use streaming, just as if your smartphone would be your E2 box.
The free app "ConnectBot" (
https://play.google.com/store/apps/details?id=org.connectbot) has the necessary capabilities of using key auth and port tunneling on Android.
Personally, I use VPNs for machines which I permanently maintain and ssh tunneling for machines that I sometimes maintain.