Securing Your Private Perimeter: Deploying NetAlertX on a VPS for Advanced VPN Intrusion Detection
The Evolution of Perimeter Security in the Remote Era
In the contemporary digital landscape, the traditional office perimeter has effectively dissolved. As organizations shift toward distributed workforces, the Virtual Private Network (VPN) has transitioned from a secondary utility to a critical piece of infrastructure. However, this extension of the internal network brings a significant security caveat: if a VPN credential is compromised, an attacker gains a 'virtual' seat inside your office. Traditional firewalls often fail to inspect traffic once it has been authenticated through a tunnel, leaving a blind spot where unauthorized devices can roam undetected.
To mitigate this risk, network administrators are turning to NetAlertX (formerly known as Pi.Alert), an advanced network security scanner. When deployed on a Virtual Private Server (VPS) that acts as a VPN gateway or hub, NetAlertX provides an automated, persistent monitoring layer. It scans the network at defined intervals, identifies every connected MAC and IP address, and alerts administrators the moment an unrecognized device appears. This blog post provides a professional, step-by-step roadmap for deploying NetAlertX on a VPS to maintain absolute visibility over your VPN intranet.
Why NetAlertX? The Business Case for Proactive Monitoring
For business readers, the primary concern is risk management. Why invest time in NetAlertX rather than relying solely on VPN logs? The answer lies in context and immediacy. NetAlertX doesn't just log connections; it builds a historical database of known devices. Key benefits include:
- Automated Discovery: Continuous scanning via ARP, DNS, and ICMP ensures no device remains hidden for long.
- Instant Notification: Integration with tools like Telegram, Gotify, or Email ensures the IT team is notified within seconds of a breach.
- Vendor Identification: By analyzing MAC addresses, it identifies the hardware manufacturer, helping distinguish between an authorized company laptop and a suspicious third-party device.
- Low Resource Overhead: It is lightweight enough to run on a budget VPS alongside your VPN server without impacting performance.
Architectural Overview: Monitoring the VPN Tunnel
When you deploy NetAlertX on a VPS, the goal is to monitor the virtual interface created by your VPN software (typically wg0 for WireGuard or tun0 for OpenVPN). Unlike a local home network where devices are connected via physical Wi-Fi or Ethernet, the VPS network consists of virtual subnets. NetAlertX must be configured to scan these specific CIDR ranges.
"Security is not a product, but a process. Monitoring the virtual interfaces of your VPN is just as vital as monitoring your physical server racks."
Step 1: Preparing Your VPS Environment
Before installation, ensure your VPS meets the basic requirements. A Linux distribution such as Ubuntu 22.04 LTS or Debian 11/12 is recommended. You will also need Docker and Docker Compose installed, as this is the most stable and portable way to run NetAlertX.
Initial Configuration
First, update your system and install essential dependencies:
sudo apt update && sudo apt upgrade -y
sudo apt install curl git software-properties-common -y
Confirm that your VPN server (WireGuard or OpenVPN) is active. You can verify the virtual interface and the IP range using the ip addr command. Take note of the subnet (e.g., 10.8.0.0/24).
Step 2: Deploying NetAlertX via Docker Compose
Docker simplifies the deployment process by encapsulating the web server, database, and scanning engines. Create a new directory for your NetAlertX installation and create a docker-compose.yml file with the following professional configuration:
- Define the image source (e.g.,
j_stuebbe/netalertx). - Map the necessary volumes for persistent data storage (config and db folders).
- Set the Network Mode to
host. This is crucial; for NetAlertX to accurately scan the network interfaces of the VPS, it needs direct access to the host network stack.
Executing docker-compose up -d will launch the service. You can then access the dashboard via http://your-vps-ip:20211.
Step 3: Configuring Scanning for the VPN Subnet
Once the dashboard is live, you must direct NetAlertX toward your VPN clients. By default, it might only scan the physical eth0 interface. Navigate to the Settings menu and locate the Network Scanning section.
Input your VPN's IP range (e.g., 10.0.0.0/24). You should also enable Active Scanning. This ensures that even if a device is configured to be 'stealthy,' the scanner will attempt to resolve its presence through multiple protocols.
Defining 'Trusted' Devices
During the first hour, NetAlertX will flag every existing VPN user as a "New Device." As an administrator, you must audit this list and mark authorized company devices as Trusted. This creates your security baseline. Any device appearing after this baseline is established will trigger a high-priority alert.
Step 4: Setting Up Real-Time Alerts
A monitoring system is only as effective as its notification mechanism. NetAlertX supports a wide array of plugins. For a professional setup, we recommend Telegram or Pushbullet for instant mobile notifications.
- Telegram: Create a Bot via BotFather, obtain your API Token and Chat ID, and input them into the NetAlertX notification settings.
- Customization: Configure the system to only alert on "New Device Found" and "Device Down" (if monitoring critical infrastructure uptime).
Best Practices for VPS Security
Running a security tool on a VPS requires the server itself to be hardened. Consider the following measures:
- Reverse Proxy: Use Nginx or Caddy with SSL/TLS certificates (Let's Encrypt) to access the NetAlertX dashboard securely via HTTPS.
- Authentication: Enable the built-in password protection in NetAlertX settings immediately.
- Firewall: Use
ufwto restrict access to the NetAlertX port (20211) only to your specific administrative IP address.
Conclusion: Toward a Zero-Trust Mentality
Deploying NetAlertX on your VPS transforms your VPN from a simple tunnel into a monitored, intelligent gateway. In an era where identity is the new perimeter, having a tool that validates the physical presence of devices on your network is an invaluable layer of defense. By following this guide, you have moved closer to a Zero-Trust Architecture, ensuring that no device—authorized or otherwise—goes unnoticed.
Regularly auditing your NetAlertX logs and keeping the software updated will ensure that your internal business data remains protected against the ever-evolving landscape of cyber threats.
