Back to articles
Technology Insight

Securing Your Remote Infrastructure: Deploying NetAlertX on a Linux VPS to Detect Intruders in VPN Networks

June 1, 2026

Introduction to VPN Security Challenges

In the modern corporate landscape, the widespread adoption of remote work has made Virtual Private Networks (VPNs) a cornerstone of business infrastructure. By creating secure, encrypted tunnels over the public internet, VPNs allow employees to access sensitive internal resources from anywhere in the world. However, this decentralized approach introduces a critical vulnerability: the expansion of the network perimeter. When a remote device connects to your corporate VPN, that device essentially becomes a part of your internal network. If an employee's home router is compromised, or if a rogue device manages to exploit VPN credentials, an intruder can gain unhindered access to your entire corporate subnet.

Traditional network monitoring tools are often designed for localized physical architectures, making them difficult or expensive to deploy across cloud-hosted VPN environments. To mitigate the risk of lateral movement by unauthorized actors, businesses need a lightweight, real-time network scanning solution. This is where NetAlertX comes into play. When deployed on a cloud-based Linux Virtual Private Server (VPS), NetAlertX acts as an automated digital sentry, constantly scanning your VPN subnets, cataloging connected devices, and instantly alerting administrators to the presence of unrecognized or anomalous intruders.

What is NetAlertX and Why Choose It?

NetAlertX (formerly known as Pi.Alert) is an open-source, highly customizable network security scanner designed to detect new devices, track active connections, and monitor changes in network topology. Unlike heavy enterprise intrusion detection systems (IDS) that require deep packet inspection and massive computational overhead, NetAlertX focuses primarily on network discovery and presence detection using active and passive scanning techniques.

Key advantages of utilizing NetAlertX for business VPN monitoring include:

  • Real-Time Alerts: Integrates seamlessly with communication channels like Slack, Telegram, Discord, and email to notify IT teams the exact moment an unknown MAC or IP address appears.
  • Multi-Protocol Scanning: Combines multiple scanning methods—including arp-scan, ping, nmap, and DNS resolution—to ensure comprehensive visibility, even across complex virtual interfaces.
  • Lightweight Footprint: It can run comfortably on a low-spec Linux VPS, minimizing infrastructure costs while maintaining robust, 24/7 surveillance.
  • Historical Logging: Maintains a detailed registry of when devices first connected, their last seen timestamps, and changes in their network behavior, which is invaluable for forensic audits.

Prerequisites for Deployment

Before initiating the installation process, ensure your environment meets the following baseline requirements:

  1. A Linux VPS: A virtual private server running a stable, LTS distribution such as Ubuntu 22.04/24.04 LTS or Debian 12. A minimal configuration of 1 vCPU and 1GB to 2GB of RAM is generally sufficient for small to medium-sized VPN networks.
  2. An Active VPN Server: A fully configured VPN server (such as OpenVPN, WireGuard, or SoftEther) hosted either on the same VPS or within a routable cloud private network (VPC) where the VPS has interface-level access to the VPN subnet.
  3. Root or Sudo Access: Administrative privileges on the Linux VPS to install dependencies, manage network interfaces, and configure system containers.
  4. Docker and Docker Compose: The recommended and most reliable method for deploying NetAlertX is via containerization, ensuring isolated dependencies and simplified upgrade paths.

Step-by-Step Guide: Deploying NetAlertX on Linux

Step 1: System Optimization and Docker Installation

First, log in to your Linux VPS via SSH and update the system repositories to guarantee all existing packages are secure and up to date. Execute the following commands in your terminal:

sudo apt update && sudo apt upgrade -y

Once the update completes, install Docker and the Docker Compose plugin by executing the official Docker convenience script or utilizing your distribution's repository manager:

sudo apt install -y docker.io docker-compose-plugin
sudo systemctl enable --now docker

Step 2: Identifying the VPN Network Interface

NetAlertX needs to know which network interface it should monitor. Because a VPN operates on virtual network adapters, you must identify the correct interface name (often designated as tun0, wg0, or tap0). Run the following command to list all active network interfaces and their associated IP subnets:

ip a

Locate the interface corresponding to your corporate VPN subnet. Note down the interface name and the CIDR notation of the subnet (for example, 10.8.0.0/24). This information is crucial for configuring NetAlertX's scan parameters.

Step 3: Creating the Docker Compose Configuration

Create a dedicated directory for NetAlertX to keep your configuration files organized, and navigate into it:

mkdir -y ~/netalertx && cd ~/netalertx

Next, use a text editor such as nano to create a docker-compose.yml file:

nano docker-compose.yml

Paste the following production-ready configuration structure into the file, ensuring you modify the environment variables to align with your specific infrastructure requirements:

version: "3"
services:
netalertx:
image: jokob/netalertx:latest
container_name: netalertx
network_mode: "host"
volumes:
- ./config:/app/config
- ./db:/app/db
environment:
- TZ=Asia/Ho_Chi_Minh
- PORT=20211
restart: unless-stopped

Note: Using network_mode: "host" is highly recommended for NetAlertX because it allows the container direct access to the host's virtual network interfaces, enabling accurate ARP and ICMP scanning across the VPN tunnel without NAT distortion.

Step 4: Customizing Scan Targets and Notification Webhooks

Save and close the file. Start the container once to allow it to generate its initial configuration structure, then pause it to edit the parameters:

docker compose up -d
docker compose stop

Navigate to the newly generated configuration directory and open the primary configuration file, typically named app.conf or managed via the web UI. Within the configuration settings, locate the SCAN_SUBNETS variable and define your VPN network range:

SCAN_SUBNETS = ['10.8.0.0/24']

To ensure immediate awareness of potential security breaches, configure the integration for notification services. If your organization utilizes Telegram, define the Bot Token and Chat ID parameters within the alert section. This guarantees that if a rogue client joins the VPN, an automated alert is instantaneously dispatched to your IT security group.

Step 5: Launching and Accessing the Application

With configurations finalized, relaunch the NetAlertX container in detached mode:

docker compose up -d

Open a web browser and navigate to the IP address of your VPS followed by the assigned port (e.g., http://your-vps-ip:20211). You will be greeted by the NetAlertX dashboard initialization wizard, where you can establish administrative credentials and lock down the interface.

Best Practices for VPN Intrusion Detection

Deploying the software is only the initial phase; maintaining an optimized configuration is essential for maximizing its efficacy. Consider implementing the following operational best practices:

  • Establish a Strict Device Whitelist: During the first week of deployment, carefully audit the discovered devices. Work with your system administrators to match MAC and IP addresses to legitimate employees, marking them as "Trusted" or "Whitelisted" within the NetAlertX database.
  • Enforce Regular Nmap Scans: Configure NetAlertX to periodically run deep nmap scans against active hosts. This helps detect if an authorized device has unexpectedly opened insecure ports, which could indicate a malware infection or unauthorized service hosting.
  • Secure the Web Dashboard: Never leave the NetAlertX port exposed directly to the public internet without protection. Implement a reverse proxy like Nginx or Traefik equipped with SSL certificates, or restrict access to the dashboard port entirely so that it can only be accessed by administrators who are themselves connected to a management VPN.

Conclusion

Securing a business network requires continuous vigilance, and relying solely on perimeter defenses like usernames and passwords is no longer sufficient. By deploying NetAlertX on a Linux VPS, organizations can implement an automated internal checkpoint within their private VPN tunnels. This setup guarantees complete visibility into every connected asset, transforming a blind spot into a well-monitored environment. By taking proactive control over your network monitoring today, you ensure that unauthorized intruders are identified and isolated before they can impact your critical business data.

Securing Your Remote Infrastructure: Deploying NetAlertX on a Linux VPS to Detect Intruders in VPN Networks | DPTCloud