Following on from my postings about DMZs and VPN servers.
I was happily testing away after following a script on t'Internet on how to set up a VPN Server (which worked nicely) when I realised that my Pi was still in the happy puppy mode where it really wanted you to login and change stuff without any of that password rubbish and it was also using default users and passwords.
So - rookie error: always step back and look at the whole picture before plunging into the fun stuff.
Cup of concrete time - harden the f*ck up before you start waving your kit at incoming calls from t'Internet.
Firewall hardened up a bit, passwords changed, but the whole thing needs a harder build as a starting point.
Cheers
Dave R