Minimize the attack envelope.
443 (HTTPS) and 1194 (VPN), both outbound only.
Your traffic flows in through a tunnel instantiated by an outbound connection.