Plusnet Firewall issue
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- Re: Plusnet Firewall issue
Re: Plusnet Firewall issue
03-01-2022 5:02 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
still ongoing since November not ideal!
Re: Plusnet Firewall issue
13-01-2022 12:50 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Any update on this?
I appear to be experiencing it too. I am trying to use an IPSEC VPN that uses UDP500 and UDP4500, but which has not worked since moving to a static IP address in December.
Is there any way to trace logs to identify if this is the PN Firewall? Or another separate issue?
If not fixed asap I will need to revert to a dynamic address - then possibly to a separate provider.
Re: Plusnet Firewall issue
13-01-2022 12:51 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Additionally, is there a list of ports that this firewall blocks? For each settings Low / High?
Re: Plusnet Firewall issue
13-01-2022 3:34 PM - edited 13-01-2022 3:34 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thanks for your post @keithdw
I'm really sorry to see you're having issues getting onto your VPN, because the broadband firewall's stuck in a high state.
I can try to force the firewall off, which would mean you'd have to rely on your router's and device's firewalls, because you wouldn't be able to configure the settings, due to the problem we're still working on getting to the bottom of.
Let me know if you're happy for me to go ahead and I'll see what I can do.
Full details of what the broadband firewall does can be found Here. In a high state, it blocks unauthorised incoming traffic, which will stop some things from working, like certain apps, VPN software or active FTP sessions.
Re: Plusnet Firewall issue
13-01-2022 3:49 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I'm happy to rely on my firewall, thank you...
is off, appropriate? or low? I don't recall what it was pre-static address, although i think it was probably off.
Re: Plusnet Firewall issue
13-01-2022 4:06 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thanks for getting back to me @keithdw
What's interesting is that it appears your broadband firewall has been in a high state for a long time as far back as I can see and that's two years, because there's nothing (from what I can see) to suggest changes have been made in that time.
This means that you'd have had a static IP previously, because when the broadband firewall is active, we automatically add a free static IP onto an account for as long as the firewall is active. This is just the way it works in our network.
I believe the firewall should be turned off now. Could you try your VPN?
Re: Plusnet Firewall issue
13-01-2022 4:54 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Oh... i deliberately requested a Static in December because we're doing so much more work related things from home, obviously, and certain clients i need to access wanted static source addresses...
I didn't take much notice prrior to then, though, but I did *think* I'd turned it off...
Now you say this though, I question my memory!
Going to try it now, will come back shortly.
ta!
Re: Plusnet Firewall issue
13-01-2022 4:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
No change - unless I need to restart routers this end?
Re: Plusnet Firewall issue
13-01-2022 5:09 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Whats also interesing is that if I had a static address, i wouldnt have needed to request one, and I wouldnt now be paying £5 extra for one... a problem for another day... i simply need this VPN to work.
The traffic is UDP, its an IPSec VPN, which is problematic at best to trace...!
Re: Plusnet Firewall issue
13-01-2022 5:13 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@keithdw wrote:
Whats also interesing is that if I had a static address, i wouldnt have needed to request one, and I wouldnt now be paying £5 extra for one...
While correct, the free static IP we added would’ve been dependent on the broadband firewall being active, and that this being always the way the service works in our network, because it didn’t used to need a static IP. It’s just in the last couple of years through some changes.
No worries though, aye I’d try rebooting your router.
Let me know how it goes.
If this post resolved your issue, please click the 'This fixed my problem' button
Re: Plusnet Firewall issue
13-01-2022 5:22 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
It may sound like a silly suggestion but I know it is.a valid check. Trying to establish a VPN from a connection within the same network boundary (LAN) wil fail. Connection has to be made from an external source. If you cannot test this then an option is to disconnect the device to link from off your network and tether it via your mobile running a hotspot - then try to link to your VPN server
Re: Plusnet Firewall issue
13-01-2022 5:25 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Also, sorry, Im just chatting to the network engineer responsible for this VPN.
He can see inbound requests from my IP on ports 500 and 4500, and he can see responses being sent. Phase1 is completing at his end, it then sends effectively an ACK, to start Phase2.
What i cannot see in the logs is those responses being received... so Phase2 is never starting, the 'Phase1 retransmit reaches maximum count and times out'.
Re: Plusnet Firewall issue
13-01-2022 5:27 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@akrypzs thanks for the response... yes, I can do that... i havent yet had a chance to, but it is the next step to confirm my internal IT department haven't done something daft with a patch... it would *not* be the first time!!!!
Re: Plusnet Firewall issue
13-01-2022 5:35 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
No joy after a restart. I'm going to take my laptop out and try tehtering it... this 'feels' like it might be the device not the network.
That said, someone on another plusnet forum suggested the routing was different for static addresses - is it possible that there's some merit in that? Are you able to trace specific traffic?
Re: Plusnet Firewall issue
13-01-2022 5:50 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Routing is slightly different between static IPs, but nothing I’d have thought that would cause an issue, compared to dynamic IPs which aren’t routed the same way.
If anything a static IP should work better than a dynamic for a VPN, in the sense that sometimes, we see issues where something’s blocking a dynamic IP, which is generally from the VPN side of things.
We don’t have any special tools to trace specific traffic, but you could try running a traceroute to the endpoint.
My knowledge I admit of networking is limited, but if @bobpullen is around, he may be able to help.
If this post resolved your issue, please click the 'This fixed my problem' button
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- Re: Plusnet Firewall issue