Closed but open ports
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Other forums
- :
- Tech Help - Software/Hardware etc
- :
- Closed but open ports
Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
My router is Draytek 2860ac, and I have checked that ports 443 & 5001 are defined as open✅. But if I use an online open port checker they both are "CLOSED"
I think this "Closed" signal is stopping the SSL being verified, therefore stopping the Alexa Skill.
I think I'm right, as port 443 is an important port, if it's closed no Internet!
I have also had to set up Firewall tiles for my Andrews & Arnold VOIP service.
any thoughts anyone?
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Versailles what router did you use before the upgrade ? if it was the 2860 , I assume you were using the VDSL port which IIRC is WAN1. You are now connected to the ONT using the WAN port on the 2860 which is WAN2 ?
Do you need to modify the firewall rules to be active from WAN2 rather than WAN1 ?
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I know some of the porting works as I use port 444 for my remote access - Draytek SMARTVPN. Cheers Stu.
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Versailles AIUI the port will show as closed unless the NAS is actually running the Lets encrypt script. Only then will it (the NAS) be listening.
Although if this all worked previously on an FTTC(VDSL) connection and you've changed the NAT rules to WAN2 , the same rules should still work. Is there any useful info in the draytek log ?
TBH its a while since I've used a Draytek router. I used to have a 2830 but when I moved to FF it couldn't handle the throughput!
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Not looked at the logs, as not sure what I'm looking for. From inside the NAS, I can obtain a SSL, but when I try to link it to Audiostation it fails to connect and if I try to link it on the amazon skills page, it says that it's not a valid SSL. confused or what!
could it be a conflict between an "Open Port rule" and my VOIP Firewall rules, but I thought ports 80 or 443 were always open, but according to online test their closed!
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
could it be a conflict between an "Open Port rule" and my VOIP Firewall rules
@Versailles i wouldn't have thought so, voip (SIP I assume?) would normally use port 5060 as the sip port and any rtp ports would be much higher.
Although I'm not quite sure why you would need rules for voip anyway. Normally its just a matter of ensuring the your voip equipment is configured for 'NAT keep alive' and then the router will keep the NAT pinhole open. I use voip myself and have not needed to add any firewall rules.
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
HTH
Re: Closed but open ports
Monday - last edited Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Do not confuse inbound and outbound ports.
For most routers used for domestic internet all outbound ports are open, you would have to open inbound ports as required using port forwarding rules.
Edit: there are some exceptions for some inbound ports but they are not used by all applications
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@MisterW - I just followed the instructions & recommendations from my provider Andrews and Arnold, basically so only data/connections linked to their IP addresses would get through to my phone - it works so I don't really want to adjust too much on those settings
@mystreet1 - Cheers for the info.
@Dan_the_Van - Yes only trying to set inbound ports to get this Alexa Skill to work.
I think I'm going to have a deep dive into my VOIP firewall rules to see what being block and not. -If, no when I get it sorted I will add a final post just in case someone else has the same problem(s).
Re: Closed but open ports
Monday - last edited Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Versailles yes I'm aware of the suggestion by A & A to restrict incoming connections to only their servers. In reality it's not needed unless you are running a PBX and using SRV records. If you are using normal VoIP equipment which registers a connection with A & A then any incoming connections will only come from the server you are registered to. So the normal NAT firewall will handle it and open a pinhole to just the a & a server thus blocking any unwanted connection. Just make sure you have keep-alive set to keep the pinhole open .
I use a & a at home with a gigaset n300 dect base , and know at least two other people who use it without needing any firewall rules.
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Closed but open ports
Monday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thats very interesting, I have Groundstream 802 as VOIP to phone interface, Gigaset base station, so that sounds very similar to you. I will have to get in touch with A&A and ask why the need for a firewall! 🤔
Re: Closed but open ports
Tuesday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Versailles they no longer suggest a need for a Firewall if you are using NAT https://support.aa.net.uk/VoIP_Firewall
I have Groundstream 802 as VOIP to phone interface, Gigaset base station, so that sounds very similar to you
Not quite the same as mine, I just have a Gigaset N300 VOIP Dect unit and so don't need the Grandstream ATA. However I know others who are using the Grandstream ATA sucessfully with A & A. Just make sure that SIP keep alive is enabled.
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Closed but open ports
Tuesday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I think it would be helpful if you described your home network, is everything connecting to the Draytek 2860ac or is there another device involved?
Having back to back routers causes double NAT and issue with port forward rules.
Re: Closed but open ports
Tuesday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
FTTP to Bt ONT,
ONT to Groundstrean 802 that connects to my Gigaset E45,
ONT to Draytek Vigor 2860ac,
from router to an 8 port switch,
Switch to Synology 218j NAS, 2 Desktops, printer and TV. Internally, 4 SSID's, Private, Guests, It's and o dedicated Alexa.
Going to leave this for a few days, apparently I have a list, and that doesn't include anything tech related 😢🙄.
Thanks so far, have a good one Stu.
Re: Closed but open ports
Tuesday
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Other forums
- :
- Tech Help - Software/Hardware etc
- :
- Closed but open ports