cancel
Showing results for 
Search instead for 
Did you mean: 

Closed but open ports

Versailles
Hooked
Posts: 9
Registered: Monday

Closed but open ports

I had full fibre installed end of October 2024. Before upgrade, I could stream music from my Synology Nas to me Amazon Alexa via port 5001, using the AudioStation Skill. This skill needs a signed SSL certificate to operate, Synology offer certificates from "Lets Encrypt" and utillises port 443 for verification.
My router is Draytek 2860ac, and I have checked that ports 443 & 5001 are defined as open. But if I use an online open port checker they both are "CLOSED"
I think this "Closed" signal is stopping the SSL being verified, therefore stopping the Alexa Skill.
I think I'm right, as port 443 is an important port, if it's closed no Internet!
I have also had to set up Firewall tiles for my Andrews & Arnold VOIP service.
any thoughts anyone?
20 REPLIES 20
MisterW
Superuser
Superuser
Posts: 16,354
Thanks: 6,282
Fixes: 451
Registered: ‎30-07-2007

Re: Closed but open ports

@Versailles what router did you use before the upgrade ? if it was the 2860 , I assume you were using the VDSL port which IIRC is WAN1. You are now connected to the ONT using the WAN port on the 2860 which is WAN2 ?

Do you need to modify the firewall rules to be active from WAN2 rather than WAN1 ?

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Versailles
Hooked
Posts: 9
Registered: Monday

Re: Closed but open ports

@MisterW, Hi, yes ONT is connected to WAN2 port and NAT open port rules are for WAN2, moved from WAN1 when switched to fibre.
I know some of the porting works as I use port 444 for my remote access - Draytek SMARTVPN. Cheers Stu.
MisterW
Superuser
Superuser
Posts: 16,354
Thanks: 6,282
Fixes: 451
Registered: ‎30-07-2007

Re: Closed but open ports

@Versailles AIUI the port will show as closed unless the NAS is actually running the Lets encrypt script. Only then will it (the NAS) be listening.

Although if this all worked previously on an FTTC(VDSL) connection and you've changed the NAT rules to WAN2 , the same rules should still work. Is there any useful info in the draytek log ?

TBH its a while since I've used a Draytek router. I used to have a 2830 but when I moved to FF it couldn't handle the throughput!

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Versailles
Hooked
Posts: 9
Registered: Monday

Re: Closed but open ports

@MisterW, Yes, if it used to work it should now

Not looked at the logs, as not sure what I'm looking for. From inside the NAS, I can obtain a SSL, but when I try to link it to Audiostation it fails to connect and if I try to link it on the amazon skills page, it says that it's not a valid SSL. confused or what!
could it be a conflict between an "Open Port rule" and my VOIP Firewall rules, but I thought ports 80 or 443 were always open, but according to online test their closed!
MisterW
Superuser
Superuser
Posts: 16,354
Thanks: 6,282
Fixes: 451
Registered: ‎30-07-2007

Re: Closed but open ports

could it be a conflict between an "Open Port rule" and my VOIP Firewall rules

@Versailles i wouldn't have thought so, voip (SIP I assume?) would normally use port 5060 as the sip port and any rtp ports would be much higher.

Although I'm not quite sure why you would need rules for voip anyway. Normally its just a matter of ensuring the your voip equipment is configured for 'NAT keep alive' and then the router will keep the NAT pinhole open. I use voip myself and have not needed to add any firewall rules.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

mystreet1
Aspiring Pro
Posts: 144
Thanks: 59
Fixes: 2
Registered: ‎26-01-2024

Re: Closed but open ports

Looking at my router for my Synology NAS, I have ports 80,443,5001 and 5002 forwarding to the ip of my NAS
HTH
Was a member for years, but moved from PN fttc to fttp from an AltNet. Getting 940Mb up and down. Happy to stay on here and try to help others. 
Dan_the_Van
Hero
Posts: 3,157
Thanks: 1,573
Fixes: 90
Registered: ‎25-06-2007

Re: Closed but open ports

@Versailles 

Do not confuse inbound and outbound ports. 

For most routers used for domestic internet all outbound ports are open, you would have to open inbound ports as required using port forwarding rules.

Edit: there are some exceptions for some inbound ports but they are not used by all applications

Versailles
Hooked
Posts: 9
Registered: Monday

Re: Closed but open ports

@MisterW -  I just followed the instructions & recommendations from my provider Andrews and  Arnold, basically so only data/connections linked to their IP addresses would get through to my phone - it works so I don't really want to adjust too much on those settings

@mystreet1 -  Cheers for the info.

@Dan_the_Van -  Yes only trying to set inbound ports to get this Alexa Skill to work.


I think I'm going to have a deep dive into my VOIP firewall rules to see what being block and not. -If, no when I get it sorted I will add a final post just in case someone else has the same problem(s).

MisterW
Superuser
Superuser
Posts: 16,354
Thanks: 6,282
Fixes: 451
Registered: ‎30-07-2007

Re: Closed but open ports

@Versailles yes I'm aware of the suggestion by A & A to restrict incoming connections to only their servers. In reality it's not needed unless you are running a PBX and using SRV records. If you are using normal VoIP equipment which  registers a connection with A  & A then any incoming connections will only come from the server you are registered to. So the normal NAT firewall will handle it and open a pinhole to just the a & a server thus blocking any unwanted connection. Just make sure you have keep-alive set to keep the pinhole open .

I use a & a at home with a gigaset n300 dect base , and know at least two other people who use it without needing any firewall rules.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Versailles
Hooked
Posts: 9
Registered: Monday

Re: Closed but open ports

@MisterW.
Thats very interesting, I have Groundstream 802 as VOIP to phone interface, Gigaset base station, so that sounds very similar to you. I will have to get in touch with A&A and ask why the need for a firewall! 🤔
MisterW
Superuser
Superuser
Posts: 16,354
Thanks: 6,282
Fixes: 451
Registered: ‎30-07-2007

Re: Closed but open ports

@Versailles they no longer suggest a need for a Firewall if you are using NAT https://support.aa.net.uk/VoIP_Firewall

 I have Groundstream 802 as VOIP to phone interface, Gigaset base station, so that sounds very similar to you

Not quite the same as mine, I just have a Gigaset N300 VOIP Dect unit and so don't need the Grandstream ATA. However I know others who are using the Grandstream ATA sucessfully with A & A. Just make sure that SIP keep alive is enabled.

 

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Dan_the_Van
Hero
Posts: 3,157
Thanks: 1,573
Fixes: 90
Registered: ‎25-06-2007

Re: Closed but open ports

@Versailles 

I think it would be helpful if you described your home network, is everything connecting to the Draytek 2860ac or is there another device involved?

Having back to back routers causes double NAT and issue with port forward rules.

Versailles
Hooked
Posts: 9
Registered: Monday

Re: Closed but open ports

Uncomplicated set-up of:g
FTTP to Bt ONT,
ONT to Groundstrean 802 that connects to my Gigaset E45,
ONT to Draytek Vigor 2860ac,
from router to an 8 port switch,
Switch to Synology 218j NAS, 2 Desktops, printer and TV. Internally, 4 SSID's, Private, Guests, It's and o dedicated Alexa.
Going to leave this for a few days, apparently I have a list, and that doesn't include anything tech related 😢🙄.
Thanks so far, have a good one Stu.
Versailles
Hooked
Posts: 9
Registered: Monday

Re: Closed but open ports

@MisterW "they no longer suggest a need for a Firewall if you are using NAT https://support.aa.net.uk/VOIP Firewall" that was the information I followed, and understood was needed to be added to give a trouble free VOIP Service. 🤔