• November 01, 2024, 04:27:09 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Pages: [1] 2

Author Topic: VPN Opening ports 4500, 500  (Read 19316 times)

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
VPN Opening ports 4500, 500
« on: April 11, 2013, 03:12:47 PM »

I am trying to get a L2TP/IPSEC VPN going on one of my servers behind the DIR655 router

I have used Port Forwarding and Virtual Server and neithere seem to allow these ports to be open


in either situation a port scan shows the ports closed..My ISP (Comcast) does not block these ports



any suggestions?
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #1 on: April 11, 2013, 03:33:55 PM »

Link>Welcome!
What Hardware version is your router? Look at sticker under router.
Link>What Firmware version is currently loaded? Found on routers web page under status.
What region are you located?

What ISP Service do you have? Cable or DSL?
What ISP Modem Mfr. and model # do you have?

Link>Checking MTU Values

Some things to try: - Log into the routers web page at 192.168.0.1. Use IE, Opera or FF to manage the router.
Turn off ALL QoS or Disable Traffic Shaping (DIR only) GameFuel (DGL only and if ON.) options. Advanced/QoS or Gamefuel.
Turn off Advanced DNS Services if you have this option under Setup/Internet/Manual or under Setup/PARENTAL CONTROL/Set to>None: Static IP or Obtain Automatically From ISP.
Enable Use Unicasting (compatibility for some ISP DHCP Servers) under Setup/Internet/Manual.
Turn on DNS Relay under Setup/Networking.
Setup DHCP reserved IP addresses for all devices ON the router. Setup/Networking. This ensures each devices gets its own IP address when turned on and connected, eliminates IP address conflicts and helps in troubleshooting.
Ensure devices are set to auto obtain an IP address.
If IPv6 is an option on the router, select Local Connection Only or Disable IPv6 options under Setup/IPv6.
Set Firewall settings to Endpoint Independent for TCP and UDP under Advanced/Firewall.
Enable uPnP and Multi-cast Streaming under Advanced/Networking. Disable uPnP for testing Port Forwarding rules.
Turn off WISH, and WPS under Advanced.
WAN Port Speed set to Auto or specific speed? Some newer ISP modems support 1000Mb so manually setting to Gb speeds can be supported by the router. Advanced/Advanced Networking/WAN Port Speed
Set current Time Zone, Date and Time. Use an NTP server feature. Tools/Time.
« Last Edit: April 11, 2013, 03:44:25 PM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #2 on: April 12, 2013, 05:43:33 AM »

I am using a motorola modem unsure of model as it is a remote installation

the router is HW Version B1  Firmware Version 2.00NA


setttings are as you stated

Comcast is a cable company and does not block these 4500 or 500
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #3 on: April 12, 2013, 06:40:34 AM »

We'll need the modem model information unless you are fully sure that the modem is a stand alone modem with out a built in router.

If this modem has a built in router, it's best to bridge the modem. Having 2 routers on the same line can cause connection problems.
Double NAT
To tell if the modem is bridged or not, look at the routers web page, Status/Device Info/Wan Section, if there is a 192.168.0.# address in the WAN IP address field, then the modem is not bridged.
If the modem can't be bridged then see if the modem has a DMZ option and input the IP address the router gets from the modem and put that into the modems DMZ.

If you are using Port Forwarding, ensure the uPnP setting is disabled.
You might try setting up Virtual Server vs using PF.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #4 on: April 12, 2013, 08:29:00 AM »

I am 75% certain it is a motorola Surfboard SB6120   I am certain it has no router


Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #5 on: April 12, 2013, 08:30:48 AM »

Good modem...ya, no built in router.

Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #6 on: April 12, 2013, 08:32:55 AM »

I have tried Virtual server and PF both with no success
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #7 on: April 12, 2013, 08:37:42 AM »

Set Firewall settings to Endpoint Independent for TCP and UDP under Advanced/Firewall.
Disable uPnP for testing Port Forwarding rules?
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #8 on: April 12, 2013, 08:42:34 AM »

did all the the things you told me to in the first post
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #9 on: April 12, 2013, 08:54:12 AM »

Lets give this a try:
Download the 2.10NA fw directly from DLinks web site and unpack the .zip file.
Then follow this please:
FW Update Process

After that has been process, set up the router from scratch and use either Virtual Server or PF. If you use PF, make sure uPnP is disabled.

Setup IP reservations ON the router. Devices set to Auto IP addresses.
NAT Endpoint Independent.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #10 on: April 12, 2013, 10:24:36 AM »

hmm its a remote location.. I will be there in two weeksw and can do that then  i feel that teh reset will make the router unavailable to me

it also will ive me the option to replace it too
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #11 on: April 12, 2013, 10:41:04 AM »

Ya, if you have remote option enabled, resetting or FW update will make the option disabled.

Suggestion:
One thing you can do, if you get to the remote site and if there is a PC connected on the other side. Install Teamviewer or some similar remote access program on the PC. Now if the router remote control gets disabled by a factory reset or FW update, you can log into the remote control program on the connected PC and then gain access to the router long enough to enable the on board remote option on the router to enable it.

I use Teamviewer all the time to help review router settings and when I don't have direct remote access to the router. You'll just need to leave the remote access control program running all the time as your back up if you need this suggestion.

Keep us posted on how it goes.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #12 on: April 12, 2013, 10:44:02 AM »

I am using Logmein....  i have several mac on the "otherside"    but if I reset the router  (and it is my main router)  won't it block access even though the Mac are static IPs??
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN Opening ports 4500, 500
« Reply #13 on: April 12, 2013, 10:57:39 AM »

It should not block I believe. If Logmein uses simple HTTP authentication and connections with out any configurations of ports, then if the router is reset to factory defaults, that application should still work afterwards. I don't have any experience with that application. I do know that TV is fairly simple and doesn't need any port configuration. Why some of use use it as a back door access to the router should something like this happen to the router. Ya, if there is a problem with the WAN side, router or PC, then of course, remote connection will be a problem.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

JOHIRSH

  • Level 2 Member
  • **
  • Posts: 65
Re: VPN Opening ports 4500, 500
« Reply #14 on: April 12, 2013, 11:05:25 AM »

hmmmmmm     no port config required for Logmin


what I might try is to update my DIR 655 at my current location

I can come in from my remote location.. if i can still gain access then i can do the remote

if i can;t I at least can undo the damage

actually sounds like kind of fun  .  throw a match and see if it burns
Logged
Pages: [1] 2