cancel
Showing results for 
Search instead for 
Did you mean: 

External connections via port forward/DMZ are received, but the response is not

FIXED
rfolwell
Hooked
Posts: 5
Thanks: 1
Registered: ‎18-02-2018

External connections via port forward/DMZ are received, but the response is not

Odd one this.  I am hoping that someone else has seem the same symptoms and has an explanation for them.

I have a web server connected to the internet using either port forwarding or by placing the machine in the DMZ (I tried both approaches, with the same results).  When testing internally against the 192.168.1.x address it all works fine.  When I connect from outside (I tried 3 completely different external locations) the initial connection is successful and I can see an entry in the webserver auth log, but nothing is received by the remote client.

I have a static internet IP address.

I spoke to PlusNet support today, but it seems that they no longer have the kind of technical expertise to help with a problem like this.

Has anyone else seen these symptoms?  Does anyone have an explanation?

8 REPLIES 8
adrianscotter
Pro
Posts: 240
Thanks: 152
Fixes: 2
Registered: ‎28-10-2016

Re: External connections via port forward/DMZ are received, but the response is not

It's not something silly like software firewall is it?

Live long and prosper!
rfolwell
Hooked
Posts: 5
Thanks: 1
Registered: ‎18-02-2018

Re: External connections via port forward/DMZ are received, but the response is not

I am fairly sure it is not a firewall problem (but of course could be wrong).  The machine running the webserver currently has no firewall running on it (checked with iptables -L), and the incoming request gets to the webserver (nginx) fine.  If I connect directly to the webserver using the PlusNet router provided IP address (not localhost or similar) then it works fine (so hairpinning on the router is working - though not relevant to the problem I am seeing).

If there was a firewall then it would have to be somewhere in the PlusNet network which, though possible, seems unlikely, particularly in the context of a response to an already accepted connection.

All three external hosts that I tried from can connect without problems to internet websites.

adrianscotter
Pro
Posts: 240
Thanks: 152
Fixes: 2
Registered: ‎28-10-2016

Re: External connections via port forward/DMZ are received, but the response is not

I'm not that familiar with Linux so my help will be limited...  I recently had an issue where Mr A. N. Other had set up his own webserver at home (on Virgin) for sharing family photos / videos across the world with other family members and had used IP address reservations via the router but had forgotten about an IP camera that he'd fixed manually on nnn.nnn.nnn.2 and forwarded ports 5000 and 554 to it.  He managed to allocate the same address to his 'server' with the obvious end result of it didn't work properly.  I'd try setting everything up on DHCP first, then reserver the relevant addresses, if it cures the issue, you can then set addresses up as you would like them.

Live long and prosper!
rfolwell
Hooked
Posts: 5
Thanks: 1
Registered: ‎18-02-2018

Re: External connections via port forward/DMZ are received, but the response is not

Thanks for the suggestion, but I am fairly sure it is not that.  The webserver's internal IP address does come from DHCP, and there are no statically allocated IP addresses on that subnet.  If I had done something similar and forgotten I would expect to also see problems when connecting internally, which I do not.

Can anyone confirm that they have this working with PlusNet, just so I know it is worth persisting?

j4m3s
Newbie
Posts: 2
Thanks: 8
Fixes: 1
Registered: ‎20-02-2018

Re: External connections via port forward/DMZ are received, but the response is not

Fix

Hi - 

 

Could be an incorrect or missing default gateway on your webserver? 

 

Cheers, 

bobpullen
Community Gaffer
Community Gaffer
Posts: 16,869
Thanks: 4,950
Fixes: 315
Registered: ‎04-04-2007

Re: External connections via port forward/DMZ are received, but the response is not

What port is the service running on?

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

rfolwell
Hooked
Posts: 5
Thanks: 1
Registered: ‎18-02-2018

Re: External connections via port forward/DMZ are received, but the response is not

Thanks for that - spot on!  The webserver machine is multi-homed, with the externally mapped ports on a secondary network interface.  There were two default routes (for some reason, nothing I had done explicitly) with the one with the lowest metric being the wrong one.  With the default route set to use the secondary network interface (the gateway had always been correct) then it all starts to work.

This explains why I could connect locally, using the same internal IP as the port forwarding, as there was an explicit route for local connections.

So not PlusNet's problem at all, but a basic configuration mistake in my network.

rfolwell
Hooked
Posts: 5
Thanks: 1
Registered: ‎18-02-2018

Re: External connections via port forward/DMZ are received, but the response is not


@bobpullen wrote:
What port is the service running on?

I had services running on port 80, 8080, 443 and 22.  The problem was, as suggested by j4m3s, an incorrectly configured default gateway.