Technical Discussion
  >> Home Networking, Internet Connection Sharing, etc.


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | 3 | (show all)   Print Thread
Standard User Peterdevon
(learned) Mon 08-Jul-24 09:14:06
Print Post

Draytek 2925 port forwarding


[link to this post]
 
I am trying to forward port 80 to NAS drive, I have changed the ports in the management setup and added port forwarding rule in NAT/port redirection but 80 still remains closed, has anyone had this problem?
Standard User copex
(committed) Mon 08-Jul-24 19:52:36
Print Post

Re: Draytek 2925 port forwarding


[re: Peterdevon] [link to this post]
 
i would strongly advise against using port 80, use https 443,

in port redirect src port 8443 dest port 443 on all interfaces for https

or

in port redirect src port 8080 dest port 80 on all interfaces for http

to access from the outside world, use https://{public ip}:8443 or http and :80 for http
Standard User danielhyde
(committed) Tue 09-Jul-24 09:37:32
Print Post

Re: Draytek 2925 port forwarding


[re: Peterdevon] [link to this post]
 
That won't work if you still access the DrayTek web admin on port 80.
But as said above opening port 80 is not good and ideally https access should be used.

Thanks
Dan


Register (or login) on our website and you will not see this ad.

Standard User Peterdevon
(learned) Tue 09-Jul-24 12:28:59
Print Post

Re: Draytek 2925 port forwarding


[re: danielhyde] [link to this post]
 
I have changed the web admin to 8080 and SSH to 4433 so in theory the redirects on 80 to local ip:80 and 443 to local ip:443 should work but they don't
Standard User Michael_Chare
(knowledge is power) Tue 09-Jul-24 13:01:01
Print Post

Re: Draytek 2925 port forwarding


[re: Peterdevon] [link to this post]
 
I use a Wireguard VPN for remote access. The client runs on my Windows 10 laptop. More secure than port forwarding.

Michael Chare
Standard User Zadeks
(experienced) Tue 09-Jul-24 13:08:35
Print Post

Re: Draytek 2925 port forwarding


[re: Peterdevon] [link to this post]
 
Try a port above 1024.
Standard User fguk
(newbie) Tue 09-Jul-24 13:59:47
Print Post

Re: Draytek 2925 port forwarding


[re: Peterdevon] [link to this post]
 
I'm not sure how to explain it not working on port 80, but do you need to disable or redirect SSL VPN as well for port 443?

Also, presume you have set it to TCP, and to All WAN connections within the NAT rule. Made sure you are up to date with the Firmware just in case?

I also presume from your PC connection (internal to the NAS) that connection to the management pages is fine?

Silly question, but you are on a fixed IP on your WAN side that doesn't use anything like CGNAT etc etc? Or you have DDNS setup etc?

Got anything else forwarding using NAT, so you know all is well with the router?
Standard User Peterdevon
(learned) Tue 09-Jul-24 14:37:36
Print Post

Re: Draytek 2925 port forwarding


[re: fguk] [link to this post]
 
By default the SSl VPN is on port 443 so have changed to 4433
Firmware is the latest.
Ports are open on NAS drive
Fixed IP address
No other ports forwarded
It worked on aTP Link router but have changed as all IPv6 is open on the internet
Standard User nofappingway
(member) Mon 15-Jul-24 14:50:43
Print Post

Re: Draytek 2925 port forwarding


[re: Peterdevon] [link to this post]
 
I would strongly advise not publishing the WebGUI of your NAS to the public internet. It's a far more secure solution to VPN into your Draytek and access your NAS.

If you wish to proceed anyway, your Draktek will be using the most of the standard ports so you'll need to publish a non-standard port. You'll also want to use the Firewall to restrict who can access that port once open. For example, block all Countries except the country you reside in would be a great place to start. Lock it down further if you can.
Standard User DFScale
(member) Mon 15-Jul-24 17:19:33
Print Post

Re: Draytek 2925 port forwarding


[re: nofappingway] [link to this post]
 
In reply to a post by nofappingway:
IYou'll also want to use the Firewall to restrict who can access that port once open. For example, block all Countries except the country you reside in would be a great place to start.

Not possible to use a firewall to bock by country. The internet is not organised in that way.
Pages in this thread: 1 | 2 | 3 | (show all)   Print Thread

Jump to