What's new

Portforwarding suggestions please!

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

iugrifma

Occasional Visitor
Hi all,
I've got a small problem and need to pick your collective brains for a solution.
I am trying to setup an SSL VPN connection to my SOHO network from out on the road (hotels mainly). But have run into an issue. My ISP.

I bought a Netgear SRXN3205 which seemed to offer all the enterprise functionality you could hope for. Including SSL VPN software & functionality built in. Nice.

However, my ISP (unknown to me at the time) blocks incoming connections to my IP address on port 443 (https). Which means that I can't get a connection from the outside world to my router to start the VPN process.

I managed to "partially" get round this problem using the SRXN3205's firewall, by setting up a rule to forward, from the WAN side, any connections coming in on another (non-blocked) port back to 443.

Behold! My VPN webpage and software are visible, but on trying to login I run into another problem. The VPN software (VirtualPassage) is partially Java based, partically dll binary code (from a third part provider, who also use the same software in Cisco Linksys equipment) and basically touching the VPN website starts a chain reaction where by the software is downloaded to your client PC and installed automatically then executed automatically (everytime you logon).
The software even removed itself when you close your session.

And here's my problem. Somewhere in the midst of the Java or dll's is a parameter that says to make a connection (independantly from the webpage) on, you guessed it 443! Doh!

So, does anyone have any ideas how I might fool the software and allow it and it's config to make the call on 443 but really forward it to my secret port that works ? I'm primarily working off Windows based clients by the way.

Any help gratefully received.

Griffo.
 
You are going to have to either contact the VPN solution vendor and ask if its possibler to customize the port it uses. Or to use a different method of VPN. Or get your ISP to unblock the port and/or find out why its being blocked.

What is on the inside of the network you are VPNing to? do you happen to have a windows server there?
 
Just to confirm..the Netgear SRX obtains the public IP on its WAN interface, correct? It's not double NAT'd somehow behind an ISP supplied gateway?

When you want business network functionality on your network....without limits imposed by your ISP on home networks....tis best to upgrade your home account to a business account.
 
the port used for ssl-vpn on the srxn3205 can be customized under administration -> remotemanagement.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top