Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TP-Link Kasa Smart Plugs and XG

Hi,

 

I run TP-Link Kasa Smart Plugs in my house. I have noticed that when trying to control remotely, they grey out on either iOS or Android. If I connect to the local network, the plug displays "Local Only". According to TP-Link this message indicates that remote access is not enabled on the plug but when I look into the settings it is.

 

TP-Link doesn't give much assistance with their devices but I found a website which says that the plugs use Ports:

  • 80 TCP
  • 9999 TCP
  • 1040 UDP

So I reserved their IP's and created two new firewall rule as follows:

Group: Smart Switches

Firewall 29: Kasa Services

Source Zones: LAN

Source Networks and devices: "My two devices"

Destination Zones: WAN

Destination Networks: Any

Services: Kasa Ports which is a port group TCP Source: 1:65535 > 80 | TCP Source: 1:65535 > 9999 | UDP Source: 1:65535 > 1040

No Scan HTTP, HTTPS, Block Google, Scan FTP

No IPS, Traffic Shaping, Web Policy, App Control

Firewall 30: Smart Switches

Source Zones: LAN

Source Networks and devices: "My two devices"

Destination Zones: WAN

Destination Networks: Any

Services: Any

No Scan HTTP, HTTPS, Block Google, Scan FTP

No IPS, Traffic Shaping, App Control

Web Policy: All All

 

I can see traffic going out as "Allowed" in logging and all looks fine from the XG side, but the switches are still inaccessible.

Why I think it's the XG... If I remove the XG from my network and plug in my D-Link DIR850L Router, I can access the smart switches remotely with no problem.

 

Thank you in advance.



This thread was automatically locked due to age.
Parents
  • Hi,

    Two things that can be happening:

    1) It's using other's ports to communicate, probably to a cloud service, can you check the Logs and filter just for the device on it? Also can you set Firewall 29 Services as ANY to confirm this?

    Or

    2) As much I hate to know some IoT devices needs this (There should be no need for this.), Doesn't this IoT device requires port forwarding, for remote access? Since It works with your D-Link router - It must be using UPnP for port forwarding, something that XG doesn't support.

    Looking at your Device I've found:

    80/tcp HTTP
    9999/tcp TP-Link Smart Home Protocol
    1040/udp TP-Link Device Debug Protocol (TDDP)

    The 80/TCP is a web server that always returns 200 OK, no matter what you send to it, so there's no need to port forward it, 1040 is just for debug, so your left with 9999/TCP.

    If your sure It needs port forwarding, then - Can you create a DNAT Rule with port 9999/TCP for the IoT Device?

    You can follow here, on how to create it.

     

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • Thank you, I can do this, but I have more than one smart device. How will I port forward to multiple devices?

     

  • Hi,

    First, can you confirm If 1) or 2) solved your first issue?

    Looking at tp-link website, there should be a central management for the devices, It's better to know first why their not available for the WAN right now with XG, then we can look at the rest.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • First, can you confirm If 1) or 2) solved your first issue?

     

    Thanks, I created a DNAT rule just on the one switch and no joy.

     

    Also, no logging to that particular ID thus far

     

  • Hi,

    you do not need fancy rules, just a normal firewall rule and MASQ in the NAT.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
  • rfcat_vk said:
    you do not need fancy rules, just a normal firewall rule and MASQ in the NAT.

     

    Hi Ian, can you elaborate a little more so I can understand exactly what you think is required?

  • Hi Daniel,

    I have a number IoT devices and the only rules after checking all the ports they require as I advised earlier are

    source LAN -> IoT device addresses or network -> Destination WAN -> any -> services (as you find them) -> allow always -> log -> NAT -> MASQ (no web proxy, but I do use IPS to try an classify the traffic for reporting, doesn't work).

     

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • source LAN -> IoT device addresses or network -> Destination WAN -> any -> services (as you find them) -> allow always -> log -> NAT -> MASQ (no web proxy, but I do use IPS to try an classify the traffic for reporting, doesn't work).

    Do you mean like this?

     

    If so, that is how I originally had it (for weeks) with no joy on having it work correctly.

  • Pleas try with just the network in lieu of the individual device addresses. I have some bad experiences recently where changing to network and changing back fixed the issue, I don't understand.

    Then review the logviewer for  the associated device IP addresses looking for connection ports and denied access.

    Further as Prism said your router will pass uPNP whereas there XG will not. One of my IoT devices I was trying out for home management would only work with uPNP enabled and I consider that protocol a security risk, so the device is in the e-recycle bin.

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Understood. I created a new rule at the very top to the network and still the problem persists.

  • Hi Daniel,

    the aim of this test was to collect data in logviewer. Did you review logviewer searching on each IP address of your devices and what did you find in successful and denied connections in the various reports?

    Ian

    XG115W - v20.0.3 MR-3 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • All actions were allowed, and the following services from the smart switches:

    8443

    123

    3475

    53