This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot open any ports via NAT or firewall rule but existing ones work?

Hi All - I am trying to enable remote access for the Plex server and it requires the opening of ports in the 32xx range. 

I enabled the following DNAT rule: TCP 1:65535 → 32400.

Unfortunately the port remains closed when testing using this site and on Plex Server's network config:
Open Port Check Tool

I tried a variety of port numbers and none of them seemed to work which is very baffling. As a last resort, I tried some common port used by RDP such as 3389 and the connection worked....

Lastly, I am also using the following rule on my UTM:

Internal (Network) -> any -> any

I've also reviewed the firewall log and below is the dropped packet:

2015:10:19-12:30:19 homestation ulogd[6592]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="ppp0" srcip="54.193.168.189" dstip="24.140.238.16" proto="6" length="60" tos="0x00" prec="0x00" ttl="47" srcport="2985" dstport="32400" tcpflags="SYN"


This thread was automatically locked due to age.
Parents Reply Children
  • IP: 54.229.139.33
    Decimal: 921013025
    Hostname: ec2-54-229-139-33.eu-west-1.compute.amazonaws.com
    ASN: 16509
    ISP: Amazon.com
    Organization: Amazon.com
    Services: None detected
    Type: Broadband
    Assignment: Static IP
    Blacklist:

    Geolocation Information

    Continent: Europe
    Country: Ireland
    State/Region: Leinster
    City: Dublin
    Latitude: 53.3389  (53° 20′ 20.04″ N)
    Longitude: -6.2595  (6° 15′ 34.20″ W)
  • Is port 32400 in your "Web Surfing" definition?  The blockage we're seeing doesn't come from "Plex_Server" - it should be for traffic going to your server.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

     

     

    Re-verify all your rules everywhere. :)

    Also more importantly plex uses that amazon ip for connectivity and metadata exchange however that is not the only ip plex uses it uses more servers then just that ip from different locations (unknown ip's as plex does not want to give the ip's out

    ! However it does look like the blocked port 32400 from plex central to your server is going to 172.xxx.xxx.xxx was that an old plex ip server you had before ?  something odd happening there (as there is also a not blocked correct call to port 32600 to ip 192.xxx.xx.xxx do you have multiple dnat rules ? Does your plex server have more then one ip ? and so on.... check everything. there should be no call going to port 32400 anymore (also possible plex central thinks there are two servers) OR

    are you using VPN to connect to your homenetwork then use plex ? 

    172.xxx.xxx.xxx looks like a vpn network setup by utm (so missing rule). Use client plex without VPN it by magic finds your server as it talks to plex central and knows the external ip of your server (whic is the utm)

    Bit hard to guess not knowing your complete setup.

  • Hi team,

     

    Indeed I have two other servers plex.
    They are connected on my internet box with upnp.

    I disabled upnp and IP WAN from UTM to DMZ.

    I do not have an IP VPN in 172.x.x.x.x.x

    After work I will make a screenshot rule "Web surfing"

  • Hi team,

     

    screenshots:

     

    Nat masquerading

     

    Firewall rule

     

     

  • Two things I see that need to be changed, Damien:

    • Add a Masquerading rule 'Internal LAN2 -> WAN'
    • In the Country Blocking Exception, instead of "Plex_Server" as the source, it should be the destination.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

    The destination is not IP plex server ?

  • Hi,

     

    can you do a simple test turn country blocking off (only coutnry blocking tab) and test your plex with mobile on external network. 

  • I have tested without but nothing.

  • "... pour le traffic provenant de ces réseaux source:"

    Le trafic provient de l'Internet.  C'est bien le Plex qui serait la destination, n'est-ce pas ?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA