DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Open Port 443 to point to internal server & VPN Troubles

  • akwe-xavante
  • Topic Author
  • Offline
  • Member
  • Member
More
13 Sep 2018 14:18 #1 by akwe-xavante
Hoping someone can help me sort out a problem.

Background

Home/Office: Draytek 2860 with latest firmware
Static IP address
Dial in LAN to LAN Setup
Internal Webserver & Samba Server

Remote Holiday Cottage: Draytek 2820 with latest firmware
Dynamic IP address
Dial Out LAN to LAN Setup

I have ports 21, 22 and 80 open and pointing to my server no problem
I want to open port 443 and point it to my server too (Enabling SSL certification)

When i do this i get the warning message: "Your port configurations here have collided with the port configurations in the Management webpages. Do you wish to proceed?"

I have followed the instructions here and i still get this message: https://www.draytek.co.uk/support/guides/kb-forwarding-tcp443

Me's thinking that it may be something to do with my LAN to LAN Setup, it's a STD LAN to LAN setup but can't find any reference to it using port 443 though.
I've even tried unticking HTTPS in System Maintenance >> Management >> Internet Access Control under "Allow management from the Internet" and i still get the warning message.

I'm now stuck, can anybody offer any help at all and tell me where i'm gong wrong.

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
13 Sep 2018 14:42 #2 by hornbyp
In the Draytek instructions you linked to, as they stand, they don't actually show the management port being changed - the highlighted value is still "443 "

I assume you did actually change it to "444", or whatever you changed to SSL VPN port to?

Please Log in or Create an account to join the conversation.

  • akwe-xavante
  • Topic Author
  • Offline
  • Member
  • Member
More
13 Sep 2018 14:58 #3 by akwe-xavante
Thank you the reply, the link refers to a Draytek support guide and not my actual config.

Yes i have changed the port numbers to 444.

All i can think is that somewhere else within the configuration port 443 is being used or has been set asside for use in some way i'm unaware of.

Just thought i would perform a port scan and 21, 22, 23 and 80 are open, that's good BUT i now have another open port, port 444 as Snpp "Simple Network Paging Protocol" I'll need to find out what this all about and for, i'm assuming that i've opened port 444 as instructed in Draytek's setup guide.

Port 443 is closed still!

Now having rolled back my routers settings SSL VPN etc to default values and then performed a port scan port 443 is open! But why and what for? Is it for my LAN to LAN VPN?

Moved on a little further...... If i disable the SSL VPN Service under "VPN and Remote Access >> Remote Access Control Setup" port 443 is closed on a port scan. If i then re-enable my LAN to LAN connection a connection is established. After a port scan port 443 is closed.

Disabling my LAN to LAN configuration (Not removing the setup, just disabling it) i still get the warning message when i try to open port 443 to point to my server. A port scan shows port 443 as closed.

Please Log in or Create an account to join the conversation.

  • hopkins35
  • User
  • User
More
14 Sep 2018 20:49 #4 by hopkins35
Did you restart after making the management and SSL VPN port changes?

Please Log in or Create an account to join the conversation.

  • akwe-xavante
  • Topic Author
  • Offline
  • Member
  • Member
More
14 Sep 2018 22:44 #5 by akwe-xavante
I did yes and it makes no difference.

Please Log in or Create an account to join the conversation.

  • hopkins35
  • User
  • User
More
15 Sep 2018 12:26 #6 by hopkins35
There are several reports (mine included) of v3.8.9.1 firmware breaking NAT. Personally it caused numerous HTTPS issues including access to my webserver, some people say v3.8.9.2 fixes the issues but it didn't for me and I've had to stay on v3.8.8.8 and contemplating moving to another brand of router. So one option for you might be to try downgrading your firmware assuming you're on one of the two mentioned versions!

The forum thread in question is here https://forum.draytek.co.uk/viewtopic.php?f=2&t=22442

Please Log in or Create an account to join the conversation.