DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Weird port forwarding/HTTP issue that I'm stuck with

  • oviano
  • Topic Author
  • User
  • User
More
25 Sep 2020 11:27 #1 by oviano
I have two routers, one in London, a 2927, and one in Istanbul a 2860.

I can access each router's admin page using the fixed public IP address, from each LAN, and I can ping each router from the other.

The 2860 has a Synology NAS behind it, which I usually access via both HTTP and HTTPS on ports 5000 and 5001 respectively using port forwarding on the 2860.

I can therefore usually access the Synology NAS from the connection in London....except, it does not work. The web page for the NAS just does not load anything. When this happens, I can observe the NAT session on the 2860, listed in Active NAT Sessions, so the connection has obviously been made, but it apparently does not send any data back to the browser. I do not know at what point the data is "dropped".

If, however, I attempt to connect to the 2860/NAS through a different Internet connection (a 4G connection) using the same laptop device it *does* work.

This combination has me a bit stuck! Clearly the 2927 can reach the 2860, otherwise the ping and access to the 2860's admin page would not work.

Clearly the port forwarding on the 2860 to the NAS is setup correctly, otherwise the NAS wouldn't be accessible when I connect to it over a 4G connection instead of the connection through my 2927.

Also, this worked until recently, but I *think* it has stopped working since I upgraded to the 2927. However, this coincided with also upgrading my Internet connection from BT to G.Network so I can't be sure at what point it stopped working.

I have spoken to G.Network and they cannot see any reason why it wouldn't work. From their point of view, there is nothing wrong with the routing between the G.Network and the ISP in Turkey as evidence by the ping working, and the fact I can access the 2860 web page from the 2927. And I cannot argue with that logic!

So, perhaps some sort of issue with the 2927? I have checked the various firewall etc settings, but I cannot see or think of anything that might prevent data from the remote NAS reaching my browser. Furthermore, the same 2927 can access another remote router (a 2862) and access other devices behind that 2862 using port forwarding.

Finally, the 2860 maintains a VPN connection to the 2927 (it dials-in to the 2927). If I attempt to connect to the NAS from the 2927 LAN using the address of the NAS on the 2860 LAN, i.e. over the VPN, then this does work and I can access the NAS. My first and obvious thought was that maybe the VPN itself was causing the issue, but even when I disconnect the VPN I still cannot access the NAS behind the 2860 using the public IP address and port forwarding.

I'm stumped!

Please Log in or Create an account to join the conversation.

  • service_bb
  • User
  • User
More
25 Sep 2020 12:08 #2 by service_bb
If it works over VPN but not on the WAN side, I'd hazard a guess it's related to MTU at one of the ends.

I remember having a very similar problem with a 2860 on vDSL a few years back, the default MTU is 1492 - it was resolved by dropping the MTU to 1442.

Could try similarly at each end.

Please Log in or Create an account to join the conversation.

  • oviano
  • Topic Author
  • User
  • User
More
25 Sep 2020 12:43 #3 by oviano
Brilliant, that has solved my issue. Thank you so much. I ran the MTU detect option on the router in Turkey and it required a lower value.

Now if only I'd posted this a few days ago I wouldn't have torn so much hair out, and I've be less bald :D

Please Log in or Create an account to join the conversation.