NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
lippy
May 06, 2012Aspirant
FVS318N Can’t Port Forward
Okay. I’m throwing the uncle card.
I can’t get the FVS318N to port forward. I’m trying to forward port 1723 (PPtP) for VPN into our server. I get out, I hit the server, but it is being blocked on the return by the FVS318N. A port scan shows the same. I can change the port from “Stealth” to “Closed”, when I port scan and can’t get any further.
Client (Dell D830; XP, Static IP) --> Switch (HP 1810G) --> FVS318N --> Modem (Motorola SB5101) --> IP Provider (DHCP; no ports blocked)
1. Security > Services > Custom Service Table: create custom TCP service for PPtP on port 1723
2. Security > Firewall > LAN WAN Rules: Create custom Inbound Service Rule.
- Tried both the preconfigured PPtP service in the FVS318N and the manually created custom service;
- Tried both the static IP client address and the router address in the "Send to LAN Server";
- The LAN device addresses have been reconfigured to 192.168.124.1 +;
- Tried bypassing the switch, with direct Ethernet into the FVS318N (rule out the hop from the switch);
- The Client has Zone Alarm as anti-virus with firewall. Tried to open a port in the firewall; likewise, shutdown Zone Alarm (rule out the AV/Firewall software);
- Tried a port scan from another client running Vista with the same results (rule out the AV/Firewall software and O.S. and machine);
What am I missing?
I can’t get the FVS318N to port forward. I’m trying to forward port 1723 (PPtP) for VPN into our server. I get out, I hit the server, but it is being blocked on the return by the FVS318N. A port scan shows the same. I can change the port from “Stealth” to “Closed”, when I port scan and can’t get any further.
Client (Dell D830; XP, Static IP) --> Switch (HP 1810G) --> FVS318N --> Modem (Motorola SB5101) --> IP Provider (DHCP; no ports blocked)
1. Security > Services > Custom Service Table: create custom TCP service for PPtP on port 1723
2. Security > Firewall > LAN WAN Rules: Create custom Inbound Service Rule.
- Tried both the preconfigured PPtP service in the FVS318N and the manually created custom service;
- Tried both the static IP client address and the router address in the "Send to LAN Server";
- The LAN device addresses have been reconfigured to 192.168.124.1 +;
- Tried bypassing the switch, with direct Ethernet into the FVS318N (rule out the hop from the switch);
- The Client has Zone Alarm as anti-virus with firewall. Tried to open a port in the firewall; likewise, shutdown Zone Alarm (rule out the AV/Firewall software);
- Tried a port scan from another client running Vista with the same results (rule out the AV/Firewall software and O.S. and machine);
What am I missing?
20 Replies
- TGlagowskiAspirantDUNNO if I can actually access it from a remote location I am not at one, I am at my local site.
I can access the HTTP server using the local LAN address AOK.
I can access the HTTP server using the NETBIOS name AOK.
I can PING the WEB URL using the router or the Windows command line client, NS lookup says the Dynamic DNS is routing me to the WAN IP that my ISP has given me via DHCP.
My FVS318 (non wireless router) worked AOK, but the new FVS318N (wireless router) does NOT seem to be letting me access the server by using the WEB URL.
Do you have an explanation or a setting that will fix this?
Terry :) - TGlagowskiAspirantMore Information...
My wife connected using here iPhone NOT on the LAN but using cell wireless...
I got the following response when trying to reach the WEB URL...
Error 502 bad gateway response error - a bad response was received from another proxy server or the destination origin server...
This did NOT happen when I was using the FVS318 (non-wireless router).
???
Terry :) - jmizoguchiVirtuosoThat means loop back issues that router can not handle if you can use private ip but not with actual domain
If remote user can access http then loop back issues
Most prosafe supports but looks like it is not on this model - TGlagowskiAspirantI hope I didn't just waste $150 for this new FVS318N router when the old FVS318 was working... I wanted a more up to date piece of equipment that is 10 years newer, perhaps with more advanced capabilities, AND better wireless than the old WG602.
Let me go over the specifics to make sure you and I are on exactly the same page.
My DynDNS URL is www.glagowski.org (glagowski.DynDns.org)
Currently as of right now, the ISP DHCP is 99.37.18.144.
On the LAN side, I'm using 192.168.9.* subnet, the router is 192.168.9.1
The HTTP server \\CONTEST is 192.168.9.6 manually set IP but on WLAN not LAN, and definitely NOT on the DMZ port #8.
From another computer on the same LAN:
In MSIE, if I issue http://CONTEST the WEB Server works.
In MSIE, if I issue http://192.168.9.6 the WEB Server works.
In console if I issue ping www.glagowski.org I get a response.
If I issue ping 99.37.18.144 I get a response.
If I issue NSLOOKUP www.glagowski.org I get the correct IP.
This indicates my Dynamic DNS is working correctly...
However, in MSIE if I issue http://www.glagowski.org I get the following:
"The server at www.glagowski.org is taking too long to respond"
Note, this MSIE is located on the same LAN as the server.
From iPhone I get the 502 error...
Everything worked AOK with the older FVS318 (non wireless) when I setup the port service for HTTP (port 80) from the WAN to the LAN 192.168.9.6 NAT translation...
I gotta think that there is some other little magic secret in the FVS318N settings that I don't have set right, not that the FVS318N is incapable of this very basic function...
Terry :) - TGlagowskiAspirantWell...
It's working AOK now...
I connected the server using ethernet wired connection to ethernet port #3 on the router and disabled the wireless adapter on the server and enabled the wired adapter on the server and setup the IP addresses accordingly.
I then went directly to the DynDns web site and manually updated the ISP DHCP IP so that NSLOOKUP gets the current IP at the router.
Everything now works to use the external URL to access the WEB server using NAT...
I DON'T know what was wrong, or what I did to fix it...
Could it be that the FVS318N doesn't like doing NAT to wireless devices?
I'll do another experiment tomorrow to verify that is the problem or not...
Thanks for your replies even if they didn't solve the problem...
Terry :) - aditMentorIt could have had the wrong default gateway programmed. It could have also been a problem if you had 2 NIC's enabled with which both had default gateway settings programmed.
- TGlagowskiAspirantAs a follow up on the FVS318N port forwarding issue...
This evening when I got home from work, I setup the WEB server on a WLAN adapter instead of a wired LAN adapter and the port forwarding still worked.
SO... its a mystery as to why I had so much trouble getting a basically straightforward feature working in the first place, but all is well...
It seems like the FVS318N is operating a little faster than the old FVS318 did.
I would expect SOME kind of improvements for 10 years advancement in technology!
Now... moving on to setting the security a little better for this LAN system!
Thanks for all who replied - Terry : ) - jmizoguchiVirtuosoSometime patient off and not rush it:)
Enjoy - LisaNelsAspirantI'm having the same type of issues.... I had a working linksys router configured to pass only ports 5060, and 10000-20000 to my pbx. Simple, worked great.
This fvs318n is not working at all, I've tried just those ports, and then also tried ANY. I've been fighting this since 4.0 firmware... it's too unstable to put in a business environment.
Having a inbound rule to pass ANY to my PBX should not only allow my pbx to connect to the trunks, but also open up my server to attacks... I'd settle for that if I could at least get it half-way working...
:mad: - aditMentor
An Inbound ANY Rule to your PBX opens all ports to Internet.LisaNels wrote: I'm having the same type of issues.... I had a working linksys router configured to pass only ports 5060, and 10000-20000 to my pbx. Simple, worked great. This fvs318n is not working at all, I've tried just those ports, and then also tried ANY. I've been fighting this since 4.0 firmware... it's too unstable to put in a business environment. Having a inbound rule to pass ANY to my PBX should not only allow my pbx to connect to the trunks, but also open up my server to attacks... I'd settle for that if I could at least get it half-way working... :mad:
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!