×

Introducing the Orbi 970 Series Mesh System with WiFi 7(BE) technology. For more information visit the NETGEAR Press Room.

Orbi WiFi 7 RBE973
Reply

Port Forwarding for IPsec

gordo5
Aspirant

Port Forwarding for IPsec

I don't want to use the built in vpn server and I've set up a RAS server at home and I can successfully connect to it locally using either PPTP or L2TP/IPsec.  I've also created a port forwarding rule in the orbi to forward tcp/1723 for PPTP and I can successfully connect to it from a remote location.

 

IPsec requires IP protocol 50 for Encapsulated Security Protocol (ESP) and IP protocol 51 for Authentication Header (AH), as well as UDP/500.  How can I forward this traffic through the ORBI?  I would prefer to just use L2TP/IPsec.

 

Model: RBR50|Orbi AC3000 Tri-band WiFi Router
Message 1 of 6
CrimpOn
Guru

Re: Port Forwarding for IPsec

Have you tried creating rules for these ports just as you did for the PPTP?

When creating rules, I ignore the drop down menu and create everything as a "Custom Rule".  Give it a cool name, enter the port, select TCP and/or UDP.

Message 2 of 6
gordo5
Aspirant

Re: Port Forwarding for IPsec

Well, that is actually the problem.  The custom rule only allows you to select ports in Protocol  6 (TCP) and Protocol 17 (UDP).  IPSec uses Protocol 50 (ESP) and Protocol 51 (AH).

 

Here is a nice summary:

https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml

 

I saw the dropdown had a pre-defined rule for PPTP, which can be config'd using the custom rules.  If the custom rules won't allow you to configure IPsec, it would be nice if it was included in the pre-defined dropdown.

 

Message 3 of 6
CrimpOn
Guru

Re: Port Forwarding for IPsec

Of course, you are correct.  (I now have a Dunce Cap for every day of the week!)  Looks like you are stuck with either PPTP  on the RAS or OpenVPN (on the Orbi itself).  I have been very happy with OpenVPN on my Orbi.

 

Perhaps you could hack at the iptables.  I know that Voxel's custom firmware for the RBR50 allows customizing iptables.  (I am also happy with this firmware.  Probably fat and dumb as well.)

Message 4 of 6
schumaku
Guru

Re: Port Forwarding for IPsec

ESP can never work as the NAT router would only translate the "outer" IP addresses, but there is no port information, ... so things will go bulloks.

 

Look for L2TP/IPsec with NAT-T, here the ESP packets will be encpasulated in packets using port 4500/UDP.¨. Before, IKE will run on 500/UDP. AFAIK that's all you need to expose by adding forward rules.

Message 5 of 6
gordo5
Aspirant

Re: Port Forwarding for IPsec

Thanks.  I wasn't aware of the NAT issue with ipsec.  I've moved onto SSTP, which just needs tcp/443.  Took a several stabs to get the certs right (or, at least, close enough), but it works now.  Too bad there isn't any native android support for it...

 

I went this route because I found the ORBI one slow.  I don't think the orbi processor is up to the task except for light duty things, like rdp.  Running my own vpn I can saturate my bandwidth.  🙂

 

Message 6 of 6
Top Contributors
Discussion stats
  • 5 replies
  • 3577 views
  • 0 kudos
  • 3 in conversation
Announcements

Orbi WiFi 7