Page 1 of 1

SE VPN Server Ports.

Posted: Mon Aug 28, 2023 3:35 pm
by goomba
We are a little frustrated with settings for the VPN server.

These are the ports we have open on our internet facing inbound router firewall rules;

TCP:
443,992,1194, 8443

UDP:
1701,500,555

Additionally, we have allowed all connections in Windows 10 Firewall for the above ports and also a rule for the VPN Server Application as well (this is a default setting).

Yet our users always get a message regarding "Punch Through???" and when connecting to the VPN server it is slow and we periodically get disconnected.

We have ran External Internet Port checkers and they all report that none of our ports are open, but internal port scans and using telnet we can confirm connecting to each specific TCP ports.

We have tried turning of the WINDOWS firewall and still have the same issue.

We also setup a Ubuntu server with the same configuration and still same results.

Users can connect, just making sense to us.

Any Ideas???

Re: SE VPN Server Ports.

Posted: Mon Aug 28, 2023 3:50 pm
by solo
goomba wrote:
Mon Aug 28, 2023 3:35 pm
These are the ports we have open on our internet facing inbound router firewall rules
...
We have ran External Internet Port checkers and they all report that none of our ports are open
You need to FORWARD these ports. Also your ISP may not allow incoming connections.

Re: SE VPN Server Ports.

Posted: Mon Aug 28, 2023 4:13 pm
by goomba
Sorry, when I say OPEN, I mean FORWARDED.

All our clients have static IP and nothing blocked.

We have rhe same issue with our internal VPN Server and we host Mail, Web and a host of other services and we know for sure nothing is blocked. Same thing with clients.

Any other ideas?

Re: SE VPN Server Ports.

Posted: Mon Aug 28, 2023 6:45 pm
by solo
https://www.vpnusers.com/viewtopic.php? ... 513#p99915

EDIT

"we host Mail, Web" - so forwarding TCP 443 to SE is not interfering with the web server?

Re: SE VPN Server Ports.

Posted: Mon Aug 28, 2023 7:45 pm
by goomba
We have 4 statics, our web email etc are all on different servers, different front facing routers.

This is purely a SE issue, he is on a different ip and different router.

Even so, does not explain why this happens with clients, some of which only have ports/traffic sent to se server.

Re: SE VPN Server Ports.

Posted: Tue Aug 29, 2023 4:06 am
by solo
goomba wrote:
Mon Aug 28, 2023 7:45 pm
This is purely a SE issue, he is on a different ip and different router.
No, let's make a quick test - on the SE server PC enable RDP, forward its port and try to connect from one of those clients.

Re: SE VPN Server Ports.

Posted: Tue Aug 29, 2023 12:58 pm
by goomba
Yes they ALL can.

Re: SE VPN Server Ports.

Posted: Tue Aug 29, 2023 2:02 pm
by solo
https://www.vpnusers.com/viewtopic.php? ... 372#p89372

Is it the same server? What was the SE problem in that RDP case?