Reply
New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Port forwarding on USG when using Vigor 120

Hi Guys,

I have spent the last few days struggling with a couple of issues, the first one is detailed 

below hopefully I have plenty of info here to facilitate your help already.

As seen in the below layout my parents have a partial Unifi network (I am slowly replacing items) Internally (LAN) I can connect to the camera at the end of this example using its internal address 192.168.1.103:1004 on port 1004

Network.jpg

I have port forwarding configured to these cameras as shown below

 Parents forwarding.JPG

And this has in turn created firewall exceptions as shown here

 Parents Firewall.JPG

When I look at the external address given to the USG on WAN 1 I can see the external address but when I try to connect (on another device tethered to my mobile the traffic doesn't appear to be getting through the USG (I tried a tcp dump via ssh)

 

wan address parents.JPG

 

I dont know what else to try. Am I missing something really stupid here?

 

Thanks in anticipation for your help.

 

Steve

 

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

Just to add in case it makes a difference the controller is on my network and I have the devices connected to there (without any other issues) and I have the Inform and STUN ports forwarded on my network so the device traffic can reach the controller.

Ubiquiti Employee
Posts: 1,001
Registered: ‎02-28-2017
Kudos: 298
Solutions: 104

Re: Port forwarding on USG when using Vigor 120

Run the following command on the USG:

sudo tcpdump -npi eth0 port 1004

And then test connecting to the camera from the client tethered to your phone's LTE connection again. Make sure you're connecting to the public address 92.26.x.x there, and pointing to port 1004. 

If you don't see the traffic coming in on that tcpdump, then it's not *arriving* at the USG.
If you do see the traffic coming in, then run the following: (assuming 192.168.1.103 is on eth1, not a vlan)

sudo tcpdump -npi eth1 port 1004

If you see the traffic being sent out there destined to the camera, the port forward is working. 

If you don't see traffic here, it's either missing a rule or a route. The route and rule are most likely there based off of all the info you provided, so this scenario is highly unlikely to happen.

Brandon Jaffe | UniFi Routing & Switching | Austin, TX
Highlighted
New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

Thanks, @UBNT-jaffe this is similar to what I tested the other day, however, I didn't get any traffic.

I tested as per your suggestion again just now and it appears that it is not "arriving" at the USG,

I contacted Draytek when I got similar results the other day and they advised

"The Vigor 120 is a bridge- it does not intercept any traffic so it
doesn't need a DMZ. Please contact UK support (link below) and they
can try to diagnose."

 

I will contact Draytek again but if you have any advice I would gladly accept that too :-)

 

Thanks

 

Steve

 

Ubiquiti Employee
Posts: 1,001
Registered: ‎02-28-2017
Kudos: 298
Solutions: 104

Re: Port forwarding on USG when using Vigor 120

I agree with them, what they mean by DMZ is a 1:1 NAT, that isn't needed since the public IP lives straight on your USG's WAN interface. The Draytek should pass everything through as a bridge (won't filter anything).

But if it doesn't arrive at the USG, then it's unlikely the USG is the culprit. Try opening up ICMP on WAN_LOCAL on the UniFi controller firewall rules and see if you can ping that external address from the outside.

Brandon Jaffe | UniFi Routing & Switching | Austin, TX
New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

[ Edited ]

What is ICMP on WAN_Local?  I'm not familiar with that terminology. Nevermind I found this :-)

https://help.ubnt.com/hc/en-us/articles/115003146787-UniFi-How-to-Enable-ICMP-over-WAN-with-USG-

 

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

[ Edited ]

I can confirm I can now ping the USG from external port but still nothing on the camera

 

tracert.PNG

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

I managed to get a tracert through to the external IP address now, however still blocking traffic to the ports i need.

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

I have had a response to my question about what is blocking traffic through the Vigor 120, and Drayteks response is

 

"Dear steve,

The 120 is basic modem there is not anything you can alter on the modem for this configuration. It is a plug and play device."

 

Is there something more I need to do on the USG to get the traffic to pass through?

 

Thanks

 

Steve

 

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

@UBNT-jaffe Any ideas what I need to look at next?

Ubiquiti Employee
Posts: 1,001
Registered: ‎02-28-2017
Kudos: 298
Solutions: 104

Re: Port forwarding on USG when using Vigor 120

Run the tcpdumps again I mentioned earlier in the thread. First, ping your WAN IP and instead of "port 1004", put "icmp" there and see if the traffic arrives. If it does, then put "port 1004" there again and see if it comes in, it it doesn't, something could be wrong with your testing method. How are you testing anyways?

Brandon Jaffe | UniFi Routing & Switching | Austin, TX
New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

Thanks for getting back to me @UBNT-jaffe 

The other day I tested from my home using team viewer to my dads PC and running ssh there.

 

I'll try again now

 

Thanks

 

Steve

 

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

Performed the tests again but still nothing Banghead

tcpdump.PNG

ping.PNG

Check the ip on the controller

usg.PNG

And double checked via google

ip.PNG

 

Its going to be one of those crazy stupid things but I cant see what I'm missing

 

Any insight? and thanks again for helping

 

Thanks

 

Steve

 

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

tracert.PNG

 

Hopefully this shows how I'm testing

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

@UBNT-jaffe am I testing correctly? can I help with any more info?

New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

Is anyone able to help out here?

 

really wanting to get this issue resolved 😃

 

thanks

 

steve

Ubiquiti Employee
Posts: 1,001
Registered: ‎02-28-2017
Kudos: 298
Solutions: 104

Re: Port forwarding on USG when using Vigor 120

If you're not seeing the requests come in on eth0 (WAN) when you ping it, then something else is answering for it... either that or you're sourcing your ping from "inside" your LAN (most likely what's happening). If you're sourcing that ping from inside your LAN, you won't see it ingress or egress eth0, it will only ingress/egress the eth1, nothing physically has to enter or leave eth0.

If that's the case, try it again when sourcing the ping externally, you can even use a ping-checker website to do it.

Once we have those results, we'll move further into diagnosing the port testing.

Brandon Jaffe | UniFi Routing & Switching | Austin, TX
New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

I’ll try an external website, however when I was last testing I was at my house (5 miles away from the USG I was ssh’d into) you can see on the tracert screen shot  BA539C6A-B1FC-4BB1-956D-178872F1EC44.png

does this not show the traffic coming in from an external source?

 

thanks

 

steve

Ubiquiti Employee
Posts: 1,001
Registered: ‎02-28-2017
Kudos: 298
Solutions: 104

Re: Port forwarding on USG when using Vigor 120

@herishi forget the tracert, just use icmp ping... sometimes tracert's use UDP instead of ICMP, so unless we have that information, we're gambling on the ICMP filter for the tcpdump.

Brandon Jaffe | UniFi Routing & Switching | Austin, TX
New Member
Posts: 37
Registered: ‎06-04-2017
Kudos: 4

Re: Port forwarding on USG when using Vigor 120

IMG_3049.jpg

 

Same Results when using a web based ping tool @UBNT-jaffe

Reply