DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Open Port 443 to point to internal server & VPN Troubles
- akwe-xavante
- Topic Author
- Offline
- Member
Less
More
- Posts: 107
- Thank yous received: 0
13 Sep 2018 14:18 #92884
by akwe-xavante
Open Port 443 to point to internal server & VPN Troubles was created by akwe-xavante
Hoping someone can help me sort out a problem.
Background
Home/Office: Draytek 2860 with latest firmware
Static IP address
Dial in LAN to LAN Setup
Internal Webserver & Samba Server
Remote Holiday Cottage: Draytek 2820 with latest firmware
Dynamic IP address
Dial Out LAN to LAN Setup
I have ports 21, 22 and 80 open and pointing to my server no problem
I want to open port 443 and point it to my server too (Enabling SSL certification)
When i do this i get the warning message: "Your port configurations here have collided with the port configurations in the Management webpages. Do you wish to proceed?"
I have followed the instructions here and i still get this message:
https://www.draytek.co.uk/support/guides/kb-forwarding-tcp443
Me's thinking that it may be something to do with my LAN to LAN Setup, it's a STD LAN to LAN setup but can't find any reference to it using port 443 though.
I've even tried unticking HTTPS in System Maintenance >> Management >> Internet Access Control under "Allow management from the Internet" and i still get the warning message.
I'm now stuck, can anybody offer any help at all and tell me where i'm gong wrong.
Background
Home/Office: Draytek 2860 with latest firmware
Static IP address
Dial in LAN to LAN Setup
Internal Webserver & Samba Server
Remote Holiday Cottage: Draytek 2820 with latest firmware
Dynamic IP address
Dial Out LAN to LAN Setup
I have ports 21, 22 and 80 open and pointing to my server no problem
I want to open port 443 and point it to my server too (Enabling SSL certification)
When i do this i get the warning message: "Your port configurations here have collided with the port configurations in the Management webpages. Do you wish to proceed?"
I have followed the instructions here and i still get this message:
Me's thinking that it may be something to do with my LAN to LAN Setup, it's a STD LAN to LAN setup but can't find any reference to it using port 443 though.
I've even tried unticking HTTPS in System Maintenance >> Management >> Internet Access Control under "Allow management from the Internet" and i still get the warning message.
I'm now stuck, can anybody offer any help at all and tell me where i'm gong wrong.
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank yous received: 0
13 Sep 2018 14:42 #92885
by hornbyp
Replied by hornbyp on topic Re: Open Port 443 to point to internal server & VPN Troubles
In the Draytek instructions you linked to, as they stand, they don't actually show the management port being changed - the highlighted value is still "443
"
I assume you did actually change it to "444", or whatever you changed to SSL VPN port to?
I assume you did actually change it to "444", or whatever you changed to SSL VPN port to?
Please Log in or Create an account to join the conversation.
- akwe-xavante
- Topic Author
- Offline
- Member
Less
More
- Posts: 107
- Thank yous received: 0
13 Sep 2018 14:58 #92886
by akwe-xavante
Replied by akwe-xavante on topic Re: Open Port 443 to point to internal server & VPN Troubles
Thank you the reply, the link refers to a Draytek support guide and not my actual config.
Yes i have changed the port numbers to 444.
All i can think is that somewhere else within the configuration port 443 is being used or has been set asside for use in some way i'm unaware of.
Just thought i would perform a port scan and 21, 22, 23 and 80 are open, that's good BUT i now have another open port, port 444 as Snpp "Simple Network Paging Protocol" I'll need to find out what this all about and for, i'm assuming that i've opened port 444 as instructed in Draytek's setup guide.
Port 443 is closed still!
Now having rolled back my routers settings SSL VPN etc to default values and then performed a port scan port 443 is open! But why and what for? Is it for my LAN to LAN VPN?
Moved on a little further...... If i disable the SSL VPN Service under "VPN and Remote Access >> Remote Access Control Setup" port 443 is closed on a port scan. If i then re-enable my LAN to LAN connection a connection is established. After a port scan port 443 is closed.
Disabling my LAN to LAN configuration (Not removing the setup, just disabling it) i still get the warning message when i try to open port 443 to point to my server. A port scan shows port 443 as closed.
Yes i have changed the port numbers to 444.
All i can think is that somewhere else within the configuration port 443 is being used or has been set asside for use in some way i'm unaware of.
Just thought i would perform a port scan and 21, 22, 23 and 80 are open, that's good BUT i now have another open port, port 444 as Snpp "Simple Network Paging Protocol" I'll need to find out what this all about and for, i'm assuming that i've opened port 444 as instructed in Draytek's setup guide.
Port 443 is closed still!
Now having rolled back my routers settings SSL VPN etc to default values and then performed a port scan port 443 is open! But why and what for? Is it for my LAN to LAN VPN?
Moved on a little further...... If i disable the SSL VPN Service under "VPN and Remote Access >> Remote Access Control Setup" port 443 is closed on a port scan. If i then re-enable my LAN to LAN connection a connection is established. After a port scan port 443 is closed.
Disabling my LAN to LAN configuration (Not removing the setup, just disabling it) i still get the warning message when i try to open port 443 to point to my server. A port scan shows port 443 as closed.
Please Log in or Create an account to join the conversation.
- hopkins35
- Offline
- Junior Member
Less
More
- Posts: 84
- Thank yous received: 0
14 Sep 2018 20:49 #92900
by hopkins35
Replied by hopkins35 on topic Re: Open Port 443 to point to internal server & VPN Troubles
Did you restart after making the management and SSL VPN port changes?
Please Log in or Create an account to join the conversation.
- akwe-xavante
- Topic Author
- Offline
- Member
Less
More
- Posts: 107
- Thank yous received: 0
14 Sep 2018 22:44 #92901
by akwe-xavante
Replied by akwe-xavante on topic Re: Open Port 443 to point to internal server & VPN Troubles
I did yes and it makes no difference.
Please Log in or Create an account to join the conversation.
- hopkins35
- Offline
- Junior Member
Less
More
- Posts: 84
- Thank yous received: 0
15 Sep 2018 12:26 #92905
by hopkins35
Replied by hopkins35 on topic Re: Open Port 443 to point to internal server & VPN Troubles
There are several reports (mine included) of v3.8.9.1 firmware breaking NAT. Personally it caused numerous HTTPS issues including access to my webserver, some people say v3.8.9.2 fixes the issues but it didn't for me and I've had to stay on v3.8.8.8 and contemplating moving to another brand of router. So one option for you might be to try downgrading your firmware assuming you're on one of the two mentioned versions!
The forum thread in question is here
https://forum.draytek.co.uk/viewtopic.php?f=2&t=22442
The forum thread in question is here
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek