<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules! in Broadband &amp; Landline</title>
    <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630697#M141912</link>
    <description>&lt;P&gt;It does appear to be the&amp;nbsp;UPnP issue; Plex had added the rule - but I had created this manually for a single port - so I changed the configuration in Plex (not to use&amp;nbsp;&lt;SPAN&gt;UPnP), this then removed the automatic rule from the hub; I've disabled DMZ and left all the existing rules as-is - and it works!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As stated, badly written, poorly tested firmware.&lt;/P&gt;&lt;P&gt;I'm leaving well alone now - it works and won't be making any additional changes to save more firmware disasters!&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jul 2026 12:56:30 GMT</pubDate>
    <dc:creator>Hyperjase</dc:creator>
    <dc:date>2026-07-24T12:56:30Z</dc:date>
    <item>
      <title>Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629769#M141613</link>
      <description>&lt;P&gt;Just had a 20 minute call with a tech "trying" to resolve an issue with a brand new Super Hub 7 Plus (just fitted on full fibre today).&lt;/P&gt;&lt;P&gt;Had a load of firewall rules for different devices, different ports - so I copied these all over as they were.&lt;/P&gt;&lt;P&gt;First problem, I had the DHCP range set to 192.168.1.50 &amp;gt; 192.168.1.253, but obviously I could use anything &amp;lt; 192.168.1.50 - to which most of my devices which had firewall rules assigned were set to - on this new awful "thing", the IP addresses disappear and show the MAC address; but then, as they're outside the DHCP range&amp;nbsp; - the IP addresses show as "N/A" and when you select ONE you select ALL of them!&amp;nbsp; Making this a totally unusable feature.&amp;nbsp; This was working on my previous hub (not full fibre) - without issue.&amp;nbsp; Firmware written by someone who doesn't have a clue obviously.&lt;/P&gt;&lt;P&gt;But this then led to the next problem.&amp;nbsp; Added all the firewall rules in - all good (apart from the fact the original DHCP issue meant I couldn't actually remove or add any new ones, had to factory reset this thing!).&lt;/P&gt;&lt;P&gt;But as I have a web server - running port 443 (HTTPS) - this was not working.&amp;nbsp; Checked via a port checker website - all ports EXCEPT 443 were working!&amp;nbsp; So I tested the theory via DMZ; guess what - IT WORKS!&amp;nbsp; So I disabled DMZ, then the port was showing as closed again - despite the fact I've removed and readded several times.&amp;nbsp; Port 80 assigned to the same device - working fine.&lt;/P&gt;&lt;P&gt;Screwy firmware, badly written - I've raised a complaint but doubt it will come to anything.&lt;/P&gt;&lt;P&gt;The only good thing is the speed is better now - but now I have to FULLY expose a Windows server to open port 443!!!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Broken firmware version: r4.27.0-R-1862249-PROD-84001&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 12:11:05 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629769#M141613</guid>
      <dc:creator>Hyperjase</dc:creator>
      <dc:date>2026-07-20T12:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629797#M141615</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/5025695"&gt;@Hyperjase&lt;/a&gt;&amp;nbsp;Can you first check your version in case you did it wrong, the one below is reported by others. If your version is lower please say, you could have a new one and that is the OOB FW applied and the sucker has not been FW updated as yet, surprised EE did not say if you raised that with them.... Reference to all the EE is EE Smart Hub 7 Plus as the version although it may just change again, so everyone is sure just getting used to the New EE naming conventions at present....&lt;/P&gt;&lt;P&gt;FW: r4.27.1-R-1862254-PROD-84001 and the gui is at App version 3.14.5 13/07/2026&lt;/P&gt;&lt;P&gt;Nothing we can do about the DHCP scope, that is what it is with EE's setup for all there hubs and the reserved space that they have decided. Do believe that others have port https:443 open and working so will tag&amp;nbsp;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/2696281"&gt;@bobpullen&lt;/a&gt;&amp;nbsp;he can say as got the same 7 Plus as you but not sure which ports he is using. Let's just wait till he reply's....&lt;/P&gt;&lt;P&gt;There is a few oops on the 7 Plus to start with and PF sure is one off those.... Cluelessness may be one off the factor's just not for me to say, know what i mean....&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 14:02:40 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629797#M141615</guid>
      <dc:creator>JimM11</dc:creator>
      <dc:date>2026-07-20T14:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629808#M141620</link>
      <description>&lt;P&gt;I tried everything - I even reset the hub; the only way I could get port 443 to work was through DMZ, had to lock the server down - not an ideal situation.&lt;/P&gt;&lt;P&gt;The GUI version on mine is&amp;nbsp;&lt;SPAN&gt;3.14.5 - I see there is a slight difference in my firmware version - I wonder if there's a fix between these two versions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hopefully something simple and can be resolved - just frustrating!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 14:53:32 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629808#M141620</guid>
      <dc:creator>Hyperjase</dc:creator>
      <dc:date>2026-07-20T14:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629811#M141623</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/5025695"&gt;@Hyperjase&lt;/a&gt;&amp;nbsp;The person that i tagged has extensive knowledge in using the 7 Plus version, so if he comes back when time permits for him if he is using port 443:https wise and working for him he will say, again the Hub is new just out Jan has had a somewhat rocky road to even get were it is currently, and the wheels on the EE bus just go one pace and that is slowly, there will be NO Instant get it done and fixed for sure.... That's why i said you FW may be the OOB out off box as delivered to you being just new Factory supplied version, the usual is connect it up and the FW gets updated, re-boots etc but it all depends on what is going on etc in EE land..... DMZ is the get out off jail and testing advised to see what happens, relying on how good your server Fire Wall is working now, but you are well aware from your posted start!&lt;/P&gt;&lt;P&gt;Also here is the EE FW pinned post on the opening Forum top page....&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.ee.co.uk/t5/Broadband-Landline/EE-Hub-firmware-versions/td-p/1624543" target="_blank"&gt;(2) EE Hub firmware versions - The EE Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 15:05:44 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629811#M141623</guid>
      <dc:creator>JimM11</dc:creator>
      <dc:date>2026-07-20T15:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629939#M141671</link>
      <description>&lt;P&gt;FYI I've just checked and it appears the firmware has updated, it's now showing as&amp;nbsp;&lt;SPAN&gt;r4.27.1-R-1862254-PROD-84001&amp;nbsp; - but still having to use DMZ to get port 443 open, I have just disabled DMZ and left TCP 443 open against the MAC address of the device in question - with DMZ disabled, still not showing as open, so I've had to re-enable DMZ.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 08:07:45 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1629939#M141671</guid>
      <dc:creator>Hyperjase</dc:creator>
      <dc:date>2026-07-21T08:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630307#M141790</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/5025695"&gt;@Hyperjase&lt;/a&gt;&amp;nbsp;- I've managed to successfully forward port 443 using 7 Plus previously. In my case it was forwarded to a reverse proxy, then onward forwarded to various local web servers. Couple of questions spring to mind: -&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What machine is the HTTPS server running on? Windows ot something else? If it's Windows, then have you ensured the Network connection Properties in Windows haven't reverted from 'Private' to 'Public' when swapping the hub out?&lt;/LI&gt;&lt;LI&gt;What does your list of port forwarding rules look like? Are there any 'greyed out' UPnP rules present? This has been found to be a problem previously if the UPnP rule sits above the one you're trying to create - see &lt;A href="https://community.ee.co.uk/t5/Broadband-Landline/Smart-Hub-7-Plus-Port-Forwarding-Issue/m-p/1611414/highlight/true#M135983" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Unsure I'm following what you observed with the 'N/A' LAN IP's? Are you saying that devices assigned IP's outside of the hub's DHCP range were showing an 'N/A' IP address in the Hub Manager? And that this was somehow stopping you from creating a port forwarding rule? In what way exactly? It's also unclear to me why you had to factory reset things after trying?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 13:16:23 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630307#M141790</guid>
      <dc:creator>bobpullen</dc:creator>
      <dc:date>2026-07-22T13:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630643#M141893</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/2696281"&gt;@bobpullen&lt;/a&gt;&amp;nbsp;thanks for the reply, to clarify these points:&lt;/P&gt;&lt;P&gt;I was using an older EE hub on a "super fast" broadband (not full fibre) line - and I had all the rules set up correctly, DHCP was assigned to be 192.168.1.50 &amp;gt; 192.168.1.253, also Dynamic DNS enabled; all has been working absolutely brilliantly.&lt;/P&gt;&lt;P&gt;So when I received the new Super Hub, I configured exactly the same; DHCP range as previously set up.&amp;nbsp; All my servers were assigned IP address outside of this range (192.168.1.10 &amp;gt; 192.168.1.24).&amp;nbsp; When I then attempted to add these out-of-dhcp-range devices to the firewall rules; it shows you a list of devices, their MAC address and assigned IP address (again, on the previous hub - no issues with this).&amp;nbsp; When I wanted to select my Windows Server (192.168.1.21) - I could figure this out by the MAC address, but the IP address wasn't shown, but just "N/A" - along with two other Linux servers (I didn't hang around long enough to figure out which was which) - so there were 3 different devices with MAC addresses showing and all displayed "N/A" for the IP address.&amp;nbsp; Clicking the MAC address of the Windows Server; all 3 were selected!!&amp;nbsp; I couldn't actually only select 1 - selecting any of the 3, would select all 3.&amp;nbsp; So I did test this, and this wasn't the solution as it used the first MAC address.&lt;/P&gt;&lt;P&gt;I then attempted to change it to use the IP address, but was met with an error each time.&amp;nbsp; I couldn't update them, I couldn't delete them - hence I was forced to factory reset the hub.&lt;/P&gt;&lt;P&gt;So that mess aside (and I'm sorry - this is just badly built, badly tested firmware), I then changed the DHCP scope to include the servers and made them all static (they are static on the servers themselves anyway).&lt;/P&gt;&lt;P&gt;Then I began opening ports (and I have multiple; around 10 in total for different reasons) - all worked well adding - but did spot yet another issue.&amp;nbsp; Adding a firewall rule in, then putting the port (eg 443 in all 4 boxes), then setting to TCP only - if you then change the drop-down to be TCP/UDP, it says the range is wrong!&amp;nbsp; The left two port boxes display red.&amp;nbsp; Yet more badly written firmware.&lt;/P&gt;&lt;P&gt;But - as I find these little annoying issues, I get to the end and test my web server connectivity - dead.&amp;nbsp; Won't load anything.&amp;nbsp; So I use a website to check ports open.&amp;nbsp; Port 443 - closed.&amp;nbsp; Port 80 - open!&amp;nbsp; Along with ALL the other ports I'd opened on the hub, just not 443.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brainwave to fix EE's badly written and tested firmware; use DMZ - not idea but solves their mess.&amp;nbsp; DMZ works, but obviously exposes the server to the internet - security risk or what!&amp;nbsp; This is a Windows Server 2019 running just IIS but has internal connectivity to multiple SQL Express servers (no external access).&amp;nbsp; I lock this down best I can to only permit IIS (port 80/443) as access.&amp;nbsp; This solves my issue.&lt;/P&gt;&lt;P&gt;There is one PnP Firewall Rule - which sits at the top of the list.&amp;nbsp; I will review the link you provided above.&lt;/P&gt;&lt;P&gt;For clarity, the Windows Server network is showing as Private.&lt;/P&gt;&lt;P&gt;Maybe some of this is on me - but I would half expect it work the same between hub versions.&amp;nbsp; The DHCP mess required a factory reset to resolve, thankfully it had only been in a few minutes so wasn't a big issue.&amp;nbsp; But it does seem like there are bugs - most of which I think I found!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 08:54:08 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630643#M141893</guid>
      <dc:creator>Hyperjase</dc:creator>
      <dc:date>2026-07-24T08:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630697#M141912</link>
      <description>&lt;P&gt;It does appear to be the&amp;nbsp;UPnP issue; Plex had added the rule - but I had created this manually for a single port - so I changed the configuration in Plex (not to use&amp;nbsp;&lt;SPAN&gt;UPnP), this then removed the automatic rule from the hub; I've disabled DMZ and left all the existing rules as-is - and it works!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As stated, badly written, poorly tested firmware.&lt;/P&gt;&lt;P&gt;I'm leaving well alone now - it works and won't be making any additional changes to save more firmware disasters!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 12:56:30 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630697#M141912</guid>
      <dc:creator>Hyperjase</dc:creator>
      <dc:date>2026-07-24T12:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Super Hub 7 Plus - unless you want DMZ - forget port 443 on Firewall Rules!</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630749#M141922</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/5025695"&gt;@Hyperjase&lt;/a&gt;&amp;nbsp;Well done, just another uPnP FW update introduction to mess with Port Forwarding rules. Think that one is on the EE Radar 7 Plus wise and if they are seeing the posted threads the 6 Plus may just be doing it also... Factory reset with the uPnP devices disabled until you get all the Manual ones in seems to be the work around at present although not a pretty way to be doing it all.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 15:48:52 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Super-Hub-7-Plus-unless-you-want-DMZ-forget-port-443-on-Firewall/m-p/1630749#M141922</guid>
      <dc:creator>JimM11</dc:creator>
      <dc:date>2026-07-24T15:48:52Z</dc:date>
    </item>
  </channel>
</rss>

