cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Port Forwarding Smart Hub 6

79Chris79
Investigator
Investigator

I'm trying to set up port forwarding on my hub for my NAS, I've watched many videos and blogs. And trawled the forums here... But for the life of me it will not work.

Just says port is closed on port checker websites..

9 REPLIES 9
XRaySpeX
EE Community Star
EE Community Star

Let's see your Port Forwarding setting & we may be able to advise you further.

If you think I helped please feel free to hit the "Thumbs Up" button below.

To phone EE CS: Dial Freephone +44 800 079 8586 - Option 1 for Home Broadband & Home Phone or Option 2 for Mobile Phone & Mobile Broadband

ISPs: 1999: Freeserve 48K Dial-Up > 2005: Wanadoo 1 Meg BB > 2007: Orange 2 Meg BB > 2008: Orange 8 Meg LLU > 2010: Orange 16 Meg LLU > 2011: Orange 20 Meg WBC > 2014: EE 20 Meg WBC > 2020: EE 40 Meg FTTC > 2022:EE 80 Meg FTTC SoGEA > 2025 EE 150 Meg FTTP
79Chris79
Investigator
Investigator

Hello, thanks for the reply.

I have 2 rules, pointing at my NAS IP - ports 80 and 443 so I can access the NAS from elsewhere when not at home.

When I check the port on port checker - it says closed - I have seen things about a factory reset might fix it - but I am unsure why this isn't working...

https://ee.co.uk/help/broadband/getting-started/set-up-port-forwarding

IPs.jpg

Shouldn't the External Ports & Internal Ports be swapped?

Aren't you trying to access the HTTP & HTTPS of NAS by letting external users come in on other arbitrary incoming ports?

Ports 80 & 443 incoming to the router are the router's own HTTP & HTTPS.

If you think I helped please feel free to hit the "Thumbs Up" button below.

To phone EE CS: Dial Freephone +44 800 079 8586 - Option 1 for Home Broadband & Home Phone or Option 2 for Mobile Phone & Mobile Broadband

ISPs: 1999: Freeserve 48K Dial-Up > 2005: Wanadoo 1 Meg BB > 2007: Orange 2 Meg BB > 2008: Orange 8 Meg LLU > 2010: Orange 16 Meg LLU > 2011: Orange 20 Meg WBC > 2014: EE 20 Meg WBC > 2020: EE 40 Meg FTTC > 2022:EE 80 Meg FTTC SoGEA > 2025 EE 150 Meg FTTP

I am following this blog for it

https://mariushosting.com/how-to-enable-https-on-your-ugreen-nas/

79Chris79_0-1780339026572.png

Step 8 is the one where I think it is going wrong / failing

The start / end box also havw a tendancy to go red and nothing can be saved...

And of course not as easy as the video suggests

https://youtu.be/LJ3X3dD3DFU?si=clpJhjTUSWHJTfgy&t=647

 

Step 8 will never work as external ports 80 & 443 are already active ports of the router & so you can't also use them for the NAS.

Your Port Forwarding should be like:

RuleDeviceExternal PortsInternal PortsTCP/UDP
80NAS9999-999980-80TCP/UDP
443NAS9443-9443443-443TCP/UDP

& tell your external users to come in on port 9999 or 9443.

However it looks like Step 6 has already carried out this mapping. So if you've already applied Step 6 to the NAS, your Port Forwarding should look like:

RuleDeviceExternal PortsInternal PortsTCP/UDP
80NAS9999-99999999-9999TCP/UDP
443NAS9443-94439443-9443TCP/UDP

 

If you think I helped please feel free to hit the "Thumbs Up" button below.

To phone EE CS: Dial Freephone +44 800 079 8586 - Option 1 for Home Broadband & Home Phone or Option 2 for Mobile Phone & Mobile Broadband

ISPs: 1999: Freeserve 48K Dial-Up > 2005: Wanadoo 1 Meg BB > 2007: Orange 2 Meg BB > 2008: Orange 8 Meg LLU > 2010: Orange 16 Meg LLU > 2011: Orange 20 Meg WBC > 2014: EE 20 Meg WBC > 2020: EE 40 Meg FTTC > 2022:EE 80 Meg FTTC SoGEA > 2025 EE 150 Meg FTTP

@XRaySpeX wrote:

Step 8 will never work as external ports 80 & 443 are already active ports of the router & so you can't also use them for the NAS.


You can. There's no issue at all forwarding inbound traffic on these ports to a device on your network. It's exactly what I do for a server I'm running.

@79Chris79 - we need to understand how your NAS is configured to accept traffic from the Internet and on what ports? A port checker will only show things as open if there's something behind the port forwarding rule actively listening for traffic.

It would also help to understand exactly how you plan on trying to access the NAS externally e.g what web address would you be using?

Are there any other port forwarding entries visible in the Hub manager, or is it just the two you're trying to add?

thanks, i'll give it another go

I'm following that example below, and have set up a domain name at NOIP...

https://mariushosting.com/how-to-enable-https-on-your-ugreen-nas/

https://my.noip.com/

and set up a proxy manager there - but the SSL but fails...

https://mariushosting.com/how-to-install-nginx-proxy-manager-on-your-ugreen-nas/ 

I  am not sure if it is the port forwarding rule causing that though...

79Chris79_0-1780738649934.png

 

 

@79Chris79 - don't know if you're still struggling with this but a failure at the stage in your pic suggests that the SSL certificate issuer's HTTP challenge is failing. This would happen if the NGINX proxy is unreachable from the outside world on port 80/443.

I have to admit, it does feel like you're trying to tackle quite a lot of stuff at once - especially if it's all new to you! Reading through the articles you've shared, we're not just talking port forwarding; there's also Docker containers, reverse proxy configurations, dynamic DNS and SSL certificate issue/installation! All aspects that could go wrong.

If I were to offer you my interpretation of things then it would be that you need to be forwarding the vanilla ports as below. I doubt you need UDP to be honest but that's what the article is suggesting 🤷: -

RuleDeviceExternal PortsInternal PortsTCP/UDP
HTTPNAS80-8080-80TCP/UDP
HTTPSNAS443-443443-443TCP/UDP

If it were me struggling, then I'd be configuring my NAS (or something else) to briefly listen on the above ports to see if I can get to them remotely/using a port checker. Assuming you can then the port forwarding works and you can then worry about introducing everything else.

Please also take a moment to read about the risks of exposing stuff to the Internet, especially if there's important/sensitive stuff on your NAS that you would not want to put under jeopardy.