30-12-2025 02:26 PM - edited 30-12-2025 02:38 PM
Hi,
Just switched from Virgin Media (FTTP into a media converter to take it back to DOCSIS) to EE Full Fiber. I am using an OPNSense router connected directly to the ONT.
I have an SFTP server and a Wireguard VPN Server, both of which worked fine with Virgin, both of which no longer work after the switch to EE. Other traffic (eg HTTP over any port) seems to work fine.
There have been no LAN side or router config changes with the exception of enabling PPPoE on the WAN interface.
nmap shows port 22 or 52222 as filtered, canyouseeme.org shows as open, yet I cannot connect via SSH. Wireguard is also unable to establish a connection from EE mobile data. I'm on an 86.xx.xx.xx/32 subnet so no CGNAT either. I ran tcpdump on the sftp server, no packets hit the server. I ran tcmpdump on the wan interface of my router, also no traffic.
I called EE and got escalated to someone in the technical team, apparently EE do not block or filter anything by default, but I dont see how its possible that they arent blocking this traffic?
Any ideas?
Solved! See the answer below or view the solution in context.
06-01-2026 10:09 PM
Gentlemen, it was FU**ING DNS...
Time to hang up my sysadmin hat in shame and swallow myself in 27 beers, maybe even some silkroad philosophy rock. A truly unacceptable error on my behalf.
EE - I owe you flowers and an apology. Please contact me to arrange this.
30-12-2025 05:16 PM - edited 30-12-2025 05:24 PM
Updates:
Waiting on callback from Openreach, however, I suspect the blocking would be EE side as it would be commercially advantageous for them.
30-12-2025 06:56 PM
@james_s60 VM move is your better choice don't waste time waiting on EE to sort anything out, should have done your homework before switching!
30-12-2025 07:12 PM
Well, lets see what openreach come back with. Theres a whole list of reasons Ive been keen to move away from VM and cityfiber isnt in my area yet.
I did ensure no CGNAT before signing up and couldn't see anything to imply EE block anything (as the official stance is that they dont). On paper it should work.
30-12-2025 07:15 PM
@james_s60 Then just keep the supplied EE Router on the wan connection, anything else you will have NO support!
30-12-2025 07:18 PM
Issue persists with the EE router too though, its clearly filtering the packets somewhere upstream. Seemingly anything bar HTTP HTTPS DNS isnt playing ball.
30-12-2025 07:20 PM - edited 30-12-2025 07:21 PM
@james_s60 It's your choice, put your opnsense router on and watch everyone walk away!
30-12-2025 07:28 PM - edited 30-12-2025 07:28 PM
You'll get no callback from OR. Your contract is with EE. OR don't talk to end-users other than regarding any visit when they are acting on behalf of EE.
30-12-2025 07:28 PM
Not a helpful response though is it.
The opnsense router was a non issue with virgin and there have been zero config changes. EE do not forbid third party routers, they have support articles for such on their own website. But most importantly of all - the issue persists on the EE router!
30-12-2025 07:31 PM
Thanks for the comment - I did think this strange, but thats what the EE guide said.
Ultimately EE are leasing the OR back haul, but still have their own ISP infra, so while they may have an escalation team for issues outside of their control (eg line damage), im surprised they don't have an internal tech team that would investigate first (especially considering that logically, the issue would most likely lay with them).
Even with the EE router in place, they had a very "dont care" first line attitude towards it with no offer of escalation past logging a fault with openreach.
The guide did seem a bit "first line" - do you think its worth calling again?