Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1045 > unrolled thread

accessing to router

Started byalanford <af@mfb.com>
First post2012-02-09 11:18 +0100
Last post2012-02-17 07:56 +0100
Articles 18 — 7 participants

Back to article view | Back to comp.os.linux.networking


Contents

  accessing to router alanford <af@mfb.com> - 2012-02-09 11:18 +0100
    Re: accessing to router Ralph Spitzner <rasp@spitzner.org> - 2012-02-09 12:21 +0100
      Re: accessing to router alanford <af@mfb.com> - 2012-02-09 12:57 +0100
        Re: accessing to router Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-02-09 21:11 +0200
          Re: accessing to router alanford <af@mfb.com> - 2012-02-10 16:02 +0100
            Re: accessing to router Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-02-10 22:29 +0200
              Re: accessing to router alanford <alanford@kjas.com> - 2012-02-11 16:29 +0100
                Re: accessing to router Bit Twister <BitTwister@mouse-potato.com> - 2012-02-11 16:17 +0000
                  Re: accessing to router Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-02-11 18:38 +0000
                    Re: accessing to router alanford <alanford@kjas.com> - 2012-02-12 11:26 +0100
                      Re: accessing to router Bit Twister <BitTwister@mouse-potato.com> - 2012-02-12 10:46 +0000
                        Re: accessing to router alanford <af@mfb.com> - 2012-02-13 09:57 +0100
                          Re: accessing to router Bit Twister <BitTwister@mouse-potato.com> - 2012-02-13 09:21 +0000
                            Re: accessing to router alanford <af@mfb.com> - 2012-02-14 07:54 +0100
                              Re: accessing to router Bit Twister <BitTwister@mouse-potato.com> - 2012-02-14 08:10 +0000
                                Re: accessing to router alanford <af@mfb.com> - 2012-02-16 12:38 +0100
                                  Re: accessing to router Bit Twister <BitTwister@mouse-potato.com> - 2012-02-16 11:46 +0000
                                    Re: accessing to router nescafe <nc@ms.com> - 2012-02-17 07:56 +0100

#1045 — accessing to router

Fromalanford <af@mfb.com>
Date2012-02-09 11:18 +0100
Subjectaccessing to router
Message-ID<jh06ip$cce$1@l01news1.ot.hr>
How can i access my local IP from outside of my local network.
The main thing is that i dont want to use ddns service of my router.
The port is open and the dmz is set.

e.g. if this is the ip of my router -12.34.56.78- and if this is opened 
port - 3000 - then when i enter this info in web browser i should land 
on local IP.

[toc] | [next] | [standalone]


#1046

FromRalph Spitzner <rasp@spitzner.org>
Date2012-02-09 12:21 +0100
Message-ID<pqmc09-6dr.ln1@spitzner.org>
In reply to#1045
alanford wrote:
[...]

  e.g. if this is the ip of my router -12.34.56.78- and if this is opened
> port - 3000 - then when i enter this info in web browser i should land
> on local IP.
>

Errm, the just forward that Port to your local IP address
an make sure someone is listening on it.
Your not feit from your Provider changing IP address, though.

Sorry, what was your question ? :-P


	-rasp


-- 
RTMPDump & ffmpeg are your friends..
     -icke

[toc] | [prev] | [next] | [standalone]


#1047

Fromalanford <af@mfb.com>
Date2012-02-09 12:57 +0100
Message-ID<jh0cbs$e85$1@l01news1.ot.hr>
In reply to#1046
> Errm, the just forward that Port to your local IP address
> an make sure someone is listening on it.
*** I made this, but like i write i can not access it.

Your not feit from your Provider changing IP address, though.
*** this should not be a problem

[toc] | [prev] | [next] | [standalone]


#1048

FromTauno Voipio <tauno.voipio@notused.fi.invalid>
Date2012-02-09 21:11 +0200
Message-ID<jh15pq$pp7$1@dont-email.me>
In reply to#1047
On 9.2.12 1:57 , alanford wrote:
>> Errm, the just forward that Port to your local IP address
>> an make sure someone is listening on it.
> *** I made this, but like i write i can not access it.
>
> Your not feit from your Provider changing IP address, though.
> *** this should not be a problem


'Can not access' is not a good diagnostic.
What happens really (not just imagined)?

Use a network sniffer, e.g. tcpdump or Wireshark to capture
the traffic with responses. If you cannot interpret the
results, post them, so we can try to help you.

-- 

Tauno Voipio

[toc] | [prev] | [next] | [standalone]


#1049

Fromalanford <af@mfb.com>
Date2012-02-10 16:02 +0100
Message-ID<jh3bk0$en8$1@l01news1.ot.hr>
In reply to#1048
On 02/09/2012 08:11 PM, Tauno Voipio wrote:
> On 9.2.12 1:57 , alanford wrote:
>>> Errm, the just forward that Port to your local IP address
>>> an make sure someone is listening on it.
>> *** I made this, but like i write i can not access it.
>>
>> Your not feit from your Provider changing IP address, though.
>> *** this should not be a problem
>
>
> 'Can not access' is not a good diagnostic.
> What happens really (not just imagined)?
>
> Use a network sniffer, e.g. tcpdump or Wireshark to capture
> the traffic with responses. If you cannot interpret the
> results, post them, so we can try to help you.
>
-----------------
wireshark is really very nice tool.
What information do you need and for should i setup the wireshark.

192.168.1.222 is the local ip where i want to connect myself when in 
accessing my local network from internet, and this ip is opened, dmz-ed 
and forwarded.

D-Link_dc:51:2c	Broadcast ARP Who has 192.168.1.222?  Tell 192.168.1.1

[toc] | [prev] | [next] | [standalone]


#1050

FromTauno Voipio <tauno.voipio@notused.fi.invalid>
Date2012-02-10 22:29 +0200
Message-ID<jh3unk$cc4$1@dont-email.me>
In reply to#1049
On 10.2.12 5:02 , alanford wrote:
> On 02/09/2012 08:11 PM, Tauno Voipio wrote:
>> On 9.2.12 1:57 , alanford wrote:
>>>> Errm, the just forward that Port to your local IP address
>>>> an make sure someone is listening on it.
>>> *** I made this, but like i write i can not access it.
>>>
>>> Your not feit from your Provider changing IP address, though.
>>> *** this should not be a problem
>>
>>
>> 'Can not access' is not a good diagnostic.
>> What happens really (not just imagined)?
>>
>> Use a network sniffer, e.g. tcpdump or Wireshark to capture
>> the traffic with responses. If you cannot interpret the
>> results, post them, so we can try to help you.
>>
> -----------------
> wireshark is really very nice tool.
> What information do you need and for should i setup the wireshark.
>
> 192.168.1.222 is the local ip where i want to connect myself when in
> accessing my local network from internet, and this ip is opened, dmz-ed
> and forwarded.
>
> D-Link_dc:51:2c Broadcast ARP Who has 192.168.1.222? Tell 192.168.1.1


192.168.x.y is a RFC 1918 block address, which is not allowed to
be forwarded in the public Net. It is absolutely correct that you
cannot (and should not be able) access it from the outside.

To access something in the internal RFC 1918 network from the outside
net, you have to use the IP address on the outside network interface
in the router and do an address translation in the router, usually
called port forwarding.

-- 

Tauno Voipio

[toc] | [prev] | [next] | [standalone]


#1052

Fromalanford <alanford@kjas.com>
Date2012-02-11 16:29 +0100
Message-ID<jh61gr$kuk$1@l01news1.ot.hr>
In reply to#1050
you have to use the IP address on the outside network interface
in the router and do an address translation in the router, usually
called port forwarding.
*** Thank you Tauno but like i write before, i have done this part.
My router has three possible options:
DMZ
open port
port forward

btw. there no NAT settings.
-------------
I set all this to the local IP ( 192.168.1.222 ).
OK. i agree with you that i can not access this IP.ΕΎ

IP address on the outside network interface in the router
** if i understand you right you are suggesting that i take one public 
ip address ( i own one and it's the address of my future dns server) and 
to put this IP into router.

Then to put this ip into port forward list and point to some local port 
(e.g. 3434 )

I hope i understand you correctly.


[toc] | [prev] | [next] | [standalone]


#1053

FromBit Twister <BitTwister@mouse-potato.com>
Date2012-02-11 16:17 +0000
Message-ID<slrnjjd54h.2ej.BitTwister@wb.home.test>
In reply to#1052
On Sat, 11 Feb 2012 16:29:30 +0100, alanford wrote:

> ** if i understand you right you are suggesting that i take one public 
> ip address ( i own one and it's the address of my future dns server) and 
> to put this IP into router.

In a nutshell:
If you want any inbound connections to hit your router, they will have
to use your router's Internet ip address (89.201.136.173).

To hit any ip on the LAN (192.168.1.xx), you will have to use port forward.

[toc] | [prev] | [next] | [standalone]


#1054

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2012-02-11 18:38 +0000
Message-ID<slrnjjddd8.1ls.grahn+nntp@frailea.sa.invalid>
In reply to#1053
On Sat, 2012-02-11, Bit Twister wrote:
> On Sat, 11 Feb 2012 16:29:30 +0100, alanford wrote:
>
>> ** if i understand you right you are suggesting that i take one public 
>> ip address ( i own one and it's the address of my future dns server) and 
>> to put this IP into router.
>
> In a nutshell:
> If you want any inbound connections to hit your router, they will have
> to use your router's Internet ip address (89.201.136.173).
>
> To hit any ip on the LAN (192.168.1.xx), you will have to use port forward.

Or wait for IPv6, where all of this is a non-issue.

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#1056

Fromalanford <alanford@kjas.com>
Date2012-02-12 11:26 +0100
Message-ID<jh8443$al6$1@l01news1.ot.hr>
In reply to#1054
On 02/11/2012 07:38 PM, Jorgen Grahn wrote:
> On Sat, 2012-02-11, Bit Twister wrote:
>> On Sat, 11 Feb 2012 16:29:30 +0100, alanford wrote:
>>
>>> ** if i understand you right you are suggesting that i take one public
>>> ip address ( i own one and it's the address of my future dns server) and
>>> to put this IP into router.
>>
>> In a nutshell:
>> If you want any inbound connections to hit your router, they will have
>> to use your router's Internet ip address (89.201.136.173).
>>
>> To hit any ip on the LAN (192.168.1.xx), you will have to use port forward.
>
> Or wait for IPv6, where all of this is a non-issue.
>
> /Jorgen
>
-----------------------
To hit any ip on the LAN (192.168.1.xx), you will have to use port forward.
*** :-) . I wrote this in the first post. The port forward is set and 
dmz also. The problem is that i have to check which IP should i enter.
As Tauno has suggested "you have to use the IP address on the outside 
network interface in the router and do an address translation in the 
router".

Simply:
which address is the address od the outside network intrface 
(89.201.136.XXX ? ) and which is the LAN address that i can port forward.

What address should i put into port forward list ?



[toc] | [prev] | [next] | [standalone]


#1057

FromBit Twister <BitTwister@mouse-potato.com>
Date2012-02-12 10:46 +0000
Message-ID<slrnjjf638.vsb.BitTwister@wb.home.test>
In reply to#1056
On Sun, 12 Feb 2012 11:26:25 +0100, alanford wrote:
>
> Simply:
> which address is the address od the outside network intrface 
> (89.201.136.XXX ? ) and which is the LAN address that i can port forward.

According to your header, your "outside network interface" ip is
89.201.130.134 at this time.

> What address should i put into port forward list ?

You put the ip address of the target system you wish the port to be
forwarded to.


Example: you tell the router to forward the ssh port to 191.168.1.200.

You then do a ssh alanford@89.201.130.134 and you should see an ssh
attempt at the ssh port on 191.168.1.200.

[toc] | [prev] | [next] | [standalone]


#1058

Fromalanford <af@mfb.com>
Date2012-02-13 09:57 +0100
Message-ID<jhajam$5mk$1@l01news1.ot.hr>
In reply to#1057
This are the setting in my router:


Port redirection part
---------------------
Comment:
Internet port: 80	
Local port: 3333
Protocol: TCP
Local computer: 192.168.1.253


Open port part
----------------
Enable open ports - checked
Comment: this is ip where i will put my dvr or pc
Local PC: 192.168.1.253
Protocol: TCP


DMZ
dmz enabled - check
DMZ Client IP : 192.168.1.253

Where should i define the outbound address ?

Those three options are the only options where i can change something.

[toc] | [prev] | [next] | [standalone]


#1059

FromBit Twister <BitTwister@mouse-potato.com>
Date2012-02-13 09:21 +0000
Message-ID<slrnjjhlg6.tie.BitTwister@wb.home.test>
In reply to#1058
On Mon, 13 Feb 2012 09:57:42 +0100, alanford wrote:
> This are the setting in my router:
>
>
> Port redirection part
> ---------------------
> Comment:
> Internet port: 80	
> Local port: 3333
> Protocol: TCP
> Local computer: 192.168.1.253
>
> Where should i define the outbound address ?

Why are you asking about the outbound address?
Your software listening on port 3333 on 192.168.1.253 decides what
port it wants to use for outbound connections.

From what I see, you should be able to run wireshark on 192.168.1.253
and put something like     85.114.42.50 
in your browser. Your router should see the inbound attempt at port
80, redirect the packet to 192.168.1.253 port 3333 and whatever is
listening on 3333 will do whatever it wants with the request.

wireshark should show you the in/outbound packets.

[toc] | [prev] | [next] | [standalone]


#1064

Fromalanford <af@mfb.com>
Date2012-02-14 07:54 +0100
Message-ID<jhd0kb$109$1@l01news1.ot.hr>
In reply to#1059
On 02/13/2012 10:21 AM, Bit Twister wrote:
> On Mon, 13 Feb 2012 09:57:42 +0100, alanford wrote:
>> This are the setting in my router:
>>
>>
>> Port redirection part
>> ---------------------
>> Comment:
>> Internet port: 80	
>> Local port: 3333
>> Protocol: TCP
>> Local computer: 192.168.1.253
>>
>> Where should i define the outbound address ?
>
> Why are you asking about the outbound address?
> Your software listening on port 3333 on 192.168.1.253 decides what
> port it wants to use for outbound connections.
>
>  From what I see, you should be able to run wireshark on 192.168.1.253
> and put something like     85.114.42.50
> in your browser. Your router should see the inbound attempt at port
> 80, redirect the packet to 192.168.1.253 port 3333 and whatever is
> listening on 3333 will do whatever it wants with the request.
>
> wireshark should show you the in/outbound packets.
>
--------------------------
This are the setting of my video recorder connected to my local network:
192.168.1.250
255.255.255.0
192.168.1.1
dns: 85.114.42.51
This is where i need to connect from internet, throe my router.
Video recorder has normal network card, as any computer.
------------------------------------------------------------
I have also tested with my local PC located on 192.168.1.11 and this is 
the result.The settings in router are the same as for video recorder but 
250 is changed to 11. DMZ,open port, port forward.

62235	59211.598950	192.168.1.1	192.168.1.11	TCP	http > 55964 [ACK] 
Seq=695 Ack=416 Win=2100 Len=0

63161	59478.373130	91.123.204.56	192.168.1.11	TCP	5938 > 59301 [PSH, 
ACK] Seq=7205 Ack=7271 Win=66304 Len=5 TSV=670499247 TSER=14974283

63398	59652.468703	85.114.34.28	192.168.1.11	TCP	pop3s > 34332 [FIN, 
ACK] Seq=3999 Ack=756 Win=4961 Len=0 TSV=2055748525 TSER=15017834

[toc] | [prev] | [next] | [standalone]


#1065

FromBit Twister <BitTwister@mouse-potato.com>
Date2012-02-14 08:10 +0000
Message-ID<slrnjjk5od.aps.BitTwister@wb.home.test>
In reply to#1064
On Tue, 14 Feb 2012 07:54:46 +0100, alanford wrote:

> This are the setting of my video recorder connected to my local network:
> 192.168.1.250
> 255.255.255.0
> 192.168.1.1
> dns: 85.114.42.51
> This is where i need to connect from internet, throe my router.
> Video recorder has normal network card, as any computer.

If 192.168.1.250 is something like mythtv backend, you do not want to
limit port connections. If you are trying to just hit the web server
then just forwarding port 80 should be ok.

> ------------------------------------------------------------
> I have also tested with my local PC located on 192.168.1.11 and this is 
> the result.The settings in router are the same as for video recorder but 
> 250 is changed to 11. DMZ,open port, port forward.
>
> 192.168.1.1	192.168.1.11	TCP	http > 55964 [ACK] 

Ok, I'll guess that is a result of you putting your internet address
into your browser or a script kitty script hitting port 80.

> 91.123.204.56	192.168.1.11	TCP	5938 > 59301 [PSH, 

There is a packet from somewhere in Sweden.

> 85.114.34.28	192.168.1.11	TCP	pop3s > 34332 [FIN, 

Guessing that appears to be a connection from your ISP's email server.

It is kinda hard to see what is going on when 192.168.1.11 apps are
chatting on the net.

With wireshark in the promiscuous mode on 192.168.1.11, and set to
watch for 192.168.1.250 packets only, you should be able to have the
router forward to 192.168.1.250 and see activity when you try to
connect to the video application from 192.168.1.11.

If you see packet activity but no application operation then I would
have to guess firewall/video access restrictions on 192.168.1.250
causing the malfunction.

By the way, you can get your internet ip with something like
wget -nv -O- http://cfaj.freeshell.org/ipaddr.cgi 

[toc] | [prev] | [next] | [standalone]


#1068

Fromalanford <af@mfb.com>
Date2012-02-16 12:38 +0100
Message-ID<jhiptl$552$1@l01news1.ot.hr>
In reply to#1065
On 02/14/2012 09:10 AM, Bit Twister wrote:
> On Tue, 14 Feb 2012 07:54:46 +0100, alanford wrote:
>
>> This are the setting of my video recorder connected to my local network:
>> 192.168.1.250
>> 255.255.255.0
>> 192.168.1.1
>> dns: 85.114.42.51
>> This is where i need to connect from internet, throe my router.
>> Video recorder has normal network card, as any computer.
>
> If 192.168.1.250 is something like mythtv backend, you do not want to
> limit port connections. If you are trying to just hit the web server
> then just forwarding port 80 should be ok.
*** it's just video recorder with built in sw. You can watch it per firefox.

I will send you e-mail.
Take a look when you find time.

[toc] | [prev] | [next] | [standalone]


#1069

FromBit Twister <BitTwister@mouse-potato.com>
Date2012-02-16 11:46 +0000
Message-ID<slrnjjpr5a.lgf.BitTwister@wb.home.test>
In reply to#1068
On Thu, 16 Feb 2012 12:38:49 +0100, alanford wrote:
> *** it's just video recorder with built in sw. You can watch it per firefox.

I have a few network tuners managed by mythtv for recording over the
air tv.  :)

> I will send you e-mail.

Heheh, you might want to "ping -c1 mouse-potato.com" and check the ip
address. :-D

[toc] | [prev] | [next] | [standalone]


#1070

Fromnescafe <nc@ms.com>
Date2012-02-17 07:56 +0100
Message-ID<jhktme$tq5$1@l01news1.ot.hr>
In reply to#1069
On 02/16/2012 12:46 PM, Bit Twister wrote:
> On Thu, 16 Feb 2012 12:38:49 +0100, alanford wrote:
>> *** it's just video recorder with built in sw. You can watch it per firefox.
>
> I have a few network tuners managed by mythtv for recording over the
> air tv.  :)
>
>> I will send you e-mail.
>
> Heheh, you might want to "ping -c1 mouse-potato.com" and check the ip
> address. :-D
:-) I forget about that :-)

Can you pass mail addr.?

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web