We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall. However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP. Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP. However... the mountaintop site has a static Public IP that is unique to itself. Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ? 73 Skyler
Skyler, You seem to be behind a NAT firewall, since you don't have a public IP address. This is a standard configuration used these days by many providers. Either you've got to convince the ISP to setup port forwarding (UDP port 4569) to your private IP, or, you could tunnel out using a VPN (or unencrypted IPIP/GRE) tunnel to a site where you do have a live IP address and forward ports from there. 73, David KB4FXC On Sun, 10 Jul 2016, Skyler F wrote:
We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall.
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP.
However... the mountaintop site has a static Public IP that is unique to itself.
Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ?
73 Skyler
On 7/11/16 12:13 AM, Skyler F wrote:
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
You don't have an Internet provider. Get another on that gives you a proper globally routable IP. -- Bryan Fields 727-409-1194 - Voice 727-214-2508 - Fax http://bryanfields.net
It seems to me the 10.1.50.xx is not a public IP, and essentially behind a router, which will require port forwarding. This would mean that your router is behind another router. It is not clear to me how this could work. For sure you don't appear to have control of any port forwarding via the ISP router. Bob k6ecm 73 Sent from iPad
On Jul 10, 2016, at 9:13 PM, Skyler F <electricity440@gmail.com> wrote:
We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall.
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP.
However... the mountaintop site has a static Public IP that is unique to itself.
Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ?
73 Skyler _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
I have had decent luck having the ISP forward ports. Not a problem, but you will probably have to get a static IP from them, and usually more money. Another solution that has worked in the past, partially anyway, is if you want to access the node via SSH, if you are on the same network with another computer, you should be able to get into the SSH port with no issues. You will NOT, however, be able to take any inbound connections without the 4569 port forwarded. From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of Bob Pyke Sent: Sunday, July 10, 2016 9:31 PM To: Skyler F Cc: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] Wireless ISP help It seems to me the 10.1.50.xx is not a public IP, and essentially behind a router, which will require port forwarding. This would mean that your router is behind another router. It is not clear to me how this could work. For sure you don't appear to have control of any port forwarding via the ISP router. Bob k6ecm 73 Sent from iPad
On Jul 10, 2016, at 9:13 PM, Skyler F <electricity440@gmail.com> wrote:
We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall.
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP.
However... the mountaintop site has a static Public IP that is unique to itself.
Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ?
73 Skyler _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. __________ Information from ESET NOD32 Antivirus, version of virus signature database 13782 (20160711) __________ The message was checked by ESET NOD32 Antivirus. http://www.eset.com __________ Information from ESET NOD32 Antivirus, version of virus signature database 13782 (20160711) __________ The message was checked by ESET NOD32 Antivirus. http://www.eset.com
Skyler. The answer in this case is to us a VPN to your home or other location that Internet with a Public IP address. You effectively run a tunnel to that IP and that is the on you control. You are creating a tunnel from that location to your wireless site. One of the most popular is OpenVPN but has a steep learning curve. A good alterternatin is Softether https://www.softether.org/ from Japan, it is open source, emulates openVPN and others and allows a vpn connection. It is available for Window, Mac and Linux so should be east to add. Eric Meth - ve3ei On 11/07/2016 12:13 AM, Skyler F wrote:
We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall.
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP.
However... the mountaintop site has a static Public IP that is unique to itself.
Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ?
73 Skyler
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
For open VPN tutorial goto the HAK5 podcast. It has gotten a lot easier with newer releases. Several recent episodes on setting up your own VPN connection. Sent from my iPhone Shuler KF4NQN
On Jul 11, 2016, at 7:10 AM, Eric Meth <ve3ei@iescomm.ca> wrote:
Skyler. The answer in this case is to us a VPN to your home or other location that Internet with a Public IP address. You effectively run a tunnel to that IP and that is the on you control. You are creating a tunnel from that location to your wireless site. One of the most popular is OpenVPN but has a steep learning curve. A good alterternatin is Softether https://www.softether.org/ from Japan, it is open source, emulates openVPN and others and allows a vpn connection. It is available for Window, Mac and Linux so should be east to add. Eric Meth - ve3ei
On 11/07/2016 12:13 AM, Skyler F wrote: We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall.
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP.
However... the mountaintop site has a static Public IP that is unique to itself.
Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ?
73 Skyler
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
OpenVPN is a very good product, but I would also suggest you look at IKE built-in VPN technologies in the Cisco based RV series of routers. Using the VPN built in your site gateway router, allows for a much cleaner integrated implementation of site to site VPN¹s. A key here is to reduce, if not eliminate the use of port forwarding on your router. There are many offerings for VPN technologies. ³Your requirements² will drive which one is the best for you. Keith On 7/11/16 7:56 AM, "Shuler Burton" <shulerburton@gmail.com> wrote:
For open VPN tutorial goto the HAK5 podcast. It has gotten a lot easier with newer releases. Several recent episodes on setting up your own VPN connection.
Sent from my iPhone
Shuler KF4NQN
On Jul 11, 2016, at 7:10 AM, Eric Meth <ve3ei@iescomm.ca> wrote:
Skyler. The answer in this case is to us a VPN to your home or other location that Internet with a Public IP address. You effectively run a tunnel to that IP and that is the on you control. You are creating a tunnel from that location to your wireless site. One of the most popular is OpenVPN but has a steep learning curve. A good alterternatin is Softether https://www.softether.org/ from Japan, it is open source, emulates openVPN and others and allows a vpn connection. It is available for Window, Mac and Linux so should be east to add.
Eric Meth - ve3ei
On 11/07/2016 12:13 AM, Skyler F wrote:
We are getting internet from a microwave link wireless ISP on a mountiantop. According to Mountain Broadband, ports are not blocked, and they don't have a firewall.
However, when I plug my computer or router into the jack, I am automatically assigned a 10.1.50.x address. Why is this happening? I never requested an IP manually, it assigned me a DHCP IP.
Inbound ports are all blocked to my router behind the DHCP IP address when I try to login under the public IP.
However... the mountaintop site has a static Public IP that is unique to itself.
Can someone explain how this works, and what information I need exactly to get inbound port forwarding to work to my mikrotik router from whatever Mountain Broadband has behind it ?
73
Skyler
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
participants (8)
-
Bob Pyke -
Bryan Fields -
David McGough -
Eric Meth -
Greg Stahlman -
Keith Goobie -
Shuler Burton -
Skyler F