PDA

View Full Version : Impossible to connect from Wan


LeKeiser
25-04-2005, 12:10
Hello,

I have installed the latest TS version on my Debian server.
I have opened 8767 UDP on my SpeedTouch 510v4. I checked it from my work, it is open.
But everytime my friends try to connect to my public IP, they always get the same message : server is down or ....
I have also created another virtual server, using 12000 UDP. Same problem.
Of course, I can connect within my LAN.
My friends configured their client using my public IP:8767 or IP:12000, no luck.

I have no idea now why it's not working. Ports are open, server is running fine, players are configured, etc...

Any help would be apreciated :)

Woelfchen
25-04-2005, 14:12
2) You setup the server and you can connect fine by using the LAN IP, but no one from the WAN can connect to it
When behind a NAT'ing device (broadband routers/modems) you'll need to setup a port forwarding in your router/modem. This allows any request from the WAN to the TS server port to be directly forwarded to the LAN IP of the TS server port. Withou the port forwarding all requests from the WAN are discarded by your router.
To do so, check your routers manual for "port forwarding" or sometimes called "virtual server". Remember, this forums is NOT a router forum. You can get router help at e.g. www.broadbandreports.com or check this page here: http://www.xbchelp.com/router/. This thread might be interesting as well http://forum.goteamspeak.com/showthread.php?t=15092.

guldi
25-04-2005, 15:50
- you "open" a port in a firewall
- you "forward" a port in a NAT device / software

open != forward ;)

Maybe you should read through the whole FAQ thread (no reply, link see my signature), as it is not necessary (but most surely as I guess) a problem on your side.

LeKeiser
25-04-2005, 16:05
Sorry, forgot to mention that I napted the ports to my server.
So 8767 UDP --> napt private IP
and 12000 UDP --> napt private IP

I run other servers and so far, the napt configuration of my router never failed.

guldi
25-04-2005, 17:20
smells like a firewall / NAT problem to me. However as there is an uncountable amount of possuble failure reasons it's hard to give suggestions. To make sure that the problem is server side:

- can your friends connect to other TS servers ?
- you could post the IP here to let others test test (if that doesn't cause you any problem)

LeKeiser
25-04-2005, 17:45
Thanx for your reply :)

My friend (and I also) can connect to other TS servers on the WAN.
I can of course connect to my TS server on the LAN side.
My friends saw my server on the TS list servers, but couldn't access it.

If possible, I would prefer to give my IP only through MP ;)
Like I said, I checked it the configuration of my router was alright. 8767 (and sometimes 12000) are opened, and napt to my private IP server.

guldi
26-04-2005, 08:51
then the only thing I could guess off at the moment is:

- you have several IP's in your server which may cause problems for certain users. there is a FAQ thread dealing with this ("not all can connect" or something like that)

- your friends get timeouted (that error would be displayed) => no reply / timeout FAQ

- your /your friends NAT rule / firewall is wrong. As I said, there are uncountable reasons for this last described failure, sometimes it's only a wrong protocoll / IP,... set

LeKeiser
26-04-2005, 10:17
Thanx again for your reply Guldi :)

then the only thing I could guess off at the moment is:

- you have several IP's in your server which may cause problems for certain users. there is a FAQ thread dealing with this ("not all can connect" or something like that)



Just one IP for the server. I even changed the line in the server.ini BoundtoIP, but no luck

- your friends get timeouted (that error would be displayed) => no reply / timeout FAQ

they haven't told me about a timeout but I'll check into it and I'll also check the FAQ



- your /your friends NAT rule / firewall is wrong. As I said, there are uncountable reasons for this last described failure, sometimes it's only a wrong protocoll / IP,... set

My router is my only firewall, and the NAPT configuration is good. My friends told me that they have disabled their firewall, but until they let me log onto their computer so I can see that for myself, it's always a possibility.

Temee
07-05-2005, 15:14
Hey ppl!

I'm having a problem much like LeKeiser is having. I've been trying to get Ts to work on my Debian Sarge install. It has worked fine until resently, when I changed my firewall and nat device. Before I had a Linksys BEFSX41 firewall/router acting as my home network nat and firewall. I wanted to have a wlan at my home too, so I replaced my Linksys with Zyxel Prestige 660HW-61 adsl2+/router/firewall/nat/wlan box. Now I have opened 8767 udp on my firewall, and made port forward for the same port on my nat. Problem is that friends using linux nat/firewall made with iptables are unable to connect, to them client says ts not responding. Those with no nat, just a software firewall, are able to connect without much hasle. All tho, people with software firewalls have to open up their firewall with trusted zone or similar setting to my public ip.

My linux box does not recive any packet from those users using linux nat on their home networks. Those using software firewall, before opening trust to my ip, get a connection, that is dropped after 2 seconds according the ts server log. My linux doesnt have multiple ips or virtual lans.

At this point, I'm starting to think that prestige zywalls ip spoofing blocker has something to do with the problem. Zyxel says in their manual that udp packets without sufficent means to make virtual connections are dropped. So I'm thinking that this does not allow TS server to correctly answer those users that use NAT in their network.

If there is someone with experience with prestige routers, plz, all information is highly preciated

guldi
09-05-2005, 12:51
@LeKeiser
Check the client.log for the timeout error

@Temee
Don't have the same zyxel router as you have but from my "old" 642'er I know that there are quite a few problems (especially with VPN's,...). I treid several firmwares but many of them which should have been fixed didn't work.
=> check for a firmware update, if it doesn't help, try binding the TS server to it's IP (see my thread above). If still no success... blame Zyxel