Inbound Connections / Unrestricted APN (Now Testing!)

Do you want/need an APN that allows connections initiated from outside the APN?

  • No thanks, no idea what this means - don't think it applies to me

    Votes: 8 4.5%
  • No thanks, I know what it means and I will never need it

    Votes: 4 2.3%
  • Yes please, for [desktop or other] remote support

    Votes: 110 62.5%
  • Yes please, for hosting

    Votes: 49 27.8%
  • Yes please, for some other reason explained in my post in the thread

    Votes: 33 18.8%
  • I clicked a 'Yes' option above, and am prepared to accept the risk of being hacked

    Votes: 107 60.8%
  • I clicked a 'Yes' option above, and am NOT prepared to accept the risk of being hacked

    Votes: 9 5.1%

  • Total voters
    176
Hi all,

I have my DynDNS set up and working (updating properly). Can't seem to wake my machine remotely though. Just wondering if incoming connections are blocked by default on Cell C? I think they used to be on Vodacom and you had to call to have them opened. Does the same apply to Cell C?

Thanx guys ;)

Oops - I see my post was moved to this thread - couldn't seem to find it in a search - weird...

Anyone hear back about an unrestricted APN yet?
 
I PM'd the CellC rep a while ago.

Nothing yet.

Nmap throws the following out : (run the scan against a Vista laptop)

Code:
Starting Nmap 5.00 ( http://nmap.org ) at 2010-12-15 14:33 SAST
NSE: Loaded 30 scripts for scanning.
Initiating Ping Scan at 14:33
Scanning 197.173.83.99 [8 ports]
Completed Ping Scan at 14:33, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:33
Completed Parallel DNS resolution of 1 host. at 14:33, 0.00s elapsed
Initiating SYN Stealth Scan at 14:33
Scanning 197.173.83.99 [1000 ports]
Discovered open port 80/tcp on 197.173.83.99
Completed SYN Stealth Scan at 14:33, 6.90s elapsed (1000 total ports)
Initiating Service scan at 14:33
Scanning 1 service on 197.173.83.99
Completed Service scan at 14:34, 51.06s elapsed (1 service on 1 host)
Initiating OS detection (try #1) against 197.173.83.99
Initiating Traceroute at 14:34
197.173.83.99: guessing hop distance at 1
Completed Traceroute at 14:34, 0.00s elapsed
Initiating Parallel DNS resolution of 3 hosts. at 14:34
Completed Parallel DNS resolution of 3 hosts. at 14:34, 0.00s elapsed
NSE: Script scanning 197.173.83.99.
NSE: Starting runlevel 1 scan
Initiating NSE at 14:34
Completed NSE at 14:34, 30.02s elapsed
NSE: Script Scanning completed.
Host 197.173.83.99 is up (0.00052s latency).
Interesting ports on 197.173.83.99:
Not shown: 999 filtered ports
PORT   STATE SERVICE    VERSION
80/tcp open  http-proxy Squid webproxy 2.7.STABLE6
|  http-open-proxy: Potentially OPEN proxy.
|_ Methods successfully tested: GET HEAD 
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 2.6.X
OS details: Linux 2.6.15 - 2.6.26
Uptime guess: 1.957 days (since Mon Dec 13 15:36:54 2010)
TCP Sequence Prediction: Difficulty=205 (Good luck!)
IP ID Sequence Generation: All zeros

TRACEROUTE (using port 80/tcp)
HOP RTT  ADDRESS
1   0.35 197.173.83.99

Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 91.20 seconds
           Raw packets sent: 2046 (92.496KB) | Rcvd: 34 (2372B)
 
Interestingly, when I tested telkom 3g about 3 or 4 months ago, incoming connections was possible, never had to ask them to open their ports up.
 
And a full UDP scan...

Code:
Starting Nmap 5.00 ( http://nmap.org ) at 2010-12-15 14:44 SAST
NSE: Loaded 30 scripts for scanning.
Initiating Ping Scan at 14:44
Scanning 197.173.83.99 [8 ports]
Completed Ping Scan at 14:44, 0.03s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:44
Completed Parallel DNS resolution of 1 host. at 14:44, 0.00s elapsed
Initiating SYN Stealth Scan at 14:44
Scanning 197.173.83.99 [1000 ports]
Discovered open port 80/tcp on 197.173.83.99
Completed SYN Stealth Scan at 14:44, 4.91s elapsed (1000 total ports)
Initiating UDP Scan at 14:44
Scanning 197.173.83.99 [1000 ports]
Increasing send delay for 197.173.83.99 from 0 to 50 due to max_successful_tryno increase to 5
Increasing send delay for 197.173.83.99 from 50 to 100 due to max_successful_tryno increase to 6
Warning: Giving up on port early because retransmission cap hit.
Increasing send delay for 197.173.83.99 from 100 to 200 due to 11 out of 12 dropped probes since last increase.
UDP Scan Timing: About 15.39% done; ETC: 14:47 (0:02:50 remaining)
Increasing send delay for 197.173.83.99 from 200 to 400 due to 11 out of 17 dropped probes since last increase.
Increasing send delay for 197.173.83.99 from 400 to 800 due to 11 out of 13 dropped probes since last increase.
UDP Scan Timing: About 18.11% done; ETC: 14:50 (0:04:36 remaining)
UDP Scan Timing: About 20.49% done; ETC: 14:51 (0:05:53 remaining)
UDP Scan Timing: About 22.19% done; ETC: 14:53 (0:07:04 remaining)
UDP Scan Timing: About 24.04% done; ETC: 14:54 (0:07:57 remaining)
UDP Scan Timing: About 25.73% done; ETC: 14:56 (0:08:42 remaining)
Increasing send delay for 197.173.83.99 from 800 to 1000 due to 37 out of 92 dropped probes since last increase.
UDP Scan Timing: About 27.66% done; ETC: 14:57 (0:09:20 remaining)
UDP Scan Timing: About 30.64% done; ETC: 14:58 (0:10:00 remaining)
UDP Scan Timing: About 35.51% done; ETC: 15:01 (0:10:45 remaining)
UDP Scan Timing: About 41.04% done; ETC: 15:04 (0:11:35 remaining)
UDP Scan Timing: About 61.76% done; ETC: 15:12 (0:10:34 remaining)
UDP Scan Timing: About 66.30% done; ETC: 15:11 (0:09:09 remaining)
UDP Scan Timing: About 71.31% done; ETC: 15:11 (0:07:45 remaining)
UDP Scan Timing: About 76.11% done; ETC: 15:11 (0:06:23 remaining)
UDP Scan Timing: About 80.96% done; ETC: 15:10 (0:05:02 remaining)
UDP Scan Timing: About 85.96% done; ETC: 15:10 (0:03:40 remaining)
UDP Scan Timing: About 90.86% done; ETC: 15:10 (0:02:21 remaining)
UDP Scan Timing: About 95.96% done; ETC: 15:09 (0:01:01 remaining)
Completed UDP Scan at 15:13, 1729.12s elapsed (1000 total ports)
Initiating Service scan at 15:13
Scanning 61 services on 197.173.83.99
Service scan Timing: About 6.56% done; ETC: 15:22 (0:08:19 remaining)
Service scan Timing: About 27.87% done; ETC: 15:17 (0:02:48 remaining)
Service scan Timing: About 40.98% done; ETC: 15:17 (0:02:17 remaining)
Service scan Timing: About 62.30% done; ETC: 15:16 (0:01:16 remaining)
Service scan Timing: About 83.61% done; ETC: 15:16 (0:00:30 remaining)
Completed Service scan at 15:16, 180.11s elapsed (61 services on 1 host)
Initiating OS detection (try #1) against 197.173.83.99
Initiating Traceroute at 15:16
197.173.83.99: guessing hop distance at 1
Completed Traceroute at 15:16, 0.00s elapsed
Initiating Parallel DNS resolution of 3 hosts. at 15:16
Completed Parallel DNS resolution of 3 hosts. at 15:16, 0.00s elapsed
NSE: Script scanning 197.173.83.99.
NSE: Starting runlevel 1 scan
Initiating NSE at 15:16
Completed NSE at 15:16, 30.03s elapsed
NSE: Script Scanning completed.
Host 197.173.83.99 is up (0.00049s latency).
Interesting ports on 197.173.83.99:
Not shown: 1939 filtered ports, 60 open|filtered ports
PORT   STATE SERVICE    VERSION
80/tcp open  http-proxy Squid webproxy 2.7.STABLE6
|  http-open-proxy: Potentially OPEN proxy.
|_ Methods successfully tested: GET HEAD 
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 2.6.X
OS details: Linux 2.6.15 - 2.6.26
Uptime guess: 1.978 days (since Mon Dec 13 15:48:11 2010)
TCP Sequence Prediction: Difficulty=201 (Good luck!)
IP ID Sequence Generation: All zeros

TRACEROUTE (using port 80/tcp)
HOP RTT  ADDRESS
1   0.25 197.173.83.99

Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 1947.83 seconds
           Raw packets sent: 4618 (166.000KB) | Rcvd: 2100 (114.525KB)
 
+1, was going to ask this but saw this Sticky.
 
Some feedback from Cell C. Doesn't sound too promising :(

Good afternoon

I have being dealing with your query with regards to the connections to your IP address and unfortunately Cell C does not have an unrestricted APN option. I understand that MTN and Vodacom has this option, however we cannot provide you information if this will be supported in the near future. For any assistance required please Call us on 140 and we will be glad to help you.

Regards

Brandon Naidoo
Call Centre Agent : KZN
Merchants - Dimension Data Company
 
Last edited:
Hi ginggs

Thanks for the reply, can you tell me how you know that all incoming tcp ports are blocked ?
Are they allowing statefull tcp ?
 
Last edited:
so i guess this will affect some gaming P2P as they are blocking the incoming tcp ports

Yup. In uTorrent, for example, you need to specify a listening port (or "port used for incoming connections", as they call it). You can still download torrents, but you'll run into trouble when you're the initial seeder (or uploader) of a torrent as no one else will be able to connect to you and there won't be any other seeders (disregarding any potentially found via Peer Exchange or DHT).

A lot of games (like World of Warcraft, for example) also require one or sometimes a range of ports to be open in order to work properly. I can play WoW just fine, though I suspect the built-in VOIP won't work (I haven't tried). The background downloader is crippled as well because of the reasons mentioned above: it also uses the bittorrent protocol, although luckily it's clever enough to fallback to HTTP, if needed).

A workaround for now is to change the listening port to 53 if the program allows you to do so and if it only requires one listening port, but obviously only one program can "listen" on that port at any one time, so it's still a problem.

My advice is for everyone to mail Cell C and put some pressure on them to provide us with an 'unrestricted APN' option, similar to Vodacom and MTN. Hopefully if enough people request this, they will do something.
 
I stand to be corrected, but it seems that port 53 inbound just went belly-up... working for anyone else?
 
I stand to be corrected, but it seems that port 53 inbound just went belly-up... working for anyone else?
Someone posted about it here, seems like port 53 traffic wasn't billed, or something.

So does this mean no DNS referrals on Cell-C's network?
 
Last edited:
Is anyone aware of any other ports which are currently open for inbound traffic? I need access to my lan at home from the office...
 
So I voted a "Yes please, for some other reason explained in my post in the thread" in the poll.
I would like it for connecting to my alarm and cctv systems from work/phone.

I am prepared to accept the risk of getting hacked because basically it would be no different than every adsl connection out there. I use the dongle on a router doing NAT anyway.
 
I voted YES for an unrestricted APN, was going to get myself a Cell-C setup, but I need unrestricted APN ability, so for now, I am going to have to stick with Vodacom and MTN ... , I do my own firewalling and NAT'ing ...
 
I voted YES for an unrestricted APN, was going to get myself a Cell-C setup, but I need unrestricted APN ability, so for now, I am going to have to stick with Vodacom and MTN ... , I do my own firewalling and NAT'ing ...
Do MTN have a working 'unrestricted' APN now?

I haven't seen any incoming UDP connections lately, have these also been blocked now?
 
Is anyone aware of any other ports which are currently open for inbound traffic? I need access to my lan at home from the office...

What we did once - but not on cellc - we asked the other party to vpn (PPTP) in to the office, we then determined the IP address allocated to that PC, then VNC/RDP'd to that IP. Worked well :D

I think if you can initiate a PPTP VPN connection from your house to your work, then you'll be able to connect from your work to your home PC (only the home PC though).

Another way - install openVPN, and read the manual on how to get it to listen on any UDP port you want. Haven't tested it yet.
 
Top
Sign up to the MyBroadband newsletter
X