Vumatel devices and port 80

Kosmik

Honorary Master
Joined
Sep 21, 2007
Messages
31,302
Reaction score
11,774
Location
In the valley
So been struggling to use a program locally to create a cert off Let's Encrypt. Tried certbot, using a program called Certify The Web as well.

All the programs function by having a file for the CA to read from a website. These all use standard http on port 80 to check , setup a mini site to have that checked so I can get the cert. Did the normal story of port forwarding and fire wall, all seemed fine but still blocked from external.

Called my isp and had them open the port on their device. Still no joy. Now I already have a few ports open with internal Nats so very sure that my internal network was fine and went through a very painful process with the isp. After much escalation and explaining that if THEIR router can't even see the incoming requests, sonething was wrong, finally got to someone with a decent networking bent who discovered that no matter what was done, port 80 remained closed. He was going to escalate and get back to me.

Now I get a call from the isp, "Sorry, we can't open port 80 because your fno uses it to control their devices". Offered to open another port but told them it won't help because the cert programs all use port 80. Going to escalate and get back to me.

So, firstly, anyone else aware of this restriction by a FNO? And secondly, anyone know of another means? I can't use dns validation as I'm just using no-ip as a dyndns service and want a non self signed cert for consumption locally. They don't show the addition of subdomains unless you pay and I'm really trying to avoid it as is purely for personal use.
 
Last edited:
  • Sad
Reactions: Yuu
Is this Vuma Reach or trenched or GPON? I can’t speak for Reach, but the latter two definitely would not have any role in your L3 connection. With these two networks, the IP is assigned on your router- which means you should have full access to all ports.
 
Is this Vuma Reach or trenched or GPON? I can’t speak for Reach, but the latter two definitely would not have any role in your L3 connection. With these two networks, the IP is assigned on your router- which means you should have full access to all ports.
Normal trenched Fibre, private home.

When first installed I actually used my own LB to connect directly on the Fibre device and it worked fine. Isp insisted they wanted their own device between and I warned them at the time that I would expect transparent access. Opened a few ports before with them no issue but this one just won't budge and I will not put my direct network to their mik, especially when their default install included a wifi ap setup.
 
I'm Vox and Vumatel GPON and mine works perfectly, I remember trying to set it up the one night and it wouldn't work making me hit some limit they set, the next morning I ask Vox to forward the ports for me, try it again and it goes through immediately and has been running and renewing flawlessly for probably a year now.
 
I'm Vox and Vumatel GPON and mine works perfectly, I remember trying to set it up the one night and it wouldn't work making me hit some limit they set, the next morning I ask Vox to forward the ports for me, try it again and it goes through immediately and has been running and renewing flawlessly for probably a year now.
They are the ones saying no.
 
They are the ones saying no.
I figured as much from your second post, now at least you know it's possible, I just checked my three sites to see if they still work and they're all still up and running.
 
Get them to assign your WAN IP directly to your router and then it’s your problem to manage.

But another router would be DNS based verification, instead of HTTP.
 
I figured as much from your second post, now at least you know it's possible, I just checked my three sites to see if they still work and they're all still up and running.
Yah, I'm pretty sure it was rubbish. They even had the cheek at a low level to suggest sending a tech out and billing me for it. Took a long timeto explain if THEIR device can't see the traffic, it's got fugal to do with anything downstream.
 
Get them to assign your WAN IP directly to your router and then it’s your problem to manage.

But another router would be DNS based verification, instead of HTTP.
Why? Surely that should be assigned to the isp's router? Also not to sure how it works with assignment if I was able to use a differant device to dial through the Fibre link pre instalation of the isp's router. That should mean that their router is assigned the ip. Their claim is that the fno is using port 80 for their devices prior to both isps router and my own device.

Be nice if there was both reps on this forum to give answers.
 
Why? Surely that should be assigned to the isp's router? Also not to sure how it works with assignment if I was able to use a differant device to dial through the Fibre link pre instalation of the isp's router. That should mean that their router is assigned the ip. Their claim is that the fno is using port 80 for their devices prior to bother isps router and my own device.

Because you just avoid all this kak.

While at it tell them to remove their stupid device or you’ll go to someone else.

Maybe even try just setting it up yourself directly and removing their device from the chain if you have PPPoE details.

It sounds to me like they are talking a bit of kak. Or the FNO has their own IP directly assigned in which case it’s not the same Port 80 anyway.
 
Because you just avoid all this kak.

While at it tell them to remove their stupid device or you’ll go to someone else.

Maybe even try just setting it up yourself directly and removing their device from the chain if you have PPPoE details.

It sounds to me like they are talking a bit of kak. Or the FNO has their own IP directly assigned in which case it’s not the same Port 80 anyway.
Yeah , if I don't get a favorable outcome then I'll attach my own lb directly again and see if I have the same issue. Tbh, I want sure of it was a common practice but I appreciate the feedback from others in this thread that is certainly not, so they need to explain or a hopping we go BUT wouldn't have helped to hop off it is vumatel causing the problem.
 
I would never use an ISP that forced me to use their router.
It was more of a request, didn't bother me because their router still talks only to my load balancer and they are still responsible for the connection and evaluating the quality of it. With their own device, they have no excuse, and I still have full control of everything downstream from there.
 
It was more of a request, didn't bother me because their router still talks only to my load balancer and they are still responsible for the connection and evaluating the quality of it. With their own device, they have no excuse, and I still have full control of everything downstream from there.

But then I assume you're in a double-NAT situation if you've got your own router behind their router? Could that not be the source of your issues?
 
But then I assume you're in a double-NAT situation if you've got your own router behind their router? Could that not be the source of your issues?
Nope, because their own router can't see any traffic coming IN on that port.

I also have others that are working perfectly fine. Only 80 is a problem.
 
Nope, because their own router can't see any traffic coming IN on that port.

That's what they tell you, but unless you can actually get into that router you have no way of knowing for sure, or even if they've configured port forwarding correctly on their Mikrotik.
 
That's what they tell you, but unless you can actually get into that router you have no way of knowing for sure, or even if they've configured port forwarding correctly on their Mikrotik.
If they can't check their own logs, they need to fire their techs. But no, as I said, I have others that are fine, very much aware of how to set it up correctly. Their senior techs confirmed that the issue is pre their router.
 
Top
Sign up to the MyBroadband newsletter
X