[TL-ER7206] Firewall doesn't permit inbound traffic

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

[TL-ER7206] Firewall doesn't permit inbound traffic

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
[TL-ER7206] Firewall doesn't permit inbound traffic
[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-09 10:15:16
Model: ER7206 (TL-ER7206)  
Hardware Version: V1
Firmware Version: 1.2.3 Build 20221104 Rel.41500

Hi all,

i'm in trouble with my ER7206 device.

The wan port 1 is connected to my isp router with a public ip address.

I have several services that must be published on the internet and therefore must be reachable via the public ip. At the moment, even if I put my server's private ip in the DMZ, I can't reach it via the internet. I tried also to create a new Virtual Server for my service but the error still persist.

If I connect to the public IP using the https port I can open the management console of ER7206.

 

Any advice or suggestion?

 

Thanks

Luca

  0      
  0      
#1
Options
6 Reply
Re:[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-10 05:23:35 - last edited 2023-02-10 05:23:46

  @Liuck1975 

 

Check your server IP and gateway settings, make sure it is using the new router as the gateway.

 

Go to What's my IP and check if it shows the same IP as your ER7206 WAN IP.

  0  
  0  
#2
Options
Re:[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-10 08:43:07

  @Somnus Thank you for the answer. Yes my server use the right ip of the router. I checked twice to be sure.

  0  
  0  
#3
Options
Re:[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-10 12:32:15

  @Liuck1975 

 

"At the moment, even if I put my server's private ip in the DMZ,"

What exactly does that mean?

 

The Virtual Server function of ER7206 works fine for port forwarding. I don't think you would have any issue if your ER7206 was dirrectly connected to a simple Internet modem. However, you have two Internet routers in the flow so NATting is done in two places. Best, put the ISP router in the bridge (bypass) mode to disable its NATing.

Kris K
  0  
  0  
#4
Options
Re:[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-10 13:18:29 - last edited 2023-02-10 13:19:46

  @KJK 

"At the moment, even if I put my server's private ip in the DMZ,"

What exactly does that mean?

 

It means that first of all I tried through port forwarding to publish my services on the Internet. This test failed, the server is not reachable via public ip. I then tried using DMZ Zone for my server but even then I cannot reach my device. My ISP's router is in passive mode, all traffic is forwarded directly to the ER7206.

 

Thank you for answering!!! :)

  0  
  0  
#5
Options
Re:[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-10 14:00:39

  @Liuck1975 

 

Is your ISP one of those that use Carrier-grade NAT by any chance? 

Kris K
  0  
  0  
#6
Options
Re:[TL-ER7206] Firewall doesn't permit inbound traffic
2023-02-10 14:40:00

KJK wrote

  @Liuck1975 

 

Is your ISP one of those that use Carrier-grade NAT by any chance? 

  @KJK 

No, the same configuration on a TP-Link Archer MR600 works, the wan port connected to the ISP Router with fixed public IP, Virtual Server active to internal ip address, the router forward the wan traffic to the correct device. I do the same step, also management interface has the same family look. On ER7206 it fails and on Archer MR600 works.

 

Best regards!!!

  0  
  0  
#7
Options