How to open specific port to all on LAN or WAN. Just like port 80 etc

How to open specific port to all on LAN or WAN. Just like port 80 etc

How to open specific port to all on LAN or WAN. Just like port 80 etc
How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago - last edited Wednesday
Model: ER706W  
Hardware Version: V1
Firmware Version: 1.1.2 Build 20240726 Rel.77184(4555)

Hi!

 

I bought some WiFi fire alarms but some ports need to be open for them to work. Send larm to my phone etc.

 

I cant see them on my network but added them was no problem.. (I cant see them because the ports are closed)

I got their mac adresses and binded them to some  IPs.

 

So I need to open up some ports to get it to work.

 

I just talked to a TP-Link support assistant and they said to use the NAT and Virtual Server.. Create rule for each ip. Thats crazy..

Back in the days you could easy create a simple rule like open Port X, TCP from/To WAN to LAN with any ip Thats it.

 

Anyone got suggestions?

TPLink OC200 TPLink ER706W TP-Link TL-SG2218P TP-Link SX3206HPP TP-Link SG2005P-PD TP-Link TL-SX1008 TP-Link EAP670 TP-Link EAP 650 outdoor TP-Link ES205G TP-Link VIGI NVR1004H-4P TP-Link VIGI C240
  0      
  0      
#1
Options
2 Accepted Solutions
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc-Solution
a week ago - last edited Wednesday

  @PinPale 

 

Hi,

 

And that's exactly how you should do it :) If you use Omada Controller to manage your network, go to:

Your Site => Settings => Transmission => NAT => Port Forwarding 

Then create and enable new rule:

 

If you don't use controller, but just router in standalone mode, go to:

Transmission => NAT => Virtual Servers 

Then create and save new rule there:

 

This port forwarding is for accessing those services (ports) from WAN. Within LAN every port is unblocked, I believe.

 

As I recall, usually the port forwarding (opening) required destination IP, not only on TP-Link devices. But maybe I'm wrong.

This is due to security. You don't want to grant access to your whole network on some random port... just an access to specific device/service.

 

BTW, port 80 is NOT open from WAN by default. ;)

 

Cheers

Recommended Solution
  1  
  1  
#2
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc-Solution
a week ago - last edited Wednesday

  @PinPale

 

I bought some WiFi fire alarms but some ports need to be open for them to work. Send larm to my phone etc.  

 

There is often confusion between the requirements for ports to be open for 'outgoing' connections as opposed to the need for port forwarding for incoming connections.

In general routers do not restrict outgoing connections on any port.

I may be wrong, but I'd be surprised if you need to make an incoming connection to the fire alarms. Normally these sort of devices work by connecting to the manufacturers servers and in turn you phone connects to those servers. So there is no need for port forwarding.

Perhaps if you could advise what make/model of alarm you have, we can establish whether port forwarding is really necessary.

 

Recommended Solution
  1  
  1  
#5
Options
10 Reply
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc-Solution
a week ago - last edited Wednesday

  @PinPale 

 

Hi,

 

And that's exactly how you should do it :) If you use Omada Controller to manage your network, go to:

Your Site => Settings => Transmission => NAT => Port Forwarding 

Then create and enable new rule:

 

If you don't use controller, but just router in standalone mode, go to:

Transmission => NAT => Virtual Servers 

Then create and save new rule there:

 

This port forwarding is for accessing those services (ports) from WAN. Within LAN every port is unblocked, I believe.

 

As I recall, usually the port forwarding (opening) required destination IP, not only on TP-Link devices. But maybe I'm wrong.

This is due to security. You don't want to grant access to your whole network on some random port... just an access to specific device/service.

 

BTW, port 80 is NOT open from WAN by default. ;)

 

Cheers

Recommended Solution
  1  
  1  
#2
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago
Hi! Thx for the reply. Nice screenshots :) As standard all ports are closed. Enabling uPnP opens the most standard ports. I do want certain ports to be open to the LAN network. Not just one IP. What happens if i dont got static ip to the mac adresses? This is a downgrade for TP-Link.
TPLink OC200 TPLink ER706W TP-Link TL-SG2218P TP-Link SX3206HPP TP-Link SG2005P-PD TP-Link TL-SX1008 TP-Link EAP670 TP-Link EAP 650 outdoor TP-Link ES205G TP-Link VIGI NVR1004H-4P TP-Link VIGI C240
  0  
  0  
#3
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago

  @PinPale 

 

You can always use Address Reservation option. Then, the router will always assign the same, static LAN IP to the certain devices. That's how you usually deal with that and bypass the DHCP for IoT devices.

 

 

uPnP allows the client (from LAN) to send info about required ports to be open to router, and automatically creates Port Forward Rule if needed. 

 

I have no idea if/how is it possible to open a port to whole LAN network. I guess we would have to wait for a reply of someone with better knowledge. Sorry.

  1  
  1  
#4
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc-Solution
a week ago - last edited Wednesday

  @PinPale

 

I bought some WiFi fire alarms but some ports need to be open for them to work. Send larm to my phone etc.  

 

There is often confusion between the requirements for ports to be open for 'outgoing' connections as opposed to the need for port forwarding for incoming connections.

In general routers do not restrict outgoing connections on any port.

I may be wrong, but I'd be surprised if you need to make an incoming connection to the fire alarms. Normally these sort of devices work by connecting to the manufacturers servers and in turn you phone connects to those servers. So there is no need for port forwarding.

Perhaps if you could advise what make/model of alarm you have, we can establish whether port forwarding is really necessary.

 

Recommended Solution
  1  
  1  
#5
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago

 -From the support...

 

SiGN Smart Home WiFi Brandvarnare

 

Portar som kan behöva öppnas på routern

För att brandvarnarna ska kunna kommunicera med molntjänsten kan vissa portar behöva vara öppna:

  • UDP-port: 6667, 7000, 8001
  • TCP-port: 443, 8886, 6668

 

 

TPLink OC200 TPLink ER706W TP-Link TL-SG2218P TP-Link SX3206HPP TP-Link SG2005P-PD TP-Link TL-SX1008 TP-Link EAP670 TP-Link EAP 650 outdoor TP-Link ES205G TP-Link VIGI NVR1004H-4P TP-Link VIGI C240
  0  
  0  
#6
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago

  @PinPale 

 

Google translates that as

 

Ports that may need to be opened on the router

In order for the smoke detectors to communicate with the cloud service, certain ports may need to be open:

UDP port: 6667, 7000, 8001
TCP port: 443, 8886, 6668

 

Which seems to confirm what I thought, that the detectors are communicating with a service i.e an outgoing connection , in which case no port forwarding is required. The ER706, like most routers will by default allow outgoing connections on all ports.

It is not possible to forward a single port to multiple LAN IP addresses, so if you think about the situation where you have multiple detectors with different IP's, communication cannot be possible in this way. Hence the use of an external cloud service, each detector connects to that service and updates its status, in turn your mobile app connects to the same service and can check each detector status. In addition, I suspect the service can use 'push notification' to cause your phone to be informed when a detector changes status.

 

I will see if I can find more detailed information from the suppliers website....

 

  1  
  1  
#7
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago

I Agree with you.

 

I Will skip that brand(SIGN) when investing in  smart home items. Hopfully TP-Links TAPO Serie will work better? To bad TP-Link dont got smoke alarms. People have asked about it but no straight reply on it.

 

 

TPLink OC200 TPLink ER706W TP-Link TL-SG2218P TP-Link SX3206HPP TP-Link SG2005P-PD TP-Link TL-SX1008 TP-Link EAP670 TP-Link EAP 650 outdoor TP-Link ES205G TP-Link VIGI NVR1004H-4P TP-Link VIGI C240
  0  
  0  
#8
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago

  @PinPale 

 

I use TAPO Wifi Smart bulbs, Wifi Smart plugs and a Wireless Doorbell ( via an H200 wired hub ). They all work pretty well via the Tapo App on my phone & tablet, although there is an occasional delay when, for instance, accessing a smart bulb remotely.

No configuration necessary on my router.

  1  
  1  
#9
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
a week ago
Exellent 👍🏻 Thanks for the Tip…
TPLink OC200 TPLink ER706W TP-Link TL-SG2218P TP-Link SX3206HPP TP-Link SG2005P-PD TP-Link TL-SX1008 TP-Link EAP670 TP-Link EAP 650 outdoor TP-Link ES205G TP-Link VIGI NVR1004H-4P TP-Link VIGI C240
  0  
  0  
#10
Options
Re:How to open specific port to all on LAN or WAN. Just like port 80 etc
Wednesday

Hi @PinPale 

Thanks for posting in our business forum.

This is how you do it on port forward. I don't see any easy way out.

How to set up Port Forwarding feature on TP-Link SMB Router (new UI)

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#11
Options