Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Trying to decipher Port Forwarding for XG (Home) software - web cams.

My goal is to have some webcams at home, each using their own dedicated Port number (same port #) through the Internet - Firewall - Switch - camera.  (Obviously the switch doesn't care.  But my web cams do care. 

I have posted a copy of my Firewall and NAT rules below. 

I have done this many times using cheap consumer firewalls and most recently on my Meraki MX device.  I moved from MX to the Sophos XG free solution on extra hardware I have around to take advantage of the higher download speeds that my ISP provides.  (My MX limitation is 250M). 

What disturbs me in the way that I have this working is that other than the fact that the server (camera) accepts the traffic via the specific port, neither the Firewall nor the NAT rules are doing anything except exposing the whole range of Port IDs to the Internet.  (Not happy about that).  Seems like I am asking for trouble.  Yet, on either the FW rule where I define the basic service protocols TCP and UDP - I cannot create more specific instances of these protocols with ONLY my desired port number (45953, for this specific camera).  I have experimented some with trying to use the NAT rule to define the Original Services (TCP, UDP) to a specific port number - and then using PAT - though every instance I try the NAT rules reject me because my Original and Translated Services are not identical.  I argue that they were the same, but there is something in the logic or design of Sophos that I clearly do not understand.

I am using Port 2 for Internet; (also have Port 3 Internet but a different ISP).  And incidentally I'm trying to use DYNDNS to manage my Non-Static IP Addresses on my two ISP connections.

Again - this is a home network. 

Internet WAN - Port #2 - Dynamic IP address

Server (Camera 2) - 172.16.16.82

Services TCP and UDP are default protocols from the list - so they include the entire range. 

My understanding is that the FW is allowing all packets in - and sending to this server -- I also have ZERO idea this afternoon if I am breaking something else on my network such as solicited connections to things like RING cameras, etc. 

And - What happens when I try to add rules for additional cameras ?  I believe based on my perceived logic of this config - that I have no FW nor NAT rule that really understands my desire to filter a single Port # (or small range of ports). 

Below is the Firewall Rule

Again - allowing TCP and UDP packets in but no other logic or filters.

When you finish laughing at me ..... Would love to better understand how to make this work for multiple devices (servers) each with a unique port.  Meanwhile I'm going to disable these rules. 

I did for kicks go to "Shields Up" at grc.com and found that my ports appear CLOSED with the only one OPEN is where the server itself responds.  Of course, I didn't check all of the range of ports to see what else I have exposed...

Thank you for any suggestions.

I'm not a CCNA - have done some work on that over the years, but the way these FW / vendor specific tools work, they don't seem to make logical sense.  And the examples I could find are also seemingly unclear. 

Sincerely,

Chris



This thread was automatically locked due to age.
Parents
  • I use a VPN, it's more secure than opening ports. Then I use the manufacturer-provided app on my iPhone to view my cameras.  It works great. 


    I use Tunnelblick on my MacBook and OpenVPN on my iPhone.

  • Sorry for the delay.  That is an EXCELLENT recommendation.

    I have been stuck trying to piece together the VPN setup unfortunately - without tons of time nor much luck.

    Which VPN option did you ruse?  IP-SEC or SSL-VPN?  I have set up VPN on Meraki, but (similar concern as I had with port forwarding) - just feels like this is harder than it should be...  LOL - I could do it on Meraki - behind the SOPHOS FW - but then I have the same port forwarding issues that I started with.  LOL 

    Chris

  • I would be interested to know the same.  I have a ton of cameras that I do not want to port forward for all of them.  I have an NVR that will allow access to all of them from the network and a VPN sounds like the easiest and most secure way to accomplish this.   If you get it working, I'd appreciate your experience.

  • Hi

    I used SSL-VPN with the OpenSSL app on my iPhone.  I downloaded the VPN profile from the XG user portal, changed one of the 'remote' lines in the .ovpn with my DDNS, i.e., 'remote xxxxx.ddns.net', then sent that to my iPhone where I added it into the OpenSSL app.

    I then connected to my VPN and watched the webcams via the NAS' cam app. I can also use the app from the camera manufacturer to view the camera, all using the local IP address of the cameras.

    This also works with the Tunnelblk app on my MacBook Pro.

  • Hi Brian

    Thanks for that information.  A couple of questions.  Are you using the free "home" version of the Firewall? And version 18?  One of the reasons I ask is because when I walked through both the IP SEC and also SSL - I had difficulty in finding a profile to download from the XG user portal OTHER than an MSI file for Windows (my desktop platform). 

    When you say OpenSSL app on iPhone - do you really mean the OpenVPN app? Or do you have another solution you were using? 

    Sounds like Don Fisher and I are in a similar boat! 

    Many thanks - appreciate your kind and thoughtful reply.

    Chris

  • For my Home-XG I use the OpenVPN client on my iPhone.

    Take a look at the SSL VPN guide from Sophos on youtube:

    Sophos XG Firewall (v18): How to configure SSL VPN remote access - YouTube

    _______________________________________________________

    Sophos SG 210 with Sophos XG Home - 19.5 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?