Configure NAT on a zTE router. How to check whether the port 443 is open?

What is UPNP in the router settings?

UPNP is the expansion of Plug-And-Play standards to simplify the control of devices on the network. In particular, the program on a computer in a local network can contact a “UPNP” router and demand to redirect the right port.

What is UPNP in the DVR?

The fact is that UPNP (Universal Plug and Play) is an architecture of multi.ranking connections between personal computers or video recorders and various intellectual devices.

How to disable the upnp function?

How to turn off UPNP on your Netgear router

How to get “Open NAT Type” for ANY GAME!

  • Go to the router’s page by typing www in the address bar of the browser.Routerlogin.Net.
  • Open the section “extended”, after which “additional settings” and UPNP.
  • Take off the checkmark from the “Turn on UPNP” item click “Apply” Note: After the UPNP disconnect, some Windows functions may stop working.

How to enable UPNP in the router settings?

The activation instructions are as follows:

  • We enter the web browser;
  • We enter the IP address (usually 192.168.0.1, 192.168.one.eleven);
  • enter the values ​​of the login and password;
  • Find the item under the name “Turn on the UPNP” and select the operating mode.

How to turn on on the UPNP phone?

We open the settings network and the Internet additional personal DNS server. Choosing a host name Supplier of a personal DNS server and drive the right address. The trick is that you cannot drive an IP address here, but the host address is needed.

How to turn on UPNP on the TP-Link router?

In TP-Link: Go to the Forwarding-UPNP tab (forwarding-UPNP). There should be Enabled status (inclusive).

How to turn on UPNP on a zTE router?

The easiest option is to use the universal automatic UPNP settings mechanism. Universal Plug and Play. To do this, we find the point of the same name in the “Applications” section of the main menu of the device. Put a “enable” checkplace, check for a WAN-DOCTION properly exhibited and apply changes.

How to open a port on the TP-Link router?

Click forwarding. virtual servers on the left side, and then click add. Enter the port of the service that you want to open, and the IP address of your device for which you want to open the port; Select the TCP, UDP protocol or that’s it; Change the status on inclusive. Click to save to save the settings.

How to enable UPNP in the Router Zyxel Keenetic?

In the router’s web configurator, go to the “General Settings” page, click “Change the set of components” and make sure that the component of the UPNP Service system is installed. In the factory settings, the UPNP service is on by default.

How to open ports in Zyxel Keenetic?

To open the port on Keenetic. click the “Add Rule” button. In the “Description” field, it is necessary to prescribe the name of the rule. For example, we make a port of the port for torrent. write the name torrent. In the list “Entrance” you need to select external connection to the Internet.

How to put the ports Zyxel Keenetic?

  • We go to the router’s web-integer, introducing in the address line of the Internet browser: 192.168.one.1 (IP address by default can also be 192.168.0.one).
  • We go to the Safety tab (icon with a red shield) we fall on the first tab: Rules for broadcasting network addresses (NAT).
  • Click: Add the rule.

How to open ports on the Router Zyxel Keenetic Start?

We open the port on the router after entering the router menu you need to open “safety”. the icon in the form of a shield. Then, in the subsection “Translation of network addresses (NAT)” it is required to create a rule using the “Add Rule” tab. Then a window will appear with the characteristics of the new rule.

Introduction

Internet. World System, consisting of combined computer networks based on the TCP/IP protocol.

Now the Internet. This is not just a network, but a whole information universe, subordinate to technical, social and state laws in its various parts. In the modern world, people do not do without access to the World Wide Web. The Internet opens up many opportunities to obtain information from anywhere in the world.

At the moment, IP addresses of the version are most common on the Internet. IPV4. This allows you to create 4.3 billion. IP addresses. However, this seemingly large number is critical not enough. To solve this problem. a mechanism for converting network addresses was created. NAT.

Various companies engaged in the development and implementation of network equipment help with the task of combining devices into a single network.At this moment, Cisco Systems and Huawei dominate the network equipment market. In this article we will work with Cisco equipment.

Cisco Systems has developed its own special inter.sequences for working with equipment called iOS (Internet Operating System). iOS. multitasking operating system that performs the functions of the network organization, routing, switching and transmitting data. IOS OS is a complex real.time operating system consisting of several subsystems and having many possible configuration parameters.

The iOS operating system presents a specific integration command of the CLI line (Command Line Interface). In this intese, it is possible to use a certain number of teams. The number depends on the selected mode and on the level of user privileges (user, privileged, global configuration and specific configuration).

Lack of IP addresses. NAT technology

In the 80s of the twentieth century, IPV4 was laid, which allows you to create ~ 4.3 billion. addresses, but no one assumed that this supply would dry up so quickly. Every year more and more users have appeared and from November 25, 2019. in and in Europe, IP addresses officially ended. The limit is exhausted.

To solve this problem, several ways were invented:The first way consists in strengthening control over IP addresses.

Let there be some site N C IPV4 XXX.XXX.XXX.xxx, and his host decided to stop maintaining this site. The site is abandoned, and the IP continues to be listed as busy and there can be a lot of such cases. That is, it is necessary to conduct an “inventory” of IP addresses and remove unused/abandoned.

The second method. In the mass use of the IPV6 system.

IPV6 protocol was designed as an IPV4 protocol successor. The main advantages of IPV6 over IPV4 are in an increased address space (IPV4 had 32 bits, which was 2,32 addresses, and IPV6 had 128 bits, which was 2,128 addresses), the 6th version became safer (t.to. V4 did not provide for many aspects of security, because the calculation was on third.party software, and the V6 appeared control amounts and encryption of packages), but these are far from all the advantages of IPV6 over IPV4.

The problem would seem to have been solved, however, to move from the IPV4 protocol to IPV6 causes difficulties because these protocols are incompatible. And the highlight of the cause of the difficult transition to the 6th version of the protocol is the cash value. Many campaigns are not ready to invest a sufficient number of funds for the transition, although it is worth noting that the transition process from 4 to 6 is gradually going on.

And the third way. Using technology for broadcasting network addresses. NAT.

The RFC 1918 document, Iana reserved 3 addresses for private IP (gray) (Fig. 1), the rest of the IP addresses are called public addresses (white).

Network Address Translation. This is a mechanism in TCP/IP networks, which allows you to change the IP address in the package heading passing through the traffic routing device. Taking a package from a local computer, the router looks at the IP address. If this is a local address, then the package is sent to another local computer. If not, then the package must be sent to the Internet.

The router replaces the reverse IP address of the package with its external (visible from the Internet) IP address and changes the port number (to distinguish between return packages addressed to different local computers). The route necessary for the reverse substitution, the router retains in his temporary table. Some time after the client and the server are finished exchanging packages, the router will be in the table in his table about the N-th port of the statute of limitations.

The main function is NAT. The preservation of public addresses, however, an additional function is the confidentiality of the network by hiding internal IPV4 addresses from external.

There are many types of NAT technologies, but the main ones are considered to be: Static NAT (Static Network Address Translation), Dynamic NAT (Dynamic Network Address Translation) and overloaded NAT (Network Address Translation Overload).

configure, router, check, port, open

How to open NAT type in an ADSL Router / change UPNP / Find IP / updating Ports

Static NAT Apply to display an unregistered IP address for a registered IP address based on one to one. It is especially useful when the device should be available outside the network.

Rice 2

Static NAT is most often used in corporate networks, when it is necessary that any IP address is always available from the global network. Often static IP endow the servers and place them in DMZ (Fig. 2).

Dynamic NAT displays an unregistered IP address to a registered address from a group of registered IP addresses. The dynamic NAT also establishes direct display between unregistered and registered addresses, but the display may vary depending on the registered address available in the pool (Pool. range) addresses during communication.

Overloaded NAT. This type of NAT’A has many names: NAT Overload, Many-too-One, Pat (Port Address Translation) and IP Masqurading, however, in most sources it is indicated as NAT Overload. Overloaded NAT. The form of dynamic NAT, which displays several unregistered addresses to the only registered IP address using various ports. When overloading, each computer in a private network is broadcast to the same address, but with a different port number.

Preparation of a computer networkThe logical circuit of the network topology will look as shown in the image (Fig. 3)

Rice 4

We take PC. Stations in VLAN 2, and the server in VLAN 3. To do this, you need to configure the switch S0 (Fig. 4). In order to determine the PC users in a separate VLAN, it is necessary to create VLAN 2 and shove the server itself (convenience for the sake of calling vlanes with names) (shown blue in Figure 4), determine the area of ​​the porter ports that will be included in the VLAN 2.3 and register the relevant commands (shown red in Fig. 4). The next task is to determine one port of the Trunk type to interact with the router (shown green Fig. Thus, the switch acts in the role of the “intermediary” between the terminal devices and the router.

Rice 5

Now you need to configure the router directly. Sub-Interface technology allows you to combine several virtual intenses into one and connect them to the physical integration (the FA0/0 Physical Intection is selected on the router). It is necessary to give for each VLAN its sub-intake (shown red in Figure 5) and give it an IP address (shown green in Fig. 5).Thus, in the future we will be nat’y traffic.

Then I would advise you to configure the protocol of the dynamic issuance of the IP address. DHCP, because to prescribe his address to each PC. then “pleasure”.

/12/2018

After resetting the settings, we go into the settings of the router

If necessary, sets a password from a wireless network for Wi-Fi 2 frequencies.4/5gHz

configure, router, check, port, open

We set the password for entering the Web-Inteateis. For example: admin1

We enter the Web-Inteatheis Using the Admin login and the installed password: Admin1

To configure the Internet connection, open wan select the WAN connection

Enter data for entering the Internet

To configure the IPTV, select the IPTV (as in a screenshot)

Next, we set up the integration group.

Choosing, Wan / Binding port. Click the change button and mark the port where the IPTV interactive prefix is ​​included

If you need to restore default settings, select administration / control (restore by default)

ATTENTION. After setting up the modem, it is recommended to change the standard login / password for access to the Web Inte Web.

We move to “Application”. “Voip”. “SIP” set and click “Submit”.

We go to the menu: “Application”. “Voip”. “SIP Accounts”, enter the account data and click Submit:

We check the performance, why we go to the menu:

The status should be “idle”.

We connect the telephone apparatus to the FXS Port, we are convinced of the performance of the service.

ZTE ZXHN H108N: characteristics, Internet and Wi-Fi setting up, passing the ports of the modem-riot from Rostelecom

Hi all! Today we’ll talk about setting up the ZTE H108N modem-diabage. The problem is that ZTE has several hardware versions of this device, as well as firmware. Why on the Internet you can find completely different instructions. Therefore, I described two possible options in this article. If you have any difficulties or questions, then write in the Комментарии и мнения владельцев. There are also two versions: ADSL and the usual WAN connection, but they differ only in the type of input intese.

First, let’s get acquainted with the ports, buttons and connect it:

  • On/OFF. button on and off. If it hangs you, then just click on it twice.
  • Reset. button for reset to factory settings. If you did not receive it from the company’s employees, then hold it for 10 seconds to lose the configuration to the factory.
  • Wlan-Wi-Fi activation button. By default, the wireless network has already been enabled.
  • WPS-quick connection to Wi-Fi.
  • Power. here we connect the power supply.
  • LAN1-4-ports for connecting local devices: computer, laptop, TV, etc.D. I have connected my laptop here. For primary tuning, it is better to do everything in the cable
  • DSL or Wan. we connect the cable that the provider threw you here. If you have ADSL version, then connect the telephone wire.

As soon as you connect it to the mains and turn it on, you need to connect to its local network. This can be done with the help of a cable by sticking it into one of the LAN inputs. Or connect with Wi-Fi-network name and password you can find on the label of the device.

After you connect to the network, you need to open any browser and enter one of the addresses presented into the address line:

If you will be asked to introduce a login and password, then we try the combinations:

If none of the combinations are suitable, then we look at the same piece of paper. If nothing is indicated there, then there is no password in your specification. You need to drop the router to factory settings by clicking on the “Reset” button for exactly 10 seconds.

ATTENTION! Now a very important point. It turns out that the router ZTE ZXHN H108N has two hardware specifications and two different firmware. Therefore, we look at our chapter, focusing on screenshots, which. Be sure to keep the sheet with the provider’s settings at hand.

New firmware

Manual setting

You can make manual tuning, and change some values ​​directly, not starting the “master”.

We go to the Internet tab, select “WAN” on the left. In the subsection “New Element” we indicate the necessary data. For different regions, you will need to change the values ​​of “VPI/VCI”.

For IP-TV, you just need to specify the port number in which you connected the prefix.

To change the key and the name of the network, you need to go to the “local network”. “wireless connection”. You can also change more detailed settings.

Porting ports

We go to the “Internet” section and then click on the block “Port Reviews”. Next, you need to create a new element.

And now in more detail for each of the points:

  • Name. write any understandable name.
  • Protocol. indicate the protocol. If you need to open a port for two protocols, then you need to create two rules.
  • Internet connection. indicates the connection that you created during the initial setting.
  • IP address WAN-Host-you can specify the IP from which you can have access to your router. For example, a computer at work. If you handle different devices, then indicate: 0.0.0.0. 0.0.0.0. Be sure to specify all zeros, not empty lines.
  • LAN-host-the local address of the device to which traffic will be thrown according to these ports.
  • WAN-port-indicate the Internet port.
  • Lan-host port-indicate the local port.

The same ports for WAN and LAN are usually indicated. At the end, click “Confirm”.

Settings

To configure the ZTE F660 GPON, first it needs to be connected to the operator’s fiber.optic network and to the computer from which we will set up. This is done like this:

  • Connect the plug of the power adapter into a regular 220 V electrical outlet, and the other end its end to stick in the Power nest on the router.
  • Connect the provider’s optical cable connector to the Pon nest.
  • The connector of the patch cord (cord) or cable is stuck in the appropriate port on a computer or laptop, and the other end to the first port “LAN” on the router. In this case, the corresponding LED should light up on the router.

If the indicator does not light up, then the computer connection did not happen. Then you need to check the settings of the network card with PC, replace the patch cord or check the integrity of the cable.

Now everything is ready to configure the router. Optical connection parameters should configure the provider. We give steps to launch the Internet distribution on Wi-Fi:

  • All the setting of the router occurs using the usual Internet browser (Chrome, Internet Explorer, Opera, etc.). Therefore, you should launch this program and enter 192 in the address line.168.one.one. This is the IP address of the router. Then we enter the login and password. They are the same. by default admin.

Note from the botan. Admin-Dmin-standard login-paralle on a factory router. One of our readers had to deal with the model in processing from MGTS. On it, the data for the entrance differ: login. mgts. Password. MTSOAO.

Now you can configure the device. From above we will see the main menu with the following points:

In the Network menu, select the “WLAN” item and the subparagraph “BASIC”. Next, you need to correctly fill out the data on this page. In the drop.down list of the “Wireless Rf Mode” parameter, you need to select “Enabled”. In the list “Mode” you should select “Mixed (802.11b802.11G802.11n) “.

We prescribe RUSSIA respectively. Other fields are filled as follows:

To save all the settings, you must definitely click “Submit”.

Next, you need to find the submenu “Multi Ssid Settings”. It is on the left. Here you need to fill in the fields “Choose SSID”. SSID 1, selecting the “Enable SSID” item, and in “SSID NAME” to enter the name of the network invented independently. And do not forget to save the settings by pressing “Submit”.

Further a little below is the substance “Security”. Here we fill in the following:

Here you need to come up with a password consisting of no less than 8, and no more than 63 Latin letters and numbers. It is necessary to register it in the “WPA Passphrase” field. Click Submit to save settings.

Simple passwords should be avoided to prevent unauthorized access to the network!

Now the router is configured and you can connect to it via a wireless network.

To reduce the likelihood of hacking the “admin”, you need to change the administrator password. This is done in the administrative section (last from above), in the user management subsection. Everything is simple and standard there. First you will need to enter the old password, and then come up with and save the new.

We set up as a local Web server

F660 router can be used as a simple web server. When a downloaded site with an index file is prepared.HTM is fundamentally the following:

  • Rename Index.HTM in Setlang.gch;
  • insert a USB drive into the corresponding router connector;
  • Go to the router on Telnet;
  • Perform the Mount.Bind/Mnt/USB1_1/Home/httpd command.

You can find out the password for Telnet by receiving a settings file with passwords, as described above in the section “Distinctive features of the router”. After these manipulations, the new contents can be seen at the IP address 192.168.one.one. It acts until the router reloads.

In principle, Web and FTP servers can be made available from the Internet. Settings depend on the presence or absence of a static address and a specific provider. But it is not recommended to open a router at all, since for this it has weak protection.

ZTE F660 has good characteristics, rich functionality and high reliability. It is important to correctly configure the device in order to minimize vulnerability in safety. Then the router will work for a long time and trouble.free.

Be sure to ask questions if they arise! All good and successful settings!

DNS cache wire

Suppose you went to the site directly, but looked and decided that it was worth going through Tor. Just updating the configuration is not enough. Caching DNS addresses in different places. Therefore, after updating the cache configuration, you need to reset.

On a client with Linux with Systemd-Rosolve, we launch Sudo Systemd-ReSolve.-Flush-Cache.

On the client with Windows, we launch IPConfig /Flushdns on the command line with administrator rights.

In Google Chrome, we open the Chrome page: // Net-Internals/#DNS and drop the browser cache.

Setting Wireguard VPN

And finally I will write why all this turned out to be unnecessary

Firstly, at some point, the MGTS selected a real IP and planted everyone for NAT. For some reason, at this moment, the corporate VPN fell off and in the support service it was recommended to connect the allocated IP.

Secondly, after connecting the allocated IP, IPV6 stopped working. The support service said that MGTS, in principle, never supported IPV6. Well, that is, IPV6 as if it works, but its work is not guaranteed. The forums have an explanation on this topic. Type is distinguished by static IP, but IPV6 cannot be distinguished and they cannot be embarrassed by no one when connecting a static IP stupidly chopped off V6.

Increased the tariff by 100 rubles, but this is the smaller of the evils, not even count.

Thirdly, those support of the MGTS is terrible. At first I had a Router Sercomm RV6699. It seems everything was more or less worked. And it was not the worst option. There was Telnet and access to IPTABles. They say it can even be relying. There was a jamb. The external IP address could not reach from the local network on HTTP and HTTPS. But this was decided by the removal of the two rules of the iPtables. But then I decided to assign a fixed channel of the Wi-Fi 5GHz network. The channel was not assigned. I started jumping, I turned to technical support and I was replaced by a router with ZTE ZXHN F680. And it turned out to be a complete end. He did not throw DHCP bags from a local network to Wi-Fi. I could no longer use my scheme. Technical support was sent with the conclusion “in the configuration by default the pages will be loaded, everything else is not our problem”. I thought I can try to use DNS from the router, but there is completely slag there. The maximum can be configured. 10 static addresses in the local network. Static and dynamic addresses should be in one range. In general, the Wi-Fi router is not used.

In-counted MGTS has a complete access to your router. And have a third party, or rather even a whole company in my local network. This is somehow not unhygienic.

Conclusion. You can also turn off Wi-Fi and convert the router into a bridge mode (not the fact that this can be done, not the fact that this will not fly after an unknown auto renewal, not the fact that this will not be banned).

They say that the Router Sercomm RV6699 V4 can be reflash. I wanted to try, but I can’t. I have no more this router. I was replaced by ZTE ZXHN F680.

They also say that you can buy a box of me for 1.5 thousand. rubles and she will work with a bridge. I think this is a good option.

Windows errors and ways to eliminate them

Information is relevant for those people who cannot configure the game on the network, network ball or create their own server. Example: A friend created the CS: Go server (or any other popular game). You see it in the server list, but it will not be connected to it. This despite the fact that he enters your server without obstacles. There is a problem in closed ports. To open ports, we read the article below. P.S. For the Tunngle Beta program, Port 11155 is relevant

Step 2: In the window that appears as the user’s name, you should specify Admin, As a password Admin. Next, click the OK button

Step 3: In the modem setting window, go to the tab Application and select the menu item Port Forwarding. Mark the tick Enable. In field NAME Enter the name of the program for which you open the port. In the fields Wan Start Port, Wan End Port, Lan Host Start Port, Lan Host End Port Enter the port number (or port range) for this program. In field Lan Host IP Address Enter a constant IP address of your computer (how to configure see here: Windows 8. Windows 7. Windows Vista. Windows XP/2003). Press the “Add” button.

How to open ports on the ASUS RT-N12E 1 router. Let’s go to Pu Router. http: // 192.168.one.one/ Login: admin; Password: Admin. (standard)

Click the combination key to win r. In the opened field we introduce CMD (this will open the command line). Next in the line we write the IPCONFIG command. In the falling information we remember the line IPV4 addresses: 192.168 5. Return to Pu Router. 6. We do it

Use settings and wait for the rebooting of the router. 7. Let’s go back to the “Additional Settings” menu, we are looking for DMZ

Step 1 Open the browser and indicate the IP address of the device in the address bar (by default it is 192.168.one.one). Press the Enter button (entry).

Step 2 in the entrance window to the system indicate the user name and password. By default, user name and password admin. Press the OK button.

Step 3 in the left side of the window, select Advanced Setup (extended setting).nat-Virtual Servers (virtual servers). The Virtual Servers Setup window will open (tuning virtual servers).

You can select the SELECT A Service option (select the service) and select the service from the list, then the ports for the server will be inserted automatically or you can select Custom Server (client server) and indicate the server name and the corresponding ports yourself.

1 should assign a static IP address for your computer so that the recording for a virtual server acts constantly.

2 If you installed a web server on your computer and opened the port 80, the port of the router will change by 8080. To connect to the router, it will be necessary to indicate the following address:

Step 1

We open the Internet Explorer browser, in the address bar we enter the address “192.168.one.1 “(without quotes). The authorization window will appear, enter the “admin name” in the “user name” field, enter the “password” in the “password” field (without quotation marks) and click the “Login” button.

In the Internet Explorer browser, we go to the modem setting at “192.168.one.one”

Step 2

After you press the Login button, you will get into the modem settings. Next, you need to go to the Application tab, then to the Port Forwarding tab (Figure 2). The table below will present a description of fields and buttons.

Port Forwarding on the ZXHN H208N modem

Field description
Enable A field for activating the rule (the checkbox should stand when creating the rule).
NAME The name of the rule (any name, for example, Test, CS, Warthunder).
Protocol The protocol on which the port is thrown works (TCP, UDP).
Remote Host The name of the remote node for which the rule will work. For example, if you have a static IP address, then you must enter it here. 178.124.203.104, if you have a dynamic IP address, then leave the field empty. But there is an important point here, Byfly is given to everyone a dynamic IP address, and this IP address hidden behind the NAT-device of the provider, without a static IP address, you will not be able to configure the passage of ports!
Wan Connection The reports for which the settings will work (rules). You need to choose your Internet connection, in this case it is called PVC0 (you can see the name of your connection using this instruction).
External Port The number of the port of the port. For example, 8080, 27016 and t. D.
Enable Mac Mapping Unknown. We don’t put a checkmark.
Lan Host IP Address Local IP address of the device on which a server requiring a port of the port with the specified number is launched. For example, your computer. 192.168.one.7 or any other IP address in this range.
Internet port Port number on a local device (your PC, media center and more), as a rule, equal to External port. For example, 8080, 27016 and t. D.
Add Button to add a rule.

Pros and cons of IP NAT

If something was not clear to you, or you are too lazy to read, then I advise you to watch this useful video.

Standard NAT already works in Pat mode and it is not necessary to configure it. That is, you just set up the Internet and Wi-Fi on the router. Another question, if at home you decide to organize Web, game or mail server. And maybe you want to connect surveillance cameras and monitor the house or apartment, resting in Bali. Here we need a passage of ports. about see the article about the ports. It briefly tells what ports are, why they are needed and how to throw them.