cancel
Showing results for 
Search instead for 
Did you mean: 

inbound port 80 blocked b y virgin media

jaxxchris
On our wavelength

Inbound port 80 is being blocked before it reaches me.

All other port are fine, i've tested from numerous sources and see the traffic in my fw for the other ports i've tested like 81 through 90.

How do i get Virgin Media to stop dropping inbound port 80 traffic to me.

I'm trying to get letsencrypt working autonomously but this is reliant on letsencrypt connecting in to me on port 80 to check a file on a temporary server address.

17 REPLIES 17

VM doesn't block port 80.
i have my hub in modem mode, and my own router has port 80 open to allow incoming traffic.
i host my own websites and use letsencrypt and everything works OK.

sounds like your firewall isn't configirured correctly.
another possible is that you have websafe turned on.

-----------------------------------------------------------

My Broadband Ping - spgray

jaxxchris
On our wavelength

I’m in modem mode. Modem remote access is disabled.

i’m commenting about inbound connectivity, lots of things would be broken if i couldn’t get outbound port 80.

my firewall is configured just fine, like I say when I’m testing I see traffic for other ports loggged, I never see traffic for port 80 in my fw logs or tcpdumps.

example from a separate internet connection i see drops on my fw for these which means vm is delivering the traffic to me: http://82.v.m.ip:443 or http://82.v.m.ip:79  or http://82.v.m.ip:81 

I never see traffic http://82.v.m.ip

traffic for port 80 is not reaching me, it’s being filtered before it gets to me.

i have been using the dns method for let’s encrypt but it’s not convenient for the systems that will automatically renew their certs by temporarily permitting access to an http folder that contains the ephemeral code letsncrypt uses to validate you own the domain the cert is intended for.

If vm are filtering port 80 to me they should at least let me know in advance.


@spgray wrote:
VM are NOT filtering or blocking port 80 - not sure how many time you need to told this.


There's really no need for rude comments like that.

If you can't be civil then don't bother to comment!!!

Rude FanBwoy posters like you are what puts people off providers like Virgin.

Virgin are obviously trying hard to imporove their customer image and people like you ruin it instantly.

You don't work for Virgin, you don't have access to my local system, firewall logs or traffic data from virgin so you have exactly no basis to claim Virgin are not blocking inbound port 80 to me, as with most issues yours is likely working fine. Most people don't need inbound port 80 so it won't be an issue or indeed something anyone would notice if it where not working.

I'm willing to bet you've not even checked yours or even know how to check yours.

Perhaps you misunderstood what i meant by inbound port 80 like newapollo? In bound means traffic inbound to me & i'm looking at traffic inbound to me with dst port 80.

i've not mentioned outbound connectivity & i'm not having any issues with outbound.

 

 

there was nothing rude about it, it's stating the facts straight to the point.

and you can bet all you want, but i run a webserver on my LAN which is accessible on the internet, and that can only happen if port 80 (and port 443 for SSL) is open and working for INBOUND traffic.

however, you can believe whatever you want. i only have 25 years experience in IT support and development.

a port will not report as being "open" unless the end point responds to it, and the end point is not the firewall it is the device/service that needs it. so the firewall having the port open and correctly forwarded to the local LAN IP address of the device/servie is only 1 part of it, if the end point doesn't respond then the post will report as being closed.


-----------------------------------------------------------

My Broadband Ping - spgray

for anyone else having inbound issues & finding this.

i turned Virgin Media websafe & advanced error search off & things started working hours later.

https://my.virginmedia.com/my-apps/onlinesecurity/websafe/settings

https://my.virginmedia.com/advancederrorsearch/settings

i've not found any details on how those things work but looks like they are based on DNS filtering so not sure why they have an influence on inbound but perhaps the action of toggling to off has sorted something else within VM.

web safe is a firewall, so that would ovbiously block any non-essential traffic. should have been the first thing to check and surprised no-one told you to turn it off. still the fact that virgin do not block port 80.

advanced error search would not have affected it, but it's advisable to turn that off anyway.


-----------------------------------------------------------

My Broadband Ping - spgray

jaxxchris
On our wavelength

@spgray wrote:

there was nothing rude about it, it's stating the facts straight to the point.

and you can bet all you want, but i run a webserver on my LAN which is accessible on the internet, and that can only happen if port 80 (and port 443 for SSL) is open and working for INBOUND traffic.

however, you can believe whatever you want. i only have 25 years experience in IT support and development.

a port will not report as being "open" unless the end point responds to it, and the end point is not the firewall it is the device/service that needs it. so the firewall having the port open and correctly forwarded to the local LAN IP address of the device/servie is only 1 part of it, if the end point doesn't respond then the post will report as being closed.


as i've repeatedly stated, i expect to see the traffic logged in my fw regardlesss of what ever is beyond it. 

Firewalls are stateful and must track new sessions whether in or out. My logs will show the connection attempts, i don't need to forward the traffic to anything for the fw to log the attempt. As i have repeatedly stated i saw logs for my connection attempts on ports other than 80, port 80 never reached me.

i have 30 years senior network engineering experience for large multinationals, UK nationals, UK government, finance etc etc etc etc.

Doesn't help when i can't control the other side and reliant on a third party that won't reply to support requests.

jaxxchris
On our wavelength

@spgray wrote:

web safe is a firewall, so that would ovbiously block any non-essential traffic. should have been the first thing to check and surprised no-one told you to turn it off. still the fact that virgin do not block port 80.

advanced error search would not have affected it, but it's advisable to turn that off anyway.



if you don't know its there then how are you going to turn it off?

you knew yet with all your years of IT support experience you just launched into port 80 isn't being blocked.

if you knew it was there why didn't you suggest turning it off?

 

like i wrote, comments like yours are just rude & insulting first with absolutely no help & do nothing to help VM. Unhelpful comments just put people of the service.