dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
5802

Robocub
Premium Member
join:2006-03-12
Jersey City, NJ

Robocub

Premium Member

[Networking] FIOS Quantum Gateway router G1100 issue with L2TP port forwarding

I can confirm that the FIOS Quantum Gate router G1100 (Firmware 01.03.02.03) absolutely has an issue with port forwarding for L2TP (UDP ports 500,1701, 4500, GRE, ESP, AH) as has been reported in this older forum (»[Networking] Quantum G1100 Gateway VPN Issue)

What I know is that enabling port forwarding of (UDP ports 500,1701, 4500) to an L2TP server (in my case a Synology DS214play running DSM 6.0.1) on my network will sometimes work very briefly and then will just stop working after a few minutes.

Some other observations to be aware:
- This is only a problem on the FIOS Quantum Gateway router G1100. I had the Actiontec router previously and this was not an issue on that router.
- Make sure "Back to my Mac" service is off on all Macs and Airport devices on your local network. This service stealthily uses port 4500 which will interfere with the L2TP ports.
- Only L2TP ports seem to be affected as OpenVPN (UDP 1194) and PPTP VPN (TCP 1723) services work flawlessly all the time.
- Enabling DMZ on my Synology server (L2TP server) will allow the service to work but leaving my server on DMZ is not a comfortable option for me.

I have been in touch with level 2 support at Verizon FIOS and sadly they are of no help and start spouting crap like - we do not support VPN. Blah blah blah. Well then why is there a preset Port Forwarding Rules for L2TP? And why does OpenVPN and PPTP work consistently? And why would they deliberately block one of the more secure VPN method while leaving one of the less secure VPN (PPTP) open and working?

Looking for anyone who has resolved this issue or has a viable workaround. I am thinking of enabling DMZ on a second router with double NAT but frankly this is silly to have to do that when this should just work.
Robocub

4 recommendations

Robocub

Premium Member

Eureka!!! I think I may have solved the issue and it is so ridiculous. Hours of hair pulling.

Based on other research I found...It seems the built-in port forwarding rules for L2TP on the FIOS Quantum Gateway router G1100 may be incorrect. The preset rules show the same source and destination UDP ports for 1701, 500, and 4500. This apparently will not work even though it should. What I found that does work is the source UDP port for each port should be set to ANY and the destination ports respectively set to UDP 1701, 500, and 4500. As well as services for GRE, ESP, and AH (these are not in the default built in port forwarding rules but I added them myself).

The correct port forwarding rules for L2TP
UDP Any -> 1701
UDP Any -> 500
UDP Any -> 4500
GRE
ESP
AH

Obviously in many of the reported cases for this L2TP issue on FIOS routers it will work at first and maybe for an hour and then for unknown reasons just stop working so I will be able to report on that tomorrow. But for right now it is working since I changes the source ports to ANY, whereas before it would not work at all using the same source and destination port numbers.
compsult
join:2016-10-29

2 recommendations

compsult

Member

said by Robocub:

What I found that does work is the source UDP port for each port should be set to ANY and the destination port to 1194 (for openVPN)

I have been working with the damn FIOS Quantum Gateway for 20 painful f***ing hours. Called level 2 tech, they were useless.
Changing the source port to "Any" fixed it. So, thank you thank you thank you Robocup

Anyone who is trying to port forward for openVPN, set the source port to "Any" and the destination to 1194 (or a another port, if you have configured
openVPN to use another port)
mgalloway
join:2009-07-08
Melissa, TX

1 edit

1 recommendation

mgalloway to Robocub

Member

to Robocub
Click for full size
Can you share a screenshot of how you have this setup? Here is how I have mine configured.

Robocub
Premium Member
join:2006-03-12
Jersey City, NJ

Robocub

Premium Member

Click for full size
Looks like we have the same setup. here's mine.
mgalloway
join:2009-07-08
Melissa, TX

1 recommendation

mgalloway

Member

Thank you. I need to reboot my router and it started working.