[Solved] eblocker mobile: errors while configuration

25 Posts
4 Users
5 Reactions
840 Views
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

Hello again,

since a few days I try to activate eblocker mobile.

I have a domain from a dynamic dns Provider.

I write it to the dynamic dns name field. Then I choose "

Let my eBlocker try to assign the ports on my router.

." The eblocker mobile Port is 1194. Add this extern Port: 1194.

Add the port now: then there is an error.

When I try it again and again then the message is "success" instead of the error.

Then i click: "save settings".

Then the connection test shows "error".

Your eblocker could not be reached from the internet.

Then the "Hostname Test" shows the result: error -

"The specified host name could not be resolved successfully"

I also have made an "port release" in my fritzbox. But I'm not sure what to do in the field:

"Release this device completely for Internet access via IPv4 (exposed host).
This setting can only be activated for one device."

checkmark or no checkmark in this field?

And what other things can I do now?

Thank you in advance for your help

 

__________________

the environment:

raspberry Pi 3

eblocker OS Version: 2.4.5

At the moment I'm not able to use the https integrations. There is a error while I try to import the certificate.(see my other postings in this forum)

I try to make the configuration on a imac 27 ", middle 2015 with mac OS Catalina 10.15.3.

Router: FritzBox 6591Cable with individual network configuration, (DHCP Server is not activated) 


   
ReplyQuote
(@pio78)
Member
Joined: 5 Jahren ago
Posts: 329
 

Hello Zwergkralle,

a few questions:

1. you have a statis IP from your ISP? (no)

2. do you use DDNS with a hostname for your VPN? (yes)

3. Your eBlocker has a static IP and is DHCP-Server in your network? (yes)

On your Fritzbox go to "Freigaben" and make a "Freigabe" to your eBlocker

See the attached PNG picture what to do!

 

regards

PIO

 

 portfreigabe1

   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

With Vodafone/Kabeldeutschland reaching your IPv4 from outside needs a special config by the provider as they run IPv6 and don‘t route outside IPv4 by default. It‘s just a call - and only takes minutes - and it‘s free of charge. PLS check back with your provider. 

Also check if reverse lookup of Dyndns resolves correctly. In doubt use eBlocker DNS - which works just fine. 


   
Benne reacted
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

@Zwergkralle

Any news / success?


   
ReplyQuote
(@guenther)
Active Member
Joined: 5 Jahren ago
Posts: 4
 
Posted by: @pio78

Hello Zwergkralle,

a few questions:

1. you have a statis IP from your ISP? (no)

2. do you use DDNS with a hostname for your VPN? (yes)

3. Your eBlocker has a static IP and is DHCP-Server in your network? (yes)

On your Fritzbox go to "Freigaben" and make a "Freigabe" to your eBlocker

See the attached PNG picture what to do!

 

regards

PIO

 

portfreigabe1

I have the same issue, using a FritzBox 7490. 

I was able to get access to the eBlocker while enabling a authorisation (Freigabe) for the eBlocker device called Exposed Host (Dieses Gerät komplett für den Internetzugriff über IPv4 freigeben) - Because this is very risky for my network - the Router Firewall will be disables for the eBlocker - I disabled it immediately. 

 

Are there any suggestions how to make the mobile funktion work with a FritzBox, without enabling the "Exposed Host"?

I do not have Vodafone as my Internet provider, but Deutsche Telekom...


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

@guenther

It's enough to forward port 1194 UDP to the eBlocker's (fixed) IP.

I'm not sure if there are advantages but you might want to forward TCP as well (same port).

Fritzbox->Internet->Freigaben->Portfreigaben

Don't forget to disable Exposed Host 😉 


   
Guenther reacted
ReplyQuote
(@pio78)
Member
Joined: 5 Jahren ago
Posts: 329
 

Hello,

using "Exposed Host" is a security risk! Disable it.

Forward only Port 1194 UDP to the IP of the eblocker.

 

https://service.avm.de/help/de/FRITZ-Box-Fon-WLAN-7490/017p1/hilfe_portfreigabe

https://www.youtube.com/watch?v=Ah3fRrjaItc

Hope this helps.

 

regards

PIO78

 


   
Guenther reacted
ReplyQuote
(@guenther)
Active Member
Joined: 5 Jahren ago
Posts: 4
 

Port forwarding UDP worked for me, thanks for your Support!

Cheers


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@ Random

After 2 years, I would like to solve the last unsolved problem once again.

The doctor indicates that apparently all functions work smoothly. Only eblocker mobile is not enabled because it does not work.

You gave me 2 hints what I should take care of.
Today I want to follow up first of all the following hint:

Also check if reverse lookup of Dyndns resolves correctly. In doubt use eBlocker DNS - which works just fine. 

how can i check this? Unfortunately I am not an IT expert.

Can I do this with on-board tools from my Mac and if so how?


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@Random:

Update:

I have reset the configuration of eblocker mobile.

When entering the dynamic DNS data from my provider, the following happens:
The automatic port assignment works. I then apply the settings. The connection test fails. The test for the hostname fails.

When I use the eblocker DynDNS for testing:
The automatic port assignment works. I then apply the settings. The connection test fails.


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

@zwergkralle I'm happy to continue this thread after two years, but please provide more info on where you are at.

So: how have you configured eBlocker Mobile (via Demo DNS, own DNS etc), are you using UPNP to set port forwarding or manual, what's the result of the connection test? etc. etc.

Nevertheless, to quickly answer your question: You just need to ping the individual domain that DynDNS or eBlocker's Demo DNS have assigned for you. The IP address you see (using the ping) must match your current external IP address (just visit the Privacy Check button in the upper right and the IP will be shown - DO NOT USE VPN for this.) If the IPs match DynDNS, resolves correctly.

THX! 


   
Zwergkralle reacted
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@Rando

What exactly do I have to tell my ISP Provider (Vodafone Cable) regarding the second hint:

With Vodafone/Kabeldeutschland reaching your IPv4 from outside needs a special config by the provider as they run IPv6 and don‘t route outside IPv4 by default. It‘s just a call -

 


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@random 

Thx for help.

When entering the dynamic DNS data from my provider, the following happens:
The automatic port assignment works. I then apply the settings. The connection test fails. The test for the hostname fails.

When I use the eblocker DynDNS for testing:
The automatic port assignment works. I then apply the settings. The connection test fails.

when entering the command:
ping dyndns of my provider, a different IP adress is displayed than the one when testing the privacy (without VPN).

 


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

@zwergkralle Well, this means DynDNS is not (correctly) configured. You might want to contact your DynDNS provider for help as this is provider specific.

In any case the DynDNS provider needs to be configured in your router. Your router then continuously transmits it‘s external IP-Address to the DnyDNS provider. Please see your routers manual for help about Dynamic DNS setup. 

And, even I repeat myself: You need an IPv4(!) address to access your LAN when you are on the road. Tell exactly this your phone service people and it‘s gonna be done instantly.

Once you get „ping“ working, chances are are high eBlocker Mobile will work😉

THX!

 


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@random

THx.

ok, I contact my DynDNS Provider for this problem

Before I also contact my ISP Vodafone Cable for the IPv4 adress:

When I go to the web UI of my fritzbox there is a Online Monitor. There can I see a info:

Internet, IPv4
 
FRITZ!Box verwendet einen DS-Lite-Tunnel, AFTR-Gateway:

xxxx:xxxx:xx:xxx::x:x:xxxx

Does that mean, that I have an IPv4 address to access my LAN?


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 
Posted by: @zwergkralle

Does that mean, that I have an IPv4 address to access my LAN?

Maybe. Try pinging the IP (your external IPv4 address) shown in the Privacy Check. 

When configuring eBlocker Mobile you can also enter this IP and use it instead of the domain name. Then you skip DynDNS in favor of the IP. This setup will work temporarily until your IP address changes. At least it works as a proof of concept until you get DnyDNS running 😉

THX!


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@random 

result of pingtest:

PING xx.xx.xx.xx. : 56 data bytes

64 bytes from 95.91.200.242: icmp_seq=0 ttl=60 time=35.583 ms

 

So then I don't have to contact the ISP, right?

I then selected static IP address at eblocker mobile first and then specified the IP address that I have just pinged, or that the privacy check has supplied with (without VPN).
The ports I had automatically assigned (success) and have applied the settings.

The connection test again returned an error.


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 

I get an error pinging 95.91.200.242 (your IP)

Posted by: @zwergkralle

So then I don't have to contact the ISP, right?

I fear your conclusion is incorrect. A traceroute clearly shows your address is not reachable:

grafik

 

Posted by: @zwergkralle

The connection test again returned an error.

Please share the error! I suppose it's not DNS related as before.

THX!


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@random

Thank you very much for this feedback.

Unfortunately, I am overwhelmed right now and do not know what exactly I can do now.

2 minutes ago I contacted my Dyndns provider about this matter. As soon as I have more information from there, I will let you know.

Should I still contact my ISP?

I won't be able to get back to you until this afternoon....


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 
Posted by: @zwergkralle

Should I still contact my ISP?

YES, please! Again: The IP you've mentioned above can not be reached over the Internet... Unless this is solved, it makes no sense to dig any further.

THX!


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@random 

Thank you very much.
My DynDNS provider just contacted me and also let me know that my Fritzbox is not sending any information to them.

Then I will contact my ISP right now.
So far I didn't have the idea to ask there, because I can access the internet and because e.g. e-mail reception etc. works without any problems, but there seems to be some kind of problem.

Thanks for the hint what to do.


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@random

Here the Feedback von my dyndns Provider:

"There we have the culprit:

DS-Lite ...

So that DynDns with IPV4 is not possible.

Try first that your connection can be changed to public IPV4
addresses or 'real dualstak'.

Otherwise there would be only IPV6 left and there all your
involved hard / software must be able to play along and the
is only accessible from IPV6 capable internet connections.
reachable."

Let's see if I can manage this dual stack solution in the short term. This seems to be possible only with additional costs.

Good that I had cancelled my ISP provider contract as a precaution and it expires in 2 months...


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 
Posted by: @zwergkralle

Good that I had cancelled my ISP provider contract as a precaution and it expires in 2 months...

As I discussed several times above: It's only one call to Vodafone service - and no need to cancel the contract. And the change is free and takes only minutes. (And no: I don't work for Vodafone, but feel the service is OK + value for money).

THX!


   
ReplyQuote
(@zwergkralle)
Trusted Member
Joined: 5 Jahren ago
Posts: 47
Topic starter  

@Random

Hello,

I did not cancel my contract with Vodafone because of the dual stack issue.

It took some time with the feedback from Vodafone.
Since yesterday, the switch has been made to Dual Stack. Since just now eblocker mobile works again smoothly.

I had set this up a long time ago already working, but then Vodafone had switched without notice at some point to DS light. Since I'm not an IT professional, I had no idea why it suddenly stopped working.

In this respect, many thanks for your help.


   
Random reacted
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 6 Jahren ago
Posts: 2068
 
Posted by: @zwergkralle

many thanks for your help

My pleasure 👍

THX!


   
ReplyQuote

Nach oben scrollen