OBTAINING LETS ENCRYPT SSL CERTIFICATE WITH PEPLINK MAX TRANSIT CAT-18 - SUSCPECT CGNAT ISSUE AS THE CULPRIT

jgsieve,

Your needs are totally different. Everything will depend on your networks, and equipment etc. the original poster already had a complete peplink SDWAN environment. you are in a different place.

Nothing is required, any limitations can be worked through, but you might want to start another thread. … what you have… and what you want… and what doesn’t work today. Networks are building blocks, layer, by layer we can help you make it work. Certs are only for external 3rd parties that can’t be expected to be told to just “trust this”…

I also host Plex (multiple sites) , have inbound forwarding and all of those things, but I chose to use the FusionHub at VULTR/AWS approach… which gives me the maximum control, given my network… you may be going beyond the capabilities of your OpenVPN provider… I don’t know.

Paul,
Issue resolved!
First off, I want to tell you how much I appreciate you taking the time in helping me resolve this issue. If you are a Peplink employee, please send me (via PM) the email address & name of your manager so I can send him/her an email to let him/her know how helpful you were. If you are not a Peplink employee, please know I sincerely appreciate the time & patience you demonstrated in assisting me to resolve this issue. You really went out of your way to help. Thank you!
OK, for the solution… We have a CAT-18 we use as a fail over when we have outages due to hurricanes. I wanted to set up a configuration where the NAS was behind the CAT-18 & the client was also behind the CAT-18 like I have in the RV. It did not happen right away as we think we are trying to run a small business as we attempt to resolve our network issues.
I just got a call, WebDrive is mapped to 192.168.xx.yy:5005 in that configuration. For whatever reason I was using port 5006. As soon as I changed the port to 5005, it worked. You had asked this same question in this string of posts that I had not yet had an opportunity to act upon.
I’m embarrassed that I over looked this, but attribute the oversight to my advance age and the onset of CRS.
As strange as it may seem to you, I have actually had the opportunity to help people with various issues. I always appreciated feedback of some sort.
Again, I sincerely appreciate the time & effort you expended in assisting me. Thank you!
gk

2 Likes

Just another random IT consultant.

Glad we could get it working. Unfortunately from your first post I could tell that either Webdrive or Synology had just told you “something” to make you go away. (the stuff with lets encrypt).

Now, I want to warn you, that the 5005 port is not encrypted, and you would be operationally better off switching all of the clients to https://192.168.xx.yy:5006. And once that is complete to turn off port 5005 at the synology. At no time should you expose port 5005 to the internet, and even leaving it available on your private network isn’t much of a risk, it is still an unnecessary one.

This is where things get cultural. Synology expects people to open ports and allow for remote access etc. Unless you are providing services to random people on the internet (web, email etc) , you should not be forwarding any ports. If you want to access your personal resources when away from the RV, then you should use a Remote User Access VPN method to the Balance ONE.

2 Likes

Paul,
Again; thank you!
I recognize I have a lot to learn with regards to networks. Learning can be difficult when you don’t even know what you don’t know. I’m trying though.
It’s people like you that make this forum such a valuable resource to us ‘newbs’.
If you are ever close to Southport, NC… Please let me know.
gk