LPS8V2_Firewall_TTN

Hello everyone, I configured gateways of the model “Dragino LPS8V2” to forward the Sensors packets to TTN. When I use a wifi-hotspot or even a test ethernet cable(static IP) the gateways work normally, when we installed them on a site where the network has a firewall(we opened port 1700) the gateways were never seen online on the TTN console.

My question is, using the UDP-Packet-forward protocol, do we need to open any other ports in the firewall to let the gateway go online?

Also, any suggestion on how to debug the gateway is appreciated.

Thank you

On site deployment the Firewall might have Port 1700 open but have you checked if the ISP/Backhaul service provider is fully open or do they also block Ports. Historically there has been a problem where some connectivity service providers sensor the internet, sorry block specific ports, ‘for our own good’! Though this is less of a problem these days. Still some remote control/remote management/remote assistance software can use P1700 (for entirely legitimate reasons) and unfortunately some scammers and bad actors can then make use of those same tools to pawn users machines, so the SP’s think they are doing good by blocking for all. Possibly worth testing or asking…

Also check locally that the site DNS is resolving the target TTN/TTI LNS correctly…(e.g. eu1.cloud.thethings…) Are you then on static or dynamic IP/DHCP, is GW configured for correct mode on site?

If you use the UDP packet forwarder port 1700 is sufficient. However the firewall needs to have session tracking in place for the udp traffic on that port. TTN will send responses that need to arrive at the gateway. Session tracking should allow for at least 30 seconds interval between packets in either direction.

1 Like

Thank you @Jeff-UK & @kersing for your responses.
I’m not an expert in networking but it looked like the problem was that the it-specialist didn’t set port-forwarding rules(as he has many gateways) and when the packets are received from TTN, the router doesn’t know which gateway should receive this packet(from port 1700) among the different gateways.