Port forwarding still blocking ports

Post new topic   Reply to topic    DD-WRT Forum Index -> Qualcomm Atheros based Hardware
Author Message
jtmathcs
DD-WRT Novice


Joined: 13 Nov 2025
Posts: 7

PostPosted: Fri Dec 12, 2025 5:10    Post subject: Port forwarding still blocking ports Reply with quote
Trying to configure port forwarding on Linksys MR7350 running build 62157. Screenshots tell the details but I don't know what I need to change.


iptables_vnLFORWARD.png
 Description:
The output of the forwarding, but not sure what I'm seeing here that I need to fix.
 Filesize:  120.03 KB
 Viewed:  2048 Time(s)

iptables_vnLFORWARD.png



iptables_vnLPREROUTING.png
 Description:
The port forwarding shows up in iptables
 Filesize:  28.04 KB
 Viewed:  2048 Time(s)

iptables_vnLPREROUTING.png


Sponsor
dplotz
DD-WRT User


Joined: 07 Jan 2025
Posts: 242
Location: Bethel Park, PA, USA

PostPosted: Fri Dec 12, 2025 16:55    Post subject: Reply with quote
I'm no iptables expert, but I am using port forwarding on an MR7350. I checked mine with the same commands, and it looks similar (aside from the fact that I'm forwarding different ports). I see that one of the ports you're forwarding is 3389 (RDP), so I would guess that the target device is a Windows device. I know that I had to add a firewall rule on my Windows device to allow RDP from anything other than it's local subnet. To put that another way, my internal subnet is 192.168.6.0/24. My OpenVPN clients are 192.168.100.0/24. I wanted to allow VPN clients to RDP to one of my Windows computers, but it wasn't working. I had to add a rule allowing 192.168.100.0/24 on port 3389 in the Windows firewall. A little different than your scenario, granted, but my point is that maybe it's not DD-WRT blocking the port...
_________________
Formerly dpp3530
Linksys MR7350
Gateway, 2 wired APs, NSS-ECM , Clock 1440MHz
VAPs on wlan0 and wlan1 for guest/IOT devices
IPv4 & IPv6 (Prefix Delegation)
Static Leases & DHCP
SmartDNS (DOT using NextDNS, Cloudflare), DNSMasq
Wireguard and OpenVPN server
2.4GHz: dd-wrt, AX Only, ACK Timing 1350, WPA3 SAE & WPA2 w/AES
5GHz: dd-wrt, AX/AC/N Mixed, ACK Timing 1350, WPA3 SAE & WPA2 w/AES
Verizon Fios, 500/500Mbps
Wildlion
DD-WRT Guru


Joined: 24 May 2016
Posts: 1465

PostPosted: Sat Dec 13, 2025 16:14    Post subject: Reply with quote
There is nothing wrong with the firewall rules. Did you accept on both sides... what are you trying to do?
jtmathcs
DD-WRT Novice


Joined: 13 Nov 2025
Posts: 7

PostPosted: Sat Dec 13, 2025 21:04    Post subject: Reply with quote
Wildlion wrote:
There is nothing wrong with the firewall rules. Did you accept on both sides... what are you trying to do?


What do you mean "accept on both sides"?
With my previous router, Linksys MR2000, I had forwarding rules in place and was able to reach my computer from the internet. With the DD-WRT loaded MR7350 I'm not able to reach the computer, I've tried RDP from another computer using the No-IP dns address and port, I've tried using the router global IP and have run tests using Simple Port Forwarding and Zenmap (NMap gui for windows.)

Quite simply I want to be able to RDP to local IP: 192.168.1.96 and have http access to 192.168.1.78.
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 7115
Location: Romerike, Norway

PostPosted: Sun Dec 14, 2025 10:13    Post subject: Reply with quote
Do you have the correct Protocol?

Port numbers are a function of a protocol. The common protocols that have port numbers are TCP and UDP. UDP:3389 is not the same port as TCP:3389.
jtmathcs
DD-WRT Novice


Joined: 13 Nov 2025
Posts: 7

PostPosted: Tue Dec 16, 2025 4:48    Post subject: Reply with quote
Here is a screenshot of my rules


Linksys_ddwrt_port_forwarding_screen_shot.png
 Description:
 Filesize:  18.25 KB
 Viewed:  1889 Time(s)

Linksys_ddwrt_port_forwarding_screen_shot.png


ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3765
Location: Germany

PostPosted: Wed Dec 17, 2025 18:41    Post subject: Reply with quote
This is a configuration error; your “Source NET” is incorrect.

You must leave the field blank or enter 0.0.0.0/0

Note that RDP can be both TCP and UDP.

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 24.10.4 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 7115
Location: Romerike, Norway

PostPosted: Wed Dec 17, 2025 19:36    Post subject: Reply with quote
There are many advising that exposing RDP to the Internet is a bad idea (security).

A better way is to enable Wiregard Server and VPN into your LAN.
jtmathcs
DD-WRT Novice


Joined: 13 Nov 2025
Posts: 7

PostPosted: Sat Dec 20, 2025 4:24    Post subject: Reply with quote
Per Yngve Berg wrote:
There are many advising that exposing RDP to the Internet is a bad idea (security).

A better way is to enable Wiregard Server and VPN into your LAN.


To use wireguard I have to be using my own device "from the wild", right? No way to remotely access via someone else's computer?
jtmathcs
DD-WRT Novice


Joined: 13 Nov 2025
Posts: 7

PostPosted: Sat Dec 20, 2025 4:25    Post subject: Reply with quote
ho1Aetoo wrote:
This is a configuration error; your “Source NET” is incorrect.

You must leave the field blank or enter 0.0.0.0/0

Note that RDP can be both TCP and UDP.


Thanks, completely missed the /0.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Qualcomm Atheros based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum