UPNP keeps disappearing

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
Hi - I've run the BI wizard a few times and I get it to work to access video while I'm not home. But it seems the router or windows or something keeps resetting my UPNP? Is there a way to force BI to periodically refresh the UPNP rule like it does in the wizard? Note: this is not a case of my ISP changing my WAN IP. Thanks for suggestions in advance.
 

sebastiantombs

Known around here
Joined
Dec 28, 2019
Messages
11,511
Reaction score
27,695
Location
New Jersey
Don't use UPnP.

VPN Information Thread
 

IAmATeaf

Known around here
Joined
Jan 13, 2019
Messages
3,308
Reaction score
3,293
Location
United Kingdom
With my broadband router I can’t set any static port forwarding rules so am forced to use uPNP so what I’ve done is run a scheduled task which grabs all the current uPNP settings on the router, removes them and then creates only the entries that I know about and want.

Can’t remember what the name of the utility I use is right now but it has a command line option for querying, deleting and setting.
 

bp2008

Staff member
Joined
Mar 10, 2014
Messages
12,676
Reaction score
14,024
Location
USA
Are you sure your Blue Iris computer's LAN IP isn't changing? Most of us here can't vouch for the quality of Blue Iris's UPnP client implementation because we don't use it. It could simply not be dependable and we wouldn't even know.

It would be far better for your network security, and for the reliability of your remote access, if you turned off UPnP. In most routers it is possible to set up a port forwarding rule manually for Blue Iris -- that is going to be a much more reliable solution. Better still is to use a VPN for remote access and to not allow ports to be forwarded to anything else -- but I understand there's a much bigger learning curve and inconvenience factor involved.
 

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
Thanks. Assuming my PC has a static IP, what would a typical port-forwarding setting look like? I see that I can edit that and that I can turn off UPNP.
PS Alternatively, are there simpler VPN options (like a paid service) that would work for a newbie like me?
 

bp2008

Staff member
Joined
Mar 10, 2014
Messages
12,676
Reaction score
14,024
Location
USA
Paid VPN services don't grant you remote access to your own network, and therefore will not help with this.

Here's an example port forwarding rule in a router running Tomato firmware.

1607715884789.png

In this example, Blue Iris is on a PC with static IP address 192.168.0.10, and Blue Iris's web server listens on port 81. To connect remotely, I would connect to the public WAN IP address on port 5581.
 

SouthernYankee

IPCT Contributor
Joined
Feb 15, 2018
Messages
5,170
Reaction score
5,320
Location
Houston Tx
for a VPN
1) who is your internet provider ?
2) what is the make and model number of the internet connect device (modem / router)
3) do you own the modem / router ?

Setting up a VPN on select routes is very simple.

-----------------------------------------------
My general VPN post
There are two types of VPN, do not get them confused.
The type depends on where the traffic conversation (traffic) originates

1) origination: local home network, destination the internet.
This type of VPN is purpose to hides your activity from the internet, it is outbound, it normally costs a monthly fee to use. Direction is from your home PC to the internet, going to your bank, google, porn sites,,,, this not what you want. This VPN uses a VPN server that is in the middle of your communications.

2) Origination: the internet world wide web, destination: your home network.
This VPN type is used to provide a secure connection onto your local network, in bound to you local home network, from your office computer, your cell phone in your car, tablet at the coffee shop.. This is what you want, it does not have a monthly fee and is normally completely free. OpenVPN is this type of VPN.

If you home internet provider is a cellular network, then DDNS (dynamic Domain Name System) may not work, the DDNS is needed for most Inbound VPN services (OpenVpn) to get your home IP address (it is not static) so OpenVPN may not work for you.

A video on the paid VPN.
------------------------------------------------------
Hacked VPNs
-----------------------------------------------------
 

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
Thanks all - I went the port forwarding route - too lazy to deal with my editing my modem. Seems to work just fine!
 

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
Alright - I appreciate that. My ISP is comcast, and I own the modem Netgear CM1000. Suggestions on a simple VPN setup?
My router is an Orbi Mesh.
 

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
Quick update - and I appreciate all the advice - I spent several hours trying to get VPN to work. Started with NOIP then OpenVPN, and then kept running into little problem after little problem. So honestly I gave up, went the port forwarding route which some at least say is not terrible if you have a good firewall. If there is a CLEAR and reliable guide step by step on VPN out there, that would be appreciated. Thanks.
 

Mike A.

Known around here
Joined
May 6, 2017
Messages
3,828
Reaction score
6,387
Firewall won't really help you any. At least not the firewall in a typical home router. You're bypassing it by opening up the port.

Yeah, it can be a little of a challenge sometimes. Ask questions here... You'll get help:

 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
24,984
Reaction score
48,723
Location
USA
I was there too...tried to do all this research to find directions and got to the point I just enabled it and kinda of followed what it was asking and it worked.

Just go to OpenVPN and enable it and see what it says - probably asks you to create a user/PW, DDNS name, encryption method, and create certificate. Then email that certificate to you and save the certificate on your mobile device. Then install the OpenVPN app and select the certificate and then connect and you are on your home network.

It really is simpler than our minds make it out to be.

This kinda helped me to:

 

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
Maybe my problem is the ORBI router I have? It has VPN settings. But when I put Open VPN on the computer that has BI, I could not get the config file to work. It kept complaining about TUN versus TAP, among other things.

As far as I know, you need 2 pieces, right? Open VPN running on the PC, and Open VPN on your iPhone?
 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
24,984
Reaction score
48,723
Location
USA
I have OpenVPN running on my router and phone. I do not have it running on the PC. Does the orbi have a VPN and OpenVPN option?
 

Mike A.

Known around here
Joined
May 6, 2017
Messages
3,828
Reaction score
6,387
Maybe my problem is the ORBI router I have? It has VPN settings. But when I put Open VPN on the computer that has BI, I could not get the config file to work. It kept complaining about TUN versus TAP, among other things.

As far as I know, you need 2 pieces, right? Open VPN running on the PC, and Open VPN on your iPhone?
Yes, two parts - a VPN server and a VPN client(s).

You should be enabling VPN on your ROUTER not on the BI PC. You could do the latter but more complicated and the former is easier/better in this case since the ORBI supports OpenVPN.

See the link that wittaj gave you, same as I posted earlier. That's what you should be doing.
 

CedarTree

Getting the hang of it
Joined
Feb 12, 2020
Messages
100
Reaction score
16
I did - but I think I read it to mean I needed config files on BOTH the PC and the iPhone. I'll try it again maybe tonight. Thanks!
 

Mike A.

Known around here
Joined
May 6, 2017
Messages
3,828
Reaction score
6,387
No config needed on the BI PC.

Your phone will connect to the VPN and then will function basically as a client on your network in generally the same as as if connected locally via WiFI.
 
Top