Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to open port 8883 for MyQ garage opener

    Scheduled Pinned Locked Moved Firewalling
    32 Posts 6 Posters 6.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate @cheapie408
      last edited by

      @cheapie408

      Yes. It needed nothing special (unless you are doing outbound filtering. I am not). All of the connections are outbound.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      C 1 Reply Last reply Reply Quote 0
      • C
        cheapie408 @Derelict
        last edited by

        @derelict my PFsense box is mostly stock with just a couple port forwarding to my cameras and homeseer.

        when I do port checker it shows that port 8883 is closed. Support said this needs to be open for it to work. WTH

        DerelictD johnpozJ 3 Replies Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate @cheapie408
          last edited by

          @cheapie408

          Outbound, not inbound.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate @cheapie408
            last edited by

            @cheapie408

            If an IoT device requires inbound port forwards or rules, return it.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            C 1 Reply Last reply Reply Quote 1
            • C
              cheapie408 @Derelict
              last edited by

              @derelict I'm about to do just that.

              DerelictD 2 Replies Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate @cheapie408
                last edited by

                @cheapie408

                I think they are being typical support monkeys.

                I remember it took a while to get them on the wifi but since I got that worked out they've been working fine. Opened the garage for my daughter while I was on the beach a couple states away. :)

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate @cheapie408
                  last edited by

                  @cheapie408

                  These are the states:

                  IOT 	tcp 	172.29.98.227:51798 -> 20.62.215.172:8883 	ESTABLISHED:ESTABLISHED 	4.391 K / 4.387 K 	191 KiB / 178 KiB 	
                  IOT 	tcp 	172.29.98.228:61648 -> 40.83.217.203:8883 	ESTABLISHED:ESTABLISHED 	1.067 K / 1.064 K 	47 KiB / 43 KiB 	
                  IOT 	tcp 	172.29.98.229:54858 -> 13.88.21.103:8883 	ESTABLISHED:ESTABLISHED 	240 / 237 	12 KiB / 10 KiB
                  

                  All outbound connections....

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    cheapie408 @Derelict
                    last edited by

                    it's showing connected on my Wifi I can ping it and all. In fact it sits 3 ft from one of my AP. It's been showing online for awhile but the app says that it's offline.

                    It's annoying is that it would drop in and out. I'd send a command and it would not do anything and then in the middle of no where it would open or close the garage

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      cheapie408 @cheapie408
                      last edited by cheapie408

                      btw I did a test port and received this. 171 is the address of the myq device

                      50547f8c-6750-4277-9e57-88c15d2157fb-image.png

                      DerelictD 1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate @cheapie408
                        last edited by

                        @cheapie408

                        8883 is the port the cloud servers listen on, not the door openers. They connect to My-Q on TCP/8883 not the other way around. You might want to talk to the people who installed the opener to see if they understand how it all works.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @cheapie408
                          last edited by

                          @cheapie408 said in Unable to open port 8883 for MyQ garage opener:

                          Support said this needs to be open for it to work

                          As @Derelict stated this connection is outbound. I have a MyQ and I have NO Inbound ports to it at all. Works great..

                          What are you outbound rules?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          DerelictD 1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate @johnpoz
                            last edited by Derelict

                            @johnpoz The wisdom of doing this at all can be questioned lol. I can only hope that they are using something like a private key from the secure enclave to sign requests to open the doors and that they did it all right.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            johnpozJ C 2 Replies Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @Derelict
                              last edited by johnpoz

                              @derelict said in Unable to open port 8883 for MyQ garage opener:

                              that they did it all right.

                              I found this - does seem like there are some local stuff you can do via rf, etc.

                              IoT stuff is always a question.. But overall from this finishing comment, it seems to be one of the better implementations.

                              https://www.mcafee.com/blogs/other-blogs/mcafee-labs/we-be-jammin-bypassing-chamberlain-myq-garage-doors/


                              We would like to finish by commenting that the likelihood of a real-world attack on this target is low, based on the complexity of the attack and installation footprint. We have discussed this with Chamberlain, who has validated the findings and agrees with this assessment. Chamberlain has made clear efforts to build a secure product and appears to have eliminated much of the low-hanging fruit common to IoT devices

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              DerelictD 1 Reply Last reply Reply Quote 1
                              • DerelictD
                                Derelict LAYER 8 Netgate @johnpoz
                                last edited by

                                @johnpoz Good article. Thanks.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • C
                                  cheapie408 @Derelict
                                  last edited by

                                  @derelict I'll have to dig into this. I already have an existing remote garage opener tied to HomeSeer this MyQ was an impulse buy more or less a backup so not critical. Maybe I'll hack it up and see if I can make it local.

                                  DerelictD 1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate @cheapie408
                                    last edited by

                                    @cheapie408 said in Unable to open port 8883 for MyQ garage opener:

                                    Maybe I'll hack it up and see if I can make it local.

                                    I don't know what that means but good luck.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      cheapie408
                                      last edited by

                                      Since I last posted this, I gave up and turned off my PFSense and moved to use the Xfinity Xfi router as my last resort. After several months, it was unbearable to deal with the Xfi router so I moved my network back to the PFSense.

                                      While I was using the Xfi router and even an old Asus router the garage opener worked flawlessly. As soon as I moved it to the PFsense it acted up again.

                                      Still looking for a solution to this. :(

                                      V J johnpozJ 3 Replies Last reply Reply Quote 0
                                      • V
                                        viragomann @cheapie408
                                        last edited by

                                        @cheapie408
                                        So when you check the states in pfSense, did you see your device connected to anything on destination port 8883?

                                        Is the device on a segmented network?
                                        Are there other devices in its subnet, which can successfully connect to the internet?

                                        Possibly pfBlockerNG or something else is blocking the connection?

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          Jarhead @cheapie408
                                          last edited by

                                          @cheapie408 Set up a VPN and stop opening ports for anything.
                                          You'll be glad you did!

                                          1 Reply Last reply Reply Quote 0
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator @cheapie408
                                            last edited by

                                            @cheapie408 said in Unable to open port 8883 for MyQ garage opener:

                                            Still looking for a solution to this. :(

                                            Solution to what exactly.. There are no inbound traffic needed for this, there is no UPnP needed for this.. The chamberlin hub makes outbound connections on that port..

                                            I just looked and here is mine

                                            hub.jpg

                                            3.99 is my hub IP..

                                            There is nothing in pfsense that would prevent this out of the box. Been working for years on pfsense for me - zero to do.. So unless you are blocking outbound traffic, there is nothing to do. Are you running IPS, or using block lists for ips in pfblocker?

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                                            1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.