Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    EchoLink

    Scheduled Pinned Locked Moved NAT
    18 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      grewterd
      last edited by

      I am trying to setup port forwarding for EchoLink. It needs UDP ports 5198 and 5199. I've tried everything I can think to try, read the docs, I don't understand what I'm doing wrong.

      Steps:
      Firewall, NAT, Port Forward, Add
      Interface: WAN
      Protocol: UDP
      Destination: WAN address? Is this right?
      Destination port range: Other, 5198, Other, 5199
      Redirect target IP: IP of the system running EchoLink
      Redirect target port: Other, 5198

      I would appreciate any help I could get. Thank you.

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @grewterd
        last edited by

        @grewterd said in EchoLink:

        Destination: WAN address? Is this right?

        Yes.

        Did you also add a firewall rule to allow the traffic?

        Ensure that the EchoLink device accepts access from outside your LAN.

        Also ensure that the packets aren't blocked by your ISP. Use Diagnostic > Packet Capture on WAN interface to investigate.

        1 Reply Last reply Reply Quote 0
        • G
          grewterd
          last edited by

          I believe I set the NAT rule to add the firewall rule, there is a rule named "NAT EchoLink" that was automatically added.

          Here is the result when I ran a packet capture on 5198:

          13:26:38.369465 IP 10.0.0.143.57918 > 34.207.167.50.5198: UDP, length 1
          13:26:48.371185 IP 10.0.0.143.52661 > 34.207.167.50.5198: UDP, length 1
          

          Here is the result when I run a packet capture on 5199:

          13:29:09.288776 IP 10.0.0.143.33535 > 34.207.167.50.5199: UDP, length 1
          13:29:19.290098 IP 10.0.0.143.2575 > 34.207.167.50.5199: UDP, length 1
          

          When I try doing both "5198,5199" I get no results.

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8
            last edited by

            @grewterd said in EchoLink:

            EchoLink

            ah i like it
            please post a screenshot of your Nat rules and firewall rules,
            try "packet capture" from both interface (LAN and WAN)
            check windows firewall

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            1 Reply Last reply Reply Quote 0
            • G
              grewterd
              last edited by

              LAN packet capture 5198:

              14:40:38.469654 IP 192.168.0.100.52805 > 34.207.167.50.5198: UDP, length 1
              14:40:48.472197 IP 192.168.0.100.5198 > 34.207.167.50.5198: UDP, length 1
              

              LAN packet capture 5199:

              14:41:24.213696 IP 192.168.0.100.5199 > 174.129.209.125.5199: UDP, length 60
              14:41:31.371099 IP 192.168.0.100.51043 > 34.207.167.50.5199: UDP, length 1
              14:41:41.372416 IP 192.168.0.100.5199 > 34.207.167.50.5199: UDP, length 1
              14:41:50.212412 IP 192.168.0.100.5199 > 174.129.209.125.5199: UDP, length 60
              

              I have tried with the Windows firewall disabled, still fails.

              726d93e0-b1c5-4df0-a8c7-07bedb11de38-image.png

              a4e42ece-6e17-4318-ac16-3420b20de996-image.png

              1 Reply Last reply Reply Quote 0
              • kiokomanK
                kiokoman LAYER 8
                last edited by kiokoman

                outbound TCP to port 5200 is also needed, is it open from lan to wan?

                also that port forward is wrong, you need 2 rules one for 5198 and one for 5199, you are redirecting both to port 5198

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                chpalmerC 1 Reply Last reply Reply Quote 0
                • G
                  grewterd
                  last edited by

                  I really appreciate everyone's help.

                  I have even tried hoping on VPN with no success. Wonder if it's this computer. The Android app connects without issues on the same network. Planning to test on my laptop shortly.

                  I have not created an outbound TCP port 5200 rule, reason is the TCP test works, but if you think I should I will.

                  c280ab23-5abc-4dba-be9f-8b79a57eecc3-image.png

                  I just changed the rules to the following. Still failing and the Packet Capture is the same.

                  3d3269ac-56e0-4ea9-8d88-82c819bbe283-image.png

                  6f930052-8a8f-495a-84b4-523cee617a86-image.png

                  1 Reply Last reply Reply Quote 0
                  • chpalmerC
                    chpalmer
                    last edited by

                    You can include both ports on the same port forward. If you put 5198 in the "From port" box and 5199 in the "To port" box it will work. Makes it simpler IMHO.

                    How about the firewall on the machine running Ecolink? I see you say its disabled but my guess is you need to look again.

                    You are logging the firewall rules so what does your firewall logs show?

                    Triggering snowflakes one by one..
                    Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                    1 Reply Last reply Reply Quote 0
                    • chpalmerC
                      chpalmer @kiokoman
                      last edited by chpalmer

                      @kiokoman

                      also that port forward is wrong, you need 2 rules one for 5198 and one for 5199, you are redirecting both to port 5198

                      Nah.. He did it right. I do it this way all the time.

                      The "From port" field will translate to whatever is in the "Redirect target port/ Port field.

                      The "To port field will translate and be "next in line" after whatever is in the Redirected field sequentially.

                      Triggering snowflakes one by one..
                      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                      1 Reply Last reply Reply Quote 1
                      • kiokomanK
                        kiokoman LAYER 8
                        last edited by

                        nice, I learned something new, I had the impression that it didn't work that way

                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                        Please do not use chat/PM to ask for help
                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                        1 Reply Last reply Reply Quote 0
                        • kiokomanK
                          kiokoman LAYER 8
                          last edited by

                          ok, there is nothing strange to do with the echolink program, it's a simple nat rule
                          Immagine.jpg

                          the order of the rules are important, maybe you have the permit/nat rules after a deny rule

                          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                          Please do not use chat/PM to ask for help
                          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                          1 Reply Last reply Reply Quote 0
                          • chpalmerC
                            chpalmer
                            last edited by

                            I should play with Echolink here. I never have. Been kind of a purist over the years and only used IRLP once over the air.

                            My radio gear in this room is all commercial. :)

                            grewterd- you should not need an extra outbound rule unless you have altered the default "allow all" LAN rule.

                            Triggering snowflakes one by one..
                            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                            1 Reply Last reply Reply Quote 0
                            • G
                              grewterd
                              last edited by

                              This is all I have in my rules.

                              79070799-3803-47ce-9fef-2457475cab3c-image.png

                              1 Reply Last reply Reply Quote 0
                              • chpalmerC
                                chpalmer
                                last edited by

                                From what you show there nothing is actually hitting your WAN.

                                Triggering snowflakes one by one..
                                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                1 Reply Last reply Reply Quote 0
                                • kiokomanK
                                  kiokoman LAYER 8
                                  last edited by

                                  you have "block private network", you can disable that, you have some hits there, do you have another modem before pfsense?

                                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                  Please do not use chat/PM to ask for help
                                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                  G 1 Reply Last reply Reply Quote 0
                                  • G
                                    grewterd @kiokoman
                                    last edited by

                                    @kiokoman O.M.G.

                                    I totally forgot this stupid comcast thing is a router also. grrrrr

                                    1 Reply Last reply Reply Quote 0
                                    • G
                                      grewterd
                                      last edited by

                                      Holy cow. That was it!

                                      I tried to replace the stupid comcast box with a straight modem that I purchased but the phone kept dropping calls. Then they told me I will lose my unlimited data and have to pay $50 extra a month if I used my own modem.

                                      I'm about to revisit that with them.

                                      Next stupid question. Can I allow more than one IP to use this? Say my desktop and laptop?

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator
                                        last edited by johnpoz

                                        @grewterd said in EchoLink:

                                        Then they told me I will lose my unlimited data and have to pay $50 extra a month if I used my own modem.

                                        What? The fee if you go over their cap is 50 I think. But you understand your paying them X $ a month now for whatever device they gave you..a They only do that cap in certain states, and for the last fee months been completely suspended - to be honest they going to have hard time justifying putting it back.. Other then just a easy money grab..

                                        I was comcast for years, always used my own modem.. Now on wowway - use my own.. They pay for themselves in a like a year tops.. Depending on how much their nonsense rental fee is.. And how much you spend on your modem. But $80 could be seen typical for a modem. At $10 a month rental fee, after month 8 your gravy..

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.