modem and router port forwarding

Posted on 2012-04-05
Last Modified: 2012-04-17
I am having some router networking is my configuration:

I have a DSL modem at I configured port forwarding for ports 22 and 1521 to route to

I have a router at  I have port forwarding configured to forwarding ports 22 and 1521 to

I have a linux server at

When I use PuTTY to SSH on port 22 to the linux server I get a prompt to login to the linux server but it does not allow me to login.  I get an error message that access is denied.

So it looks like traffic is getting to the linux server but the linux server is not allowing me to login.

Note that I am able to login if I am on the local network and use SSH to connect to  I only have a problem if I try to connect to the linux server using the public IP address.

Do you know what I can change to allow access to the linux server?

Note that I am confused about how traffic gets from to  The default gateway is  I am not able to set the port forwarding in the DSL modem to  If I try I get the error message "NAPT server IP address is not a valid host LAN address."

Can you point me to a log file on the linux server that explains why it's rejecting the login from the public IP address?

Can you tell me how to either configure the linux server or the network to allow logins from the public IP address?  Note that this was working at one point.  I believe a tech support person from the router company had me change my network IP address and after that I was not able to connect to the linux server through the public IP address.
Question by:david_m_jacobson
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 26

Accepted Solution

Fred Marshall earned 500 total points
ID: 37814447
Let's review those port forwards:

"I have a DSL modem at I configured port forwarding for ports 22 and 1521 to route to"

Presumably is the router WAN/Internet side, yes?  If so then understood.

"I have a router at  I have port forwarding configured to forwarding ports 22 and 1521 to"

Presumably this is the router with WAN address, yes?  If so, OK.

It sounds like it may work:
Packets arriving at the modem router, destined for port 22 will go to  But, to which port there?  That has to be part of the setup.
I'm going to suggest something different just to make the point:

When packets arrive for port 22 then we will forward then to that is, port 999.

When packets arrive for port 999 at then we will forward them to  that is port 22.  

I believe that's what you want.
So it could be:
port 111 from the outside world
port 222 between the routers
port 22 behind the last router.

That should be all there is to it.

Author Comment

ID: 37814501
I don't follow everything stated above. In the SpeedStream 4300 DSL Modem configuration in the Host Configuration I see the Default Gateway set to an empty field and I see a checkbox that is checked to indicate "Use WAN."

In the DHCP Configuration of the DSL modem I see DHCP enabled, "Start IP Range" set to and the "End IP Range" set to  Then I see the Default Gateway set o

Note that I have two physical devices: a SpeedStream 4300 DSL modem and an Encore router.  The DSL modem is plugged into the Encore router.  The linux box is plugged into the Encore router.

I don't understand how to configure

Separately, I have a Windows PC connected to the Encore router.  When I enter "ipconfig /all" from a DOS prompt on the Windows PC I see the DNS server, Default Gateway, and DHCP Server all set to

When I log into the admin tool for the Encore router I see the WAN Settings section with the IP address set to and the Default Gateway set to In the LAN Settings section of the Encore Router I see the IP address set to and DHCP enabled.

Does any of this information help? I'm not sure I followed your suggestion.  I think you are suggesting setting the DSL Modem to forward incoming requests on port 22 to port 999 on the Encore router.  Then I should configure the Encore router to forward incoming requests on port 999 to port 22 on my linux server at  Is that correct?
LVL 26

Expert Comment

by:Fred Marshall
ID: 37857905
Sorry I didn't respond sooner.  Thanks for the points!

Yes that's the idea and it sounds like it worked!  Good.

I wasn't trying to suggest any particular port numbers .. those were just examples.  You'd want to avoid "well known" port numbers.

Featured Post

Turn Insights Into Action

You’ve already invested in ITSM tools, chat applications, automation utilities, and more. Fortify these solutions with intelligent communications so you can drive business processes forward.

With xMatters, you'll never miss a beat.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Usually shares are where we want them for our users and we tend to take them for granted. There are times, however, when those shares may disappear causing difficulty for your users. One of the first things to try is searching for files that shou…
Outsource Your Fax Infrastructure to the Cloud (And come out looking like an IT Hero!) Relative to the many demands on today’s IT teams, spending capital, time and resources to maintain physical fax servers and infrastructure is not a high priority.
Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question