• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 469
  • Last Modified:

Using VPN client for web app hosting

My ISP is blocking port 443.  I can get around that by running StrongVPN on my web app server, but it intercepts all traffic including domain traffic intended for the 2nd NIC.  What I want is for all domain traffic to go over NIC2 and all internet to go over NIC1 while the StrongVPN client is running.  I contacted StrongVPN before coming here, but they are unable to assist since it is not a true connectivity problem.

What do I need to do to make this work?
  • 5
  • 3
1 Solution
RobOwner (Aidellio)Commented:
Have you contacted your ISP to allow 443 to be open?  

Have you considered running on a non standard port e.g. https://yourdomain.com:8443?  Very easy to set up a redirect to that from a sub domain if your clients need to have an easier address to remember e.g. secure.yourdomain.com would redirect to https://yourdomain.com:8443
CPA_MCSEAuthor Commented:
I tested that previously and www.checkmyports.net and other tools told me the alternate port was not open either.  

On the router side, I had it port-forwarding from (using your example) 8443 to 443 on my server (because the web app requires 443).  After that did not work, I also enabled port triggering to send 443 traffic from the server out through 8443.  So, at that point, 8443 was going to 443 and 443 was going out to 8443.  No dice.  Port 8443 not open either.  

The ISP and the server is in a country where nobody on the phones has any idea what is a port.  I also tried with a native speaker as middle-man, but still no clue...

So, my StrongVPN work-around works fine except that the machine cannot communicate with the local domain when the VPN client is turned on.  That is the problem I am hoping someone can help me resolve.

I tried running StrongVPN (DD-WRT) on the router and connecting the internet NIC to that, but for whatever reason 443 reports as blocked although StrongVPN asserts they are not blocking it.  So, now I am back to trying to run the client directly on the machine because that reports 443 as open BUT it cannot communicate with the domain.

At this point, the router is also suspect and so I want to cut that out of the equation and run the client directly on the/a machine.  Suggestions about how to get it to work so that I don't also lose domain traffic?
RobOwner (Aidellio)Commented:
Have you considered getting your site hosted outside of his restriction?

Aside from that, most VPN clients have a setting whether to route all traffic through the VPN gateway.  What client are you using to connect to the VPN as I know where it is in Windows but not sure in other clients.
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

CPA_MCSEAuthor Commented:
I am using StongVPN's client.  I believe it to be an implementation of OpenVPN.  I will look into it to see if maybe I can use vanilla OpenVPN or some implementation with those options.

Hosting it elsewhere is not an option.
CPA_MCSEAuthor Commented:
It looks like you may be on to something there, Rob.  I clueless about how to set routes, but I think it would be possible to force a route in the OpenVPN config file.  Here is what is in one of my old config files (not the one used by the server).

remote 4672 udp
remote 123 udp
remote 53 udp
key-direction 1
dev tun
resolv-retry infinite
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]
verb 4
reneg-sec 86400
echo vpn-dc5 ovpn224
tun-mtu 1500
route-method exe
route-delay 2
redirect-gateway def1
comp-lzo adaptive
explicit-exit-notify 2
fragment 1390
mssfix 1390
hand-window 30

Any idea what to put to force internet traffic over a specific NIC (preferred)?  Or (using just one NIC) exclude local domain traffic?
CPA_MCSEAuthor Commented:


Microsoft changes the network profiles to Public for guest machines when Hyper-V guests restart without being able to connect to a DC.  With the network profile set as Public, the guest was blocking everything.  I manually changed the network profile to Private and port-forwarding works just fine now.  No need for StrongVPN...

Thanks, MSFT for wasting my f time.  I am unable to figure how to set one NIC as private and the other as Domain, but whatever.  I can go back to using a single NIC now...
RobOwner (Aidellio)Commented:
Great news... well done
CPA_MCSEAuthor Commented:
See comment
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

  • 5
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now