DSM 7.1 [RT6600ax] Unable to reach internal NAS or printer or IoT devices

Currently reading
DSM 7.1 [RT6600ax] Unable to reach internal NAS or printer or IoT devices

6
0
NAS
DS920+
Router
  1. RT6600ax
Operating system
  1. macOS
Mobile operating system
  1. iOS
Hi,

I am having issues accessing internal devices over VPN. I have four VLAN's on my RT6600ax router

1. Primary Network - Personal Laptops, phones and NAS. Disabled AP isolation
2. Guest Network - Enabled AP isolation
3. IoT network - Has all IoT devices including Homekit devices, TV and Printer. Disabled AP isolation
4. Work Network - Work devices

I listed out few things that I have done to give more context

- I setup few firewall rules based on the knowledge gained from here!. To connect IoT devices using Apple Home, I manually enabled mDNS on the router. Everything works fine when I am on Primary network locally
1660070313_34W0a.png




- I have started Synology SSL VPN with the following settings and installed the VPN plus app on Iphone and turned the VPN setting ON. I can access the router login page but CAN'T access to the printer or TV on IoT network. I also can't access the homekit devices on Apple Home app. I tried to use L2TP VPN and that resulted in the same end result as well
1659994853_23Y6m.png


- The Internal IP address of all the 4 VLAN's start with 192.168..
1659995174_Lg1DJ.png





- I have tried L2TP as well and the end result didn't change. Cant connect to Apple HomeKit devices on VPN
1659995287_kh6vY.png


- I have no idea how to view/set/modify the state of homekit devices on Apple Home over VPN. Can anyone help please
1659994731_y4u5m.jpg


- This is how I setup my Primary and IoT network
1660072598_EPOIU.png

1660072612_Z3BAu.png



Yesterday, I reset the router and removed all the previous setting and firewall rules. I set up the VLAN's as is and tried to access the internal devices on VPN. However, I still couldn't get the access. These are the latest firewall rules after the restart
Screen Shot 2022-08-16 at 1.36.46 PM.png


PS: I have enabled Threat Protection with the default settings. I have disabled the Threat Protection and still have the same issue
 
Hi, welcome to the forum. Hopefully someone with a RT6600ax or other router with the SRM 1.3 RC installed will respond.

I'm still on SRM 1.2.5 so it's difficult to replay on VLAN interconnectivity and VPN Plus SSL-VPN. It may well be that the SSL-VPN gateway on the router is considered separate to the all the local VLANs.

I did a search for 'homekit TCP UDP' and found this Firewall rules for HomeKit with HomeAssistant

BTW looking at your firewall rules, the firewall is for all connections so a source of ANY will include the the Internet coming in. You should restrict access from the Internet to the bare minimum services that you wish to expose, and that probably [shouldn't] include Windows File Sharing (SMB/CIFS).

Also, you would be wise to disable SRM's UPnP and clear out the Client List. If you need the firewall rules that the UPnP clients want to create then you can add these yourself, but why go to the trouble of using VLANs only to allow the client devices to drill holes through the access control? Here's what it looks like disabled in SRM 1.2.5 ...
1660729511739.png
 
Thanks for your reply and information on the firewall rules. I will look into that article to modify the firewall rules on the NAS that host the HomeAssistant VM

I have removed the UnPnP and windows file sharing from the firewall rules. The new list has only two rules.

Screen Shot 2022-08-17 at 12.02.49 PM.png
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

  • Question
An update for the next victim after finally getting RT6600ax OpenVPN client to establish a tunnel to a...
Replies
1
Views
910
Wow! Lots of suggestions. I will have to check back after I try all that is mentioned.
Replies
22
Views
4,867
  • Question
So you have two sites with identical local IP subnets and even IP assignments? If trying to connect from...
Replies
2
Views
1,100
Hello Sorry for the long time to update. I uninstalled the VPN Server and reinstalled. Same result, I...
Replies
19
Views
3,149
Excellent!! It's frustrating to keep going over and over the same ground but so often it's a small thing...
Replies
16
Views
6,444

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top