Deco X55 VPN External Access Problems

Deco X55 VPN External Access Problems

Deco X55 VPN External Access Problems
Deco X55 VPN External Access Problems
a week ago - last edited a week ago
Tags: #VPN
Model: Deco X55  
Hardware Version:
Firmware Version: 1.7.1 Build 25080612 Rel. 70421

Hi, I know this subject is well trodden but I've reached a block and hopefully someone can help. 

 

I've run VPNs from home servers for many years and am very familiar with double NAT issues, ports and the usual pitfalls, however getting a Deco L2TP server accessible remotely using an iOS/MacOS/iPadOS device has got me.

 

My topology is: ISP --> Deco X55 using PPTP (IPV4 and IPV6) --> Mesh (note, there is no ISP router)

 

I have used DynDNS for many years and (while too expensive!) has never been an issue for me. 

 

I created the L2TP VPN server on the Deco using PSK, I've configured the iOS/macOS/iPadOS devices to connect using my DynDNS host name, the results are:

 

1. Connect internally using the external hostname, connected OK - so all credentials and config work.

2. Connect on iOS using 5g - fails.

3. Connect macOS and iPadOS using tethering via iPhone - fails. 

 

I can see the Deco logs which suggest the negotiations all work (the request reaches the server, leases etc created) but the connection seems to end on the server side with this log message. 

 

Tue Oct 28 10:10:28 2025 user.info root: IPsec-user: verb : up-host
Tue Oct 28 10:10:28 2025 user.info root: IPsec-user: /sbin/hotplug-call ipsec client is not running, exit 

 

There is clearly more in the logs - but it needs a lot of redacting!!

 

I have tested external port forwarding from the X55 to an internal NAS using the host name - that's fine, so once again proving that the ISP/DynDNS routing is fine.

 

One oddity I do have in my network, is that I use an X50-5g Deco as a hybrid mesh failover, this is always connected to a 5g network, but given that my port forward test was OK and dynDNS reports my main ISP Address for the host I don't believe this is the issue. 

 

Finally, I have discovered one problem (TP-LINK) with the Deco connecting to DynDNS, if I specify the wildcard option in the DynDNS host I want to use, the Deco fails to connect to it, if I take the wildcard option off it connected.

 

Any help gladly accepted. 

  1      
  1      
#1
Options
2 Reply
Re:Deco X55 VPN External Access Problems
Wednesday

  @RobFG 

Hi, thank you very much for the feedback.

There are some details I hope you can help check further.

Does PPTP here refer to your current IPV4 internet connection type? (If yes, may I know your ISP?)

 

 

"Finally, I have discovered one problem (TP-LINK) with the Deco connecting to DynDNS, if I specify the wildcard option in the DynDNS host I want to use, the Deco fails to connect to it, if I take the wildcard option off it connected."

Do you mean, with "Wildcard" disabled here, iPhone/iPad/Mac now are able to connect to the L2TP VPN server configured on Deco X55 via the host name?

1. Connect internally using the external hostname, connected OK - so all credentials and config work.

2. Connect on iOS using 5g - success.

3. Connect macOS and iPadOS using tethering via iPhone - success.

 

Wait for your reply.

Best regards.

  0  
  0  
#2
Options
Re:Deco X55 VPN External Access Problems
Wednesday

  @David-TP 

 

Thanks for the reply - apologies that I mentioned lots of things in my post, just trying to demonstrate I've tried to resolve this before posting. 

 

For the wildcards in DynDNS, if I created a host (bob dot server dot net) and included the wildcard option then tried to connect to this host using the DDNS facility in the app, it would fail consistently.  So I tried creating a new domain (bob1 dot server dot net) with the wildcard option disabled, the Deco connected first time and has remained connected since. 

 

For the ISP - I am using full fibre (not LTE) from EE/BT in the UK, using the DynDNS host name that is connected, I can see traffic hitting the router (port forward works and VPN starts) so I'm confident I'm not using a CG-NAT address.  I have configured an IPV4 and IPV6 connection in the Deco for PPOE - the DynDNS service is using the IPV4 address, my address begins 86.184 

 

Hope that helps

 

Regards, Rob

  1  
  1  
#3
Options