cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
2,137 Views
Message 1 of 9

FTTP - Ports being firewalled

Hi,

I am unable to connect to a certain mail server from my BT FTTP connection. It works using other internet access methods. I have checked and all security related products are disabled on my BT account.

To verify, I can see (by executing from a Linux server elsewhere on the internet) that my mail server has the following ports open:

➜ ~ sudo nmap -F a.b.net
[sudo] password for k8s:
Starting Nmap 7.80 ( https://nmap.org ) at 2023-12-02 09:13 CET
Nmap scan report for a.b.net (x.x.x.x)
Host is up (0.036s latency).
rDNS record for x.x.x.x: a.b.net
Not shown: 91 filtered ports
PORT STATE SERVICE
21/tcp open ftp
80/tcp open http
443/tcp open https
465/tcp open smtps
587/tcp open submission
993/tcp open imaps
995/tcp open pop3s
3306/tcp open mysql
8888/tcp closed sun-answerbook

Nmap done: 1 IP address (1 host up) scanned in 2.06 seconds
 

If I repeat the same from my BT connection:

➜ ~ sudo nmap -F a.b.net
Password:
Starting Nmap 7.94 ( https://nmap.org ) at 2023-12-02 08:11 GMT
Nmap scan report for a.b.net (x.x.x.x)
Host is up (0.014s latency).
rDNS record for x.x.x.x: a.b.net
Not shown: 98 filtered tcp ports (no-response)
PORT STATE SERVICE
80/tcp open http
443/tcp open https

Nmap done: 1 IP address (1 host up) scanned in 1.86 seconds
➜ ~
 
 
How do I go about getting BT to fix this firewalling?
 
Thank you.
Tags (4)
0 Ratings
Reply
8 REPLIES 8
2,120 Views
Message 2 of 9

Re: FTTP - Ports being firewalled

@resto 

Welcome to this user forum for BT Retail phone and broadband customers.

Are you a BT Business Customer?

I would guess that its BT preventing mail spam being generated, by blocking those ports, and only allowing http and https connections. 

0 Ratings
Reply
2,113 Views
Message 3 of 9

Re: FTTP - Ports being firewalled

Hi Keith,

No, residential. I just want to read my email on my phone!

Is there a way of opening a ticket to get them to re-open the ports?

Thank you, appreciate you replying.

0 Ratings
Reply
2,105 Views
Message 4 of 9

Re: FTTP - Ports being firewalled

@resto 

I have no idea, maybe another forum member can help?

This is just a customer to customer help forum, everyone here, including myself, are just customers.

The only BT Employees are the forum moderators.

0 Ratings
Reply
2,102 Views
Message 5 of 9

Re: FTTP - Ports being firewalled

Hi Keith,

Yeah, I get that & apprecite you replying.

I guess I just need the actual support avenue to go down 🙂 Struggling to find that, hence posting here.

Thank you.

0 Ratings
Reply
2,031 Views
Message 6 of 9

Re: FTTP - Ports being firewalled

@resto 

I will do some assumptions here so if any of these are wrong then do forgive me.

Assuming that the Mail Server in question is one you are hosting at your home address. And you are trying to get to this from your home, I believe I understand what is happening.

From outside your LAN, anywhere else on the internet, you will be going to the DNS name which then resolves through Dynamic DNS to your assigned public IP address and filter through your Smart Hub to your mail server on your LAN. No issue.

From internal you are looking for the DNS name that resolves through Dynamic DNS to your external public IP address which your Smart Hub already knows is you. So modern routers have a firewall rule inbuilt and hidden to stop this loop, as you will be ‘public IP’ as the source and the same ‘Public IP’ as the destination. Could be the http and https it is picking up is therefore the LAN side of the Smart Hub itself.

You could test this to a certain extent by using a VPN or iCloud Private Relay on an Apple device, and from your LAN then trying the same thing. As the source address will then be different it should allow you to reach the destination.

This does therefore mean you would need to rethink how to get to your mail server as it won’t work internally unless your LAN DNS is replaced by a local one that basically tells anything on the lan that mail.externaladdress.com actually resolved to 192.168.1.1 (or whatever private address of your mail server) instead of public IP address of your BT Router.

0 Ratings
Reply
2,027 Views
Message 7 of 9

Re: FTTP - Ports being firewalled

Sorry, I should have mentioned that this is a public machine, in a data centre.

0 Ratings
Reply
2,019 Views
Message 8 of 9

Re: FTTP - Ports being firewalled

@resto then ignore everything I said 😄

0 Ratings
Reply
2,006 Views
Message 9 of 9

Re: FTTP - Ports being firewalled

Just thinking about this, though. It is doubtful that BT would be Firewalling ‘outgoing’ connections to anywhere. I could understand ‘incoming’ connections, but why would they care to restrict connections going out of their network to a random data centre, to an IP address they wouldn’t know about, and yet allow HTTP and HTTPS? Somehow seems unlikely.

What might be more likely is that you have a firewall set up at the data centre that is restricting access from certain IP addresses for ‘incoming’ connections to only http or https. Whether you did this, or perhaps the datacentre. As to why or how, I don’t know, as your IP would be dynamically assigned from BT. But I would check the firewall settings on and around your mail server and ask the hosting company why they might be blocking access.