Tech Tip: How to Troubleshoot Your Port Forwarding Issues

Port forwarding, or port mapping as it is sometimes referred to, is a routing feature that allows users to access devices on the Internet that are behind a firewall. Ports may also require mapping to allow applications on the Internet to function properly. Configuration requires multiple steps and may fail to succeed due to certain variables. See below for just a few common issues, then head over to our Support Portal for a full checklist of troubleshooting suggestions. 

  • Can you reach the WAN IP address from a remote connection?
    • Often, this means the destination device has a publicly-routable WAN IP. Note that the connection may be NAT’d and the address seen from the Web (e.g.: whatismyip.com) may not be the address on the WAN interface of the router. This is especially common for cellular connections.
      • These specific IP address ranges (RFC 1918) are reserved specifically as non-routable addresses to be used in private networks:
        • 10.0.0.0 through 10.255.255.255
        • 172.16.0.0 through 172.32.255.255
        • 192.168.0.0 through 192.168.255.255
      • If the router receives a WAN IP address within any of these private ranges, this means that connections originating from the Internet will not be able to get past the NAT router (without port forwarding) in order to actually reach the router’s WAN interface.
      • Cellular carriers may use addresses in the RFC 6598 space.
        • The RFC 6598 address space includes addresses from 100.64.0.0/10 to 100.127.255.255
  • Rule configured incorrectly
    • Check that you have the correct port(s) as well as protocol (TCP, UDP) and the Server’s LAN IP address (i.e. the device you are forwarding ports for).
  • Don’t have all the needed ports configured
    • Sometimes multiple forwarding rules are needed for the same address. Check with the manufacturer of the server device to confirm this if needed
    • Is a single port needed or should you use a Port Range?
  • Server is not responding locally
    • Try to communicate with the Server device locally first. If this does not work, remote access will not either.
  • Port conflict
    • There is already a rule that exists or another device on the LAN using the port(s) in question. 
  • IP conflict
    • The IP address used by the Server device also belongs to another device on the LAN.

Inseego 4G/5G Routers Now Available at 5Gstore

Think back to the first time you saw or used a mobile WiFi hotspot. That’s where our new partner, Inseego got its start. For the past 25 years, they’ve been leading the way by creating entirely new types of devices that allow users to connect wherever they are. 

By staying at the front of innovation, Inseego has earned the trust of leading wireless operators, technology titans, business users, government agencies and consumers.

From 2G to 5G, they’ve been through it all. In the 1990s, they started with Industry’s First Modems for Mobile Broadband.

In the 2000s,  they invented MiFi® hotspots, enabled the First Cellular Amazon® Kindle®, and the First USB Memory Stick Modem Combos for nationwide and global use. 

In the 2010s, they came out with the First Touchscreen Mobile Hotspot, with Advanced Enterprise Features and were known to have the “Highest Performance in the Market.”

Now, Inseego has released its First Commercial Mobile Hotspots and its First Complete 5G Portfolio. This includes the S2000e Enterprise 5G, FX2000e Enterprise 5G, FW2000e Enterprise 5G (Outdoor), and the FG2000e Enterprise 5G.

Inseego also invents new technologies, which make their products work more efficiently. The company holds key patents for antenna designs, thermal performance, quick response algorithms and other know-how that sets them apart from the rest of the industry. They also work with industry leaders to design, develop, test and deploy successful, end-to-end solutions.

Something else we really favor Inseego for is the simple fact that they are designed and developed in the USA. Per Inseego, “That translates into the highest quality, security, performance and reliability that service providers, enterprises and government users demand.”

We’re happy to announce that we will be carrying these new 5G products along with a LTE solution, at 5Gstore – most of which we have available today! So let us not delay our introduction any longer. 

First, for 4G LTE support only, look at the compact Skyus 160. With a small, rugged design and multi-carrier support, it keeps you connected almost anywhere for both primary and failover communications. Its Cat 6 LTE modem supports speeds up to 300 Mbps download and 50 Mbps upload. It also comes with a built-in battery for backup, so the Skyus 160 can support your most important workloads. 

Popular use case applications include mobile applications like creating a vehicle hotspot, setting up a temporary job site, or working from home. It’s also ideal for fixed environments such as SD-WAN installations for retail locations or branch offices.

Next, we have the S2000e Enterprise 5G. The Inseego Wavemaker™ 5G industrial gateway S2000e brings the best of 5G to a wide range of enterprise environments, from factories and warehouses to ports, fleets and smart city networks. This powerful, high-performance gateway can deliver multi-gigabit speeds, low latency and secure, reliable connections for facilities and distributed operations in virtually any location, from urban centers to rural areas. Use the S2000e to bring 5G to an existing router, or to connect remote surveillance cameras, kiosks, digital displays and other IoT endpoints.

Combining six antenna ports and 4×4 MU-MIMO with Inseego’s proprietary thermal mitigation technology, it delivers sustained high throughput even at the edge of the network. The S2000e provides ethernet, USB and I/O ports along with multiple power options and mounting options, offering the flexibility for almost any deployment scenario. 

Pair your S2000e with the Inseego mobile app and simplify self-installation. Inseego Connect™ cloud management makes it easy to configure, monitor and maintain the S2000e remotely. With unsurpassed RF performance and device-to-cloud intelligence, the S2000e industrial gateway opens the door to many new business solutions.

Whether you’re an operator providing high-performance fixed wireless access to your small business and residential customers, or an enterprise organization with distributed offices and remote employees, the FX2000 series is a great solution. It works well in homes, retail stores, restaurants, branch offices, medical clinics, dormitories, apartments and more.

In particular, check out the FX2000e Enterprise 5G. This is a compact indoor router that delivers fast, reliable 5G/LTE broadband to homes and businesses. It offers support for private networks, including CBRS, and boasts Wi-Fi 6 technology and ethernet with secure connections for up to 30 devices. A host of smart security and management features let users connect with confidence in their data privacy and protection.

The Inseego Mobile app makes it easy to find the best location to set up and remotely manage settings like network name and password. Users can also use the Inseego Connect™ platform to monitor, configure and troubleshoot a single FX2000 or an entire deployment of FX2000 series devices from one user-friendly platform. You can set alarm rules, schedule and run reports for data usage, signal quality, and alarm history, and group devices together to push widespread configurations.

The FX2000e offers dual SIM support and allows for auto-switching between SIMs based on signal strength, data usage, service availability, and quality. Multi-carrier firmware allows the FX2000e to be used on most major global carriers.

Look at the FW2000e Enterprise 5G (Outdoor) for more rural and suburban customers who might be at the edge of network coverage. Or, use this to provide 5G connectivity for private enterprise networks. In either case, the FW2000 series outdoor Customer Premises Equipment (CPE) uses high-gain directional antennas to extend the reach of carrier networks, providing 5G fixed wireless access (along with 4G LTE fallback at LTE CAT 22 speeds) to serve customers in more places.

The intuitive Inseego Mobile app makes it easy to find the strongest network signal and best mounting location for the FW2000 series outdoor CPEs. Once up and running the, IP67-rated FW2000 series is designed to stand up to harsh weather conditions and temperature extremes while protecting your network with enterprise-grade security.

Lastly, we have the FG2000e Enterprise 5G. The Inseego Wavemaker™ indoor router FG2000 series delivers blazing-fast internet access to homes and businesses worldwide with breakthrough 5G and 4G LTE speeds. From fast streaming to lag-free video conferencing, the FG2000 series delivers a superb 5G user experience with best-of-network performance anywhere.

The FG2000 series offers support for private networks, including CBRS, and boasts Wi-Fi 6 technology with gigabit-class data speeds with secure connections for up to 128 Wi-Fi devices. An optional RJ11 port provides VoLTE-enabled high-definition voice service. A host of smart security and management features let users connect with confidence in their data privacy and protection.

The FG2000e offers dual SIM support and allows for auto-switching between SIMs based on signal strength, data usage, service availability, and quality. Multi-carrier firmware allows the FG2000e to be used on most major global carriers. The Inseego Mobile app and Inseego Connect™ platform is also available with this device. 

If you have any interest in mobile broadband, fixed wireless access, IIoT (Industrial IoT), Enterprise SaaS, or Edge Computing, look no further than to the specialty products from Inseego.  

Contact our sales team today if you have any questions!

5Gstore Now Sells & Support Digi 4G/5G Routers

5Gstore is excited to announce we are now stocking and shipping new products from award winning Digi. Digi has been a pioneer in the M2M/ IoT market for over 30 years. In this time, their products have adapted to evolving network standards, and optimized data communications around the most advanced protocols and emerging technologies. From radio frequency modems to gateways, cellular routers, and networking devices, Digi’s solutions have continually grown to serve the full breadth of applications across the IoT landscape. New products will include: EX12, EX50, IX10, and IX20. 

EX12

We’d like to highlight the EX12 Cellular extender first. This is great for users wanting a failover solution for their small network (i.e. POS systems, ATMs, Kiosks, etc). The EX12 has a built-in, carrier certified Cat4 LTE modem with redundant SIM slots. This allows for an additional failover with the same or different cellular carrier. Deployments are streamlined with installation accessories including an optional Remote Mounting Kit with a disposable battery pack for site survey, mounting bracket and a passive PoE injector for optimizing placement for the best cellular reception. If needed, a serial port for Out of Band management is also available. 

EX12

EX50

Next, for the power user, we have the EX50, complete with a 5G modem and redundant SIM slots. WiFi support is with the newest, version 6, and Ethernet ports support up to 2.5Gbps. This means users can achieve the full benefits of the cellular bandwidth over wired and wireless connections. Extended temperature range and multiple mounting solutions gives this unit the flexibility to be installed in more industrial environments. 

EX50

IX10

For a more ruggedized and compact solution, check out the IX10. This router offers low-touch and no-touch provisioning and features a Cat4 LTE modem (with redundant SIM slots) along with a RJ-45 serial port supporting both RS-232 and RS-485. Its flexible power and connectivity options make it a versatile choice for industrial, digital signage, ATMs, kiosks and other unattended retail applications that need to provide secure transactions.

IX10

IX20

Similar to the IX10, but larger and more feature packed, we have the IX20 with or without WiFi. This is available with a FirstNet ready modem and is prepared for any application. Its compact size and rugged hardware give any user a simple, yet advanced option for securing their network and providing automatic failover. The router supports advanced security (stateful firewall, MAC filtering and VPN), cellular redundancy (via Digi SureLink®) and management (SNMP, event logging, analyzer trace and QOS), facilitating use in PCI or NERC-CIP compliant applications. 

IX20

Digi Remote Manager

For all Digi products you also have access to Remote Management via Digi Remote Manager. Digi RM is a cloud-based solution that facilitates easy setup, mass configuration, maintenance and support, even for thousands of devices. Digi Remote Manager lets you evaluate, update and configure your Digi enterprise routers and gateways — and the health of your network — at scale, after deployment. Digi RM also provides secure, out-of-band management access to Digi units through serial ports and command-line interface. 

Digi Remote Manager

Digi SureLink

In addition to Digi RM, all of Digi’s cellular products support the Digi SureLink “keep-alive” function. This makes sure the connection will be there when it’s needed. A programmable inactivity timer and a pro-active link integrity function are available. Digi SureLink includes link integrity monitoring, with three test options. 

Digi SureLink

5Gstore is delighted to bring you Digi products and is excited about this new partnership. If you are interested in these products and want to learn more, please reach out to the team at 5Gstore to learn more!

Adding Firewall Rules to Secure Your Peplink

Firewalls establish a security barrier between your devices and the Internet by using rules to allow or deny access in and out of your network. 

In the case of our Peplink routers, the firewall configuration may differ from other routers, but the result is always the same. 

You may want your network locked down from any incoming connections and only allow your personal devices access out to the Internet. Or you might have devices on your network separated in different VLANs. Should you need to allow communication with one of these devices, but deny other connections, set up an Internal network rule to accomplish this. 

For more information, check out our Peplink firewall demo video on YouTube. Have questions? Just reach out to your friends at 5Gstore today!

T-Mobile Certifies the Sierra Wireless XR Series Routers on the 5G Network

Sierra Wireless, a world leading IoT solutions provider, announced today that its AirLink® XR Series cellular routers architected for 5G performance, are certified to operate on T-Mobile’s 5G network – the largest, fastest and most reliable in the United States. This includes the models XR80 and XR90. 

The supercharged AirLink XR90 is purpose-built for public safety and transit with available dual-5G cellular radios and dual independent 4×4 MIMO Wi-Fi 6 antennas. It is the highest performing, most flexible router in the Sierra portfolio. The AirLink XR80 is optimized for fixed and mobile applications. The available dual-5G cellular radio and 5X4 MIMO Wi-Fi 6 delivers flexibility for customized configurations. 

These solutions deliver the full performance of 5G across any network (5G, Wi-Fi 6, Ethernet) enabling customers to leverage the higher data speeds and lower latency of 5G, required for real-time video streaming in mission-critical and high performance business-critical environments. Security is designed into the routers with device to cloud security including secure boot, cryptographic keys, and support for WPA-3. Each model can accommodate expansion modules and are purpose-built for rugged environments. 

In addition, both are fully-supported, out-of-the box solutions complete with integrated device management, advanced mobility reporting and 24/7 technical support. AirLink Connection Manager delivers complete VPN security and their AirLink Professional Services maximizes your system performance and customer satisfaction. 

Yet another added benefit to your remote access and out of band management – an embedded LPWA cellular radio, connected through Sierra Wireless Global Connectivity, provides an always-on link to ALMS (AirLink Management System (ALMS), is a cloud-based management platform which includes remote device management and mobility-focused reporting through AirLink Premium). This unique capability ensures the ongoing operational success of these 5G deployments.

“The XR Series is our fastest, most intelligent, flexible, and secure router yet,” said Tom Mueller, Vice President of Product Enterprise Networking, Sierra Wireless. “The XR Series routers are purpose-built for advanced, mission and business-critical 5G applications. With a passively cooled industrial design, future-proof flexibility offering single and dual 5G as well as Wi-Fi 6 radio options, always-on connectivity, rapid response, and strong multi-layered end-to-end security, they boast best-in-class reliability. When you combine this performance with T-Mobile’s industry-leading 5G network , it’s easy to see why you should choose Sierra Wireless to enable your next-generation applications.”

For more information about these products, contact your friends at 5Gstore!

Tech Tip: How to Use VLANs to Secure Your Router Network

IoT devices – such as cameras, smart thermostats & doorbells – can generally be less secure than most network attached devices (i.e. computers, network drives, servers, etc). Still, they require Internet service to operate and allow you remote access for control and monitoring. In effort to better secure these devices from the rest of your network, this is where creating a “VLAN” can help. This stands for “Virtual Local Area Network.” This is much like creating a Guest WiFi network on your router, so it can be done on just about any router including Sierra Wireless, CradlePoint, Peplink and Digi devices. 

Check out our video on how to create a VLAN for IoT security here

For more videos like this, subscribe to our YouTube channel.

SD-WAN Branch Solutions by Peplink

5G is in our scope! Internet technologies are advancing. Security risks are increasing, along with the number of local and remote connections to manage. Many companies find themselves in a state of urgency to find the best solution, but run into confusion trying to understand what they need and how it will work for them. Not to mention having the adequate support when required. Together with Peplink, 5Gstore can assist your team at every level.

First, familiarize yourself with the terminology. For example…

  • SD-WAN means Software Defined Wide Area Network. This is a virtual Internet connection rather than a physical one coming from the cable or phone company. When you hear about Peplink’s SpeedFusion technology, this would be considered an SD-WAN. SpeedFusion creates one connection from many by establishing a VPN link between 2 or more sites – whether those be physical sites using a Peplink or Pepwave router, or a virtual site like Peplink’s FusionHub or SpeedFusion Cloud service.
  • SaaS stands for Software as a Service. If you’ve used our Remote Power IP Switches, or a security camera such as those from Nest or Amazon, think of the mobile application you use on your phone to access the Switch or Camera. In other words, this is a cloud based application rather than an application you might download onto your computer.
  • Bandwidth Bonding is part of Peplink’s SpeedFusion VPN technology. This can take any WAN connection (Wired, Cellular, or WiFi) and combine the bandwidth speeds, LESS a 19% overhead. For comparison, that’s only about 5% more than the commonly used IPSec VPN. Still, it’s important to note that high latency differences between connections can also affect the overall bonded speeds. Working with our Peplink certified sales and support engineers, we can help provide insight on factors to consider and configurations that could help combat the issues individual WAN connections may be experiencing.
  • Load Balancing, in comparison to bonding, still can utilize all your WAN connections simultaneously. However, it does not combine them together. Instead, it allows devices and types of applications/ traffic to be sent over a specific WAN connection or multiple. If your individual WAN connections are fast and stable enough for certain connections, this could save on cost.
  • Failover and the different types of failover is a good transition here as with load balancing, you do not have session persistence like you would with SpeedFusion Hot Failover. This feature can be used alongside bonding since it’s essentially the base for the other SpeedFusion features (i.e. WAN Smoothing and Bonding).

With all this in mind, even if your company only has a few users, it’s possible your bandwidth and/ or network availability needs will continue to grow with the industry. If you don’t grow with it, your legacy setup could compromise business. This doesn’t have quite as much to do with bandwidth (LTE is still more than enough for some), but more so with security, as hackers continue to find new ways into our devices.

We’ve listed some popular branch solutions as example hardware solutions for your reference below. When needed, contact the experts at 5Gstore and we’ll help guide you through the rest of the process!

Balance SDX

  • Deploy at headquarter or datacenter
  • SpeedFusion VPN provides reliable and fast access to the network resources
  • Modular design offers flexible choices of interchangeable connection interfaces, upgradeable to 5G

MAX HD4 MBX

  • Wireless SD-WAN router with up to 4 bonded LTE connections ensures high performance and 100% uptime in remote branches
  • Access corporate network resources with SpeedFusion VPN in minutes, rather than weeks with wired line

MAX HD2

  • Wireless SD-WAN router with 2 bonded LTE connections for smaller mobile branches
  • Access corporate network resources with SpeedFusion VPN in minutes

MAX Transit Duo

  • Lightweight wireless SD-WAN router with 2 LTE slots for unbreakable connectivity to HQ resources
  • Great for pop-up site or “office in a box” type setup
  • Affordable, easily scalable and manage