Bizarre connection issue with Xfinity

Smalljob

n3wb
Joined
Aug 25, 2019
Messages
12
Reaction score
3
Location
Massachusetts
I had been using port forwarding to my BI server. I know that is not smart, but just setting the stage. Forcing me to to more homework on VPN... But that aside here is the story.

Last night while out at dinner I was receiving a few notifications from my cameras. Nothing to be concerned about as I have a lot of animals around. However when I tried to use my mobile AP ( iPhone) to take a look I could not access my server. Been running fine for 4-6 weeks. When I got home, I tried from the LAN and it worked. Then I noticed that I had some alerts from Xfinity telling me that they had blocked several intrusions from sites outside the United States. It was late so I just went into my Xfinity Gateway and deleted the port forwarding. So no port forwarding. In theory no access from the internet. I am running Norton Internet Security on this server.

This morning I got a couple more warning about trying to access one camera in particular. Scratching my head at this point. Went into BI and tried to run the remote access wizard. Got to the end and it said it could not access the internet. I clicked on the link for CANYOUSEEME.ORG. Browser could not access it ????? I tried to go to blueirissoftware.com .... could not get there either. I tried 1/2 a dozen other sites not related to this subject and they all worked fine.

I went to another computer, a MAC and same thing could not access those two sites. Tried another Windows machine same symptom. I had Xfinity reset my gateway and for an instant I could access those two sites, but on second refresh of both sites no access.

Used my cellphone with the same results when on my WIFI. I disabled my WIFI and had no problem accessing both sites over cellular.

Spent two hours arguing with Xfinity as they kept telling me that I needed to contact both owners of those sites and have them fix it. Finally got to level 3 and they had me send them a trace. While I was on with them I had a thought and enabled a client VPN service that runs on my MAC ( had not been running with the failures) With the VPN client running I can access both sites. Same thing on all three desktops. Good with VPN client enabled and no good with it disabled. Of course these clients don't do me any good for accessing my BI server remotely. I also sent them the trace with the VPN client running showing how it works.

I have not done a hardware reset of the router yet.

Thoughts?

Is the Xfinity Gateway corrupted or is my WAN IP corrupted somehow? My WAN IP which is dynamic has not changed since I set this environment up.

Waiting to hear back from Xfinity Level 3

Bill
 

SouthernYankee

IPCT Contributor
Joined
Feb 15, 2018
Messages
5,170
Reaction score
5,320
Location
Houston Tx
Xfinity level 3 may never call you back. I have has open issues with xfinity and never got a call back. I called the with the ticket number and they informed me the tickets were closed. There support is pure crap.

I use my own xfinity capable modem in bypass / passthru mode. And use a ASUS router.

When in doubt reboot the router, Power it down for at least 1 minute, then power back up.

I have had usage issues and billing problems with xfinity for a while I powered down the modem at night and powered it up an hour before I get up. This also sometimes changes my internet IP address.
 

Culhane

n3wb
Joined
Mar 26, 2019
Messages
1
Reaction score
1
Location
Atlanta
I've never had a problem with xfinity, though it's very odd that they're blocking your internet traffic. I'd recommend buying your own xfinity compatible modem -- I have an Arris T25 Modem. And then you can use any wifi router that you wish, and port forward that way.
 

Smalljob

n3wb
Joined
Aug 25, 2019
Messages
12
Reaction score
3
Location
Massachusetts
SouthernYankee, can I ask which ASUS router you are using. It seems they have a large selection to choose from
 

SouthernYankee

IPCT Contributor
Joined
Feb 15, 2018
Messages
5,170
Reaction score
5,320
Location
Houston Tx
i have an older one. Asus RT-AC66U B1. It does the job for me.
I use the xfinity Modem router (from ebay) in passthu bypass mode Arris TG1682G. If getting your own modem you must use one that is recommended by xfinity, Also your speed may require a different modem.
 
Joined
Apr 26, 2016
Messages
1,090
Reaction score
852
Location
Colorado
Sounds like a DNS server issue (normally provided by your provider when your router registers). On ASUS routers check your WAN configuration, you can also test by manually configuring Google DNS on a computer to see if the problem disappears, which just confirms that you probably need to reset your cable modem.
 

Smalljob

n3wb
Joined
Aug 25, 2019
Messages
12
Reaction score
3
Location
Massachusetts
Still nothing from Xfinity. I called and they said no one had looked at it yet so I decided to do a hardware reset of the gateway. That seems to have fixed the problem. My WAN and DNS stayed the same so I guess somehow something got messed up in the hardware. What is strange if I did a restart of the gateway I could get to those sites once, but any subsequent visit I would get the cannot connect to the server message. Since the reset I have tried several times without a problem and I can also complete the remote wizard in BI successfully. Guess I will never know why.
 
Joined
Apr 26, 2016
Messages
1,090
Reaction score
852
Location
Colorado
Still nothing from Xfinity. I called and they said no one had looked at it yet so I decided to do a hardware reset of the gateway. That seems to have fixed the problem.
In my extensive experience with all internet providers, being able to troubleshoot and fix your problems yourself will save you a lot of headaches.
 

Robocop

n3wb
Joined
Sep 7, 2019
Messages
7
Reaction score
4
Location
US
I am glad a came across this thread as I am in the same boat with my Xfinity.

Mine works fine when my cellphone is on the WiFi network but when I turn WiFi off on my phone and run off my cellular connection I can access the BI app it will log in and by the time I click on a camera (which is usually instantaneous) the loading with the circle will show and it hangs.

Then like clockwork I will get a alert from my Xfinity app saying that an outside IP was blocked. I then go into my Xfinity app and it gives a little summary of what happened and why it blocked said IP address.

After logging into the Xfinity supplied router I found that there is a few levels of security you can pick from.

On a side note this did not happen until recently when Xfinity started touting they've upgraded their security with their service. Once that took place is when I started getting blocked and having issues remotely accessing blue Iris.

Went inside the interface of my Xfinity supplied router there's none, medium and high as far as levels to choose from for security. My router was set to medium. Within these three levels it tells you what it blocks and what it allows.

I'm completely fine with the extra security the issue I'm running into is every time I access, or try to access for that matter, blue Iris with my phone from cellular service it always creates a new IP address for my phone and on the cellular side.

So even if I went into my Xfinity app allowed the blocked connection through if I used my phone again on cellular service to try to access blue Iris remotely, AT&T, which is my service provider, gives my phone a new IP address to which my router blocks the incoming connection attempt as it is a new IP.

So Smalljob it sounds like we're in the same boat just on opposite ends lol.

Perhaps we will be able to help each other and iron out our issues.





Sent from my SM-G965U using Tapatalk
 

Smalljob

n3wb
Joined
Aug 25, 2019
Messages
12
Reaction score
3
Location
Massachusetts
My issue was resolved with a hardware reset of the modem/router. I never heard back from xfinity support.
 
Top