I have tried to put in place openvpn at distance
On that school that i have put nethserver
I have forward 1194 in the firewall swisscom and nethserver on port fowarding and also the allowance on the firewall as like the nethserver example at home (and at home works flowless), at the scool timeup trying to connect with an noipdns that responds into the swisscom public ip address. I put that ddns onto the openvpn configuration, the same options routed one, push network adresses etc and nothing… I have tried to deactivate the fail2ban and ips… And when I try to connect with client openvpn, turns arround and it doesnt connect… On firewall the same configuration… But doesnt connect… Any toughts ? Firewall isp deactivated only nethserver


Are you using the Swisscom Router in “Bridged mode” or in “Router Mode” ?

Bridge Mode should work, your Nethserver has a direct PPPoE conection to Swisscoms vDSL network.

Router Mode often needs a “DMZ host” or “Default Host” set in the Interface.

You can’t always use bridged mode, eg if VoIP is running over the router. In some cases, depending on the models and abos used by Swisscom, even VoiP (Terminating on the Swisscom Router) AND Bridged Mode is possible - I have one such client.

I need to see but I think he’s in routed mode

I will accès in couple of minutes and then I will gove you the answer

Check also, if using Routed mode, that you have your NethServer set as the DMZ Host or Default Host…

On the WAN side you can use DHCP for your NethServer, but fix it (reserved DHCP) on the Swisscom Router… :slight_smile:

dmz not active neither the possibility to put it :face_with_head_bandage:

Does your Router have a default host?

Send a screenshot of the Settings of your Swisscom box…

Nethserver is the only one ip fixed on swisscom dhcp

Heis not in dmz

Could you send a screenshot of the Swisscom router (Routeur et Internet)…


j’ai contacte swisscom and the guy told me that i need to activate the dmz, he will send to me the details about it because he said to me that is diferent from home router, i have described the configuration …

So the modem/router firmware has some not configurable ports that you need to use DMZ?.. hmmzzz :thinking:


This is a swiss “speciality” - we used to say it’s not a bug, it’s a feature… :slight_smile:

Certain swiss providers use custom made modems/routers. Among them: Swisscom / UPC. They have their own Firmware, and if you do not ask, you get only IPv6. If you need IPv4, you’ll get it - but you need to ask!

As I also live in Switzerland (Vitor here in the french speaking part, me in the german speaking part, Switzerland has 4 languages, each with their region), I know most of the hardware available here. And some of their “funky” settings.

Some of these routers allow eg only 8 port forwardings, less than enough to really use your NethServer. With DMZ or Default host, you pass all forward to the DMZ host, which should be stable enough to protect itself (Which a NethServer is!).

Cheap, consumer hardware, some of them really limited!

But workarounds are there for a reason! :slight_smile:

You just need to know the right one!

i think i have found the configuration but to test

i need to put it on Lan port 1 of swisscom centro business, activate the ip passtrough
and put an wan ip address like


1.6 Connexion de l’hôte sur le port LAN 1 et configuration
Fermez maintenant votre hôte (firewall) sur le port LAN 1 du routeur Centro
Business. Configurez la connexion WAN de votre hôte. Saisissez
pour l’adresse IP de l’hôte, pour le sous-réseau et indiquez
comme Gateway l’adresse Effectuez maintenant la configuration
LAN de votre pare-feu

1.6host connection with LAN 1 port and configuration…
close now your host (firewall) on the port LAN1 of the Centro Business router.
Cofigure the conection WAN of your host. Put for host IP Address, for the sub-net mask and put as gateway the address
You can configure now the LAN INTO YOUR FIREWALL…

