DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
VPN Matcher - Which UK 4G Providers are known to work?
- Paul
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 9
- Thank yous received: 0
29 May 2025 12:15 - 29 May 2025 13:27 #104969
by Paul
VPN Matcher - Which UK 4G Providers are known to work? was created by Paul
I have a client with a Draytek 2865Lac and I am trying to setup VPN Matcher so I can connect to their router over the LTE connection.
Normally I use Three SIMs at customer sites because they are cost effective way to get a public IP.
Sadlly, this site has poor Three signal so I am investigating other low cost SIM options.
I had both a 1p SIM (EE) and GiffGaff (O2) SIM to hand but neither work, they fail the STUN detection.
"Fail to get IP information from STUN Server, please check your network environment or contact your network administrator."
Has anyone got specific experience of 4G providers that are known to work?
Thanks
Paul R
Normally I use Three SIMs at customer sites because they are cost effective way to get a public IP.
Sadlly, this site has poor Three signal so I am investigating other low cost SIM options.
I had both a 1p SIM (EE) and GiffGaff (O2) SIM to hand but neither work, they fail the STUN detection.
"Fail to get IP information from STUN Server, please check your network environment or contact your network administrator."
Has anyone got specific experience of 4G providers that are known to work?
Thanks
Paul R
Last edit: 29 May 2025 13:27 by Paul.
Please Log in or Create an account to join the conversation.
- m_d
- Offline
- Junior Member
-
Less
More
- Posts: 43
- Thank yous received: 1
29 May 2025 18:43 - 29 May 2025 18:45 #104986
by m_d
Replied by m_d on topic VPN Matcher - Which UK 4G Providers are known to work?
Probably not what you are going for, but do you have a VPN server (Such as another Draytek, a spare physical box, or even a VPS) which you could use for the clients to dial-in to, and then you can access their networks through this? Then you will only have outbound VPN connections occurring over the CGNAT LTE connection, which is usually successful.
Last edit: 29 May 2025 18:45 by m_d.
Please Log in or Create an account to join the conversation.
- Paul
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 9
- Thank yous received: 0
29 May 2025 19:15 #104987
by Paul
Replied by Paul on topic VPN Matcher - Which UK 4G Providers are known to work?
I can already VPN in if their VDSL is working, the aim is to be able to connect to their LTE if it is down.
As above, I usually achieve this with a Three SIM but the signal there is not good enough.
I was hoping someone may have had experience of using VPN Matcher with a UK mobile network and CGNAT.
As above, I usually achieve this with a Three SIM but the signal there is not good enough.
I was hoping someone may have had experience of using VPN Matcher with a UK mobile network and CGNAT.
Please Log in or Create an account to join the conversation.
- m_d
- Offline
- Junior Member
-
Less
More
- Posts: 43
- Thank yous received: 1
30 May 2025 08:23 #104989
by m_d
Replied by m_d on topic VPN Matcher - Which UK 4G Providers are known to work?
I have never used the VPN Matcher, so can't help you there.
I have had good success with client Draytek's dialing-out over LTE (With CGNAT) to my VPN server, which then of course allows me (also connected to the VPN server network, directly or via a tunnel) to access their equipment. This could be a method you could use?
I have had good success with client Draytek's dialing-out over LTE (With CGNAT) to my VPN server, which then of course allows me (also connected to the VPN server network, directly or via a tunnel) to access their equipment. This could be a method you could use?
Please Log in or Create an account to join the conversation.
- Paul
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 9
- Thank yous received: 0
30 May 2025 11:15 #104990
by Paul
Replied by Paul on topic VPN Matcher - Which UK 4G Providers are known to work?
Hi. Yes I had setup an outbound VPN as a workaround but it isn't ideal as I had to setup a dedicated VLAN for their VPN as I did not want any risk devices on their LAN could access ours! I also don't like having custom solutions for customers, but that is probably my OCD!I have never used the VPN Matcher, so can't help you there.
I have had good success with client Draytek's dialing-out over LTE (With CGNAT) to my VPN server, which then of course allows me (also connected to the VPN server network, directly or via a tunnel) to access their equipment. This could be a method you could use?
Please Log in or Create an account to join the conversation.
- m_d
- Offline
- Junior Member
-
Less
More
- Posts: 43
- Thank yous received: 1
30 May 2025 17:16 #104994
by m_d
If it helps, if you have 1 VLAN for 'customer VPN's' (if you ever have to do this for other customers), I think (although it would be worth double-checking) the firewall will be able to control access between the customers, even if they are on the same VLAN / subnet - this doesn't usually work in a traditional, physical LAN, because devices can communicate on layer 2, but in this case each VPN terminates at the Draytek, so I think you can implement firewall rules.
I have never found a way to limit access from a VPN to the Draytek's web interface itself though, none of the firewall rules seem to work for this. I don't feel it is too much of an issue though, considering many people expose their web interfaces to the whole internet. (I do not recommend!)
Replied by m_d on topic VPN Matcher - Which UK 4G Providers are known to work?
I quite understand that!Hi. Yes I had setup an outbound VPN as a workaround but it isn't ideal as I had to setup a dedicated VLAN for their VPN as I did not want any risk devices on their LAN could access ours! I also don't like having custom solutions for customers, but that is probably my OCD!
If it helps, if you have 1 VLAN for 'customer VPN's' (if you ever have to do this for other customers), I think (although it would be worth double-checking) the firewall will be able to control access between the customers, even if they are on the same VLAN / subnet - this doesn't usually work in a traditional, physical LAN, because devices can communicate on layer 2, but in this case each VPN terminates at the Draytek, so I think you can implement firewall rules.
I have never found a way to limit access from a VPN to the Draytek's web interface itself though, none of the firewall rules seem to work for this. I don't feel it is too much of an issue though, considering many people expose their web interfaces to the whole internet. (I do not recommend!)
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek