change ssl port for webserver

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
dasPaul
DD-WRT Novice


Joined: 28 Nov 2012
Posts: 17
Location: Dresden, Germany

PostPosted: Sat Oct 07, 2017 17:27    Post subject: change ssl port for webserver Reply with quote
Hi there

I have a local webserver that supports https and I want to make it accessible to the WAN. But as I connect to DDWRT via ssl port 443 is already occupied by DDWRT. So I tried to change the DDWRT https default port:

wd_sslport=443
to
wd_sslport=667
then
nvram commit && reboot

Then if I try to open my browser at "https://192.168.1.1:667" I get an "Unable to connect", but connecting to the old "https://192.168.1.1" I can reach still reach the webinterface.

What am I doing wrong?

_________________
Riesige Gepanzerte Luftschiffe
Sponsor
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sat Oct 07, 2017 17:54    Post subject: Reply with quote
That port 443 is in use at the lan interface does not mean it's occupied at the WAN interface. Port forward 443 to your web server. Access it from internet (not your local lan) using the public wan ip address.

I will not recommend making the GUI accessible from the wan.
dasPaul
DD-WRT Novice


Joined: 28 Nov 2012
Posts: 17
Location: Dresden, Germany

PostPosted: Sat Oct 07, 2017 18:26    Post subject: Reply with quote
you're absolutly right and it was not my intention to serve the webinterface to WAN. I did not try to access from outside...

I will reset the sslport via nvram and make an portforward from WAN 443 to LANIP 10443 (my webserver ssl port) and try to connect from outside and not lan. I will report back...

_________________
Riesige Gepanzerte Luftschiffe
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Sat Oct 07, 2017 19:55    Post subject: Reply with quote
http://svn.dd-wrt.com/ticket/5953 isnt helping either
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

dasPaul
DD-WRT Novice


Joined: 28 Nov 2012
Posts: 17
Location: Dresden, Germany

PostPosted: Sun Oct 08, 2017 6:53    Post subject: Reply with quote
it works, from WAN I get the portforwarded webserver with my own certifikate, from LAN the webinterface with ddwrt's certificate.

Thanks!

_________________
Riesige Gepanzerte Luftschiffe
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Oct 08, 2017 7:45    Post subject: Reply with quote
On the lan, use the local private ip address of the web server.

You can have a local dns that resolves the same domain name to the local ip when on lan.

dnsmasq can be used on dd-wrt for this.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum