NextCloud access from LAN but not from WAN

Dmac9244

Cadet
Joined
Jul 15, 2023
Messages
2
Here's the situation:

I have NextCloud running in TrueNAS Core on its own IP which is reserved on my router. I have a domain which I want to be able to use to connect to Nextcloud remotely. The DNS is set up, ports 80 and 443 are forwarded on my router and I believe I have my NextCloud jail configured to accept traffic from my domain. Because the default certificates are set up for localhost I have a custom certbot updating certificates for my domain using a DNS handshake so browsers don't complain about invalid certificates.

When I try to access NextCloud through the domain from within my LAN I have no issue. I can reach the server as intended. But when I try to access it from anywhere else I get timed out or refused. I am at wit's end trying to figure out why this is happening. When I try to ping my domain all I get are timeouts, but when I nmap my domain ports 80 and 443 are open. DNS seems to be configured properly as my domain resolves properly to my public IP. The ports *are* open on my router. It seems like I shouldn't be having any problems, but my server is absolutely unreachable from outside my own network.

I'm aware that some ISPs block traffic on 80 and 443, could this be the issue? If so, can I switch things over to 8080 and 8443 given the fact I'm not using port 80 to renew my certs? Could NextCloud's default behavior to listen to port 8232 be messing things up though it seems to work as intended inside my LAN? Any help would be appreciated, I'm at the end of my line after hours of researching online and making small changes to various config files.
 

Dmac9244

Cadet
Joined
Jul 15, 2023
Messages
2
*Sigh* after an average night's rest and a moment of clarity I switched the ports on my nginx configs and tried it again. Works totally as intended, just with an ugly :8443 appended to the host. Seems to be that my ISP *does* block 80 and 443 traffic, but I was unaware that they would reflect such traffic back into the LAN.
 
Top