PDA

View Full Version : Using a VPN Service Provider to get around port forwarding issues?



Pages : [1] 2

Trenloe
January 4th, 2014, 08:09
I'm currently travelling overseas and I found it quite annoying that I couldn't access many of my US based websites because they could only be accessed from within the UK - Hulu, sections of Netflix, HBO-GO, etc. so I started looking into VPN solutions to make it look like I was still in the US. It turns out there are many "VPN Service Providers" available that allow you to "appear" as if you're in another country - essentially making you have an IP address in another country by using a VPN from where you are currently to an exit point in said country. This has allowed me to access websites and use apps as if I was in the US.

You may be asking "What does this have to do with Fantasy Grounds?" Well, I discovered that this also allows a GM to get around port forwarding issues without the players having to install software as well. Most people who frequent these boards know that most port forwarding issues can be solved by using a VPN application called Hamachi - which usually works fine, but has limitations such as each person has to install the software to be able to connect, and the free version is limited to 5 users.

Using a VPN service provider results in the players not knowing any different and the players don't have to install any software or do anything differently - FG pick up the IP address of the VPN and uses this to update the alias, so the players just connect to the alias as normal and the VPN service provider provides the "tunnel" directly to the GM PC.

The down side? So far I have only found a subscription bases VPN service provider - costing around $50-$60 per year depending on who you go with. This is where Hamachi is better as it is free for 5 connections (including the GM) I believe.

The up side? This allows you to use FG without having to mess around with port forwarding and also where port forwarding is not possible. For example, I will be running a game later today over a 4G wireless access point (EE in the UK if anyone is interested). This wireless access point has not port forwarding possibilities and so I wouldn't be able to run Fantasy Grounds as normal. But, using a VPN service provider allows me to get an external IP address that tunnels directly to my PC - it is this IP address that FG will use for connections, not need for port forwarding as the VPN provides the direct link. Only the GM has to have the VPN configured.

This would also be useful for GMs running a game from a hotel room over the hotel's WiFi and other similar locations - run a game from Starbucks anyone? :)

I thought people would be interested in this as an option for port forwarding issues/travelling restrictions. I'll let you know how I go when I play later today.

Blacky
January 4th, 2014, 11:38
Hamachi can also mess up your installation, does collect email addresses, and is proprietary (meaning it very well can study everything you do with it, and probably without it, and sell this).

The real number of cases where port forwarding doesn't work is really, really, really low. 99% of the time, reading the manual and setting it up properly solve any issues. Well, except when the internet providing is purposefully hatched and gutted.

Also, VPN does a lot of things besides managing strange port forwarding. It's a good way to clean things up and keep things private, as per your example of public wifi usage. It will for example allow someone to bypass almost any bandwidth throttle or port restriction. Yes it has a cost, and for some that cost is inflated, but resources aren't free. Someone has to pay somewhere. Usually, when something is free, it's because it's not the product but the people using it are.

Note that a VPN isn't very resources hungry. One could partner with a few people, and get a cheap (but good) VPS or dedicated server than set it up for VPN. Yes that demand some basic technical know-how, or following tutorial, and it's not very hard. And it's cheap. One can get a small good dedicated server for 15USD, probably a lot less for a VPS, and it can hold several people at the same time. An unmetered 100Mb/s Celeron is at 10€ per month at OVH for example, 100Mb/s can hold ten people easily. But that would mean having one dedicated IP outgoing, doesn't allow to switch IP to fake a geolocation like a big VPN service offer.

In any cases, all of these solution will add some latency. Probably not the end of the world for FG, but it could show in VOIP. If you tested VOIP with a basic VPN provider on a public wifi, I'm curious to know how that went.

But for that type of situation, this could be a service SmiteWorks do (and sell). A limited VPN service, very easy to use, that include the appropriate FG port forwarding and does not block or throttle anything. Doesn't need to provide a huge bandwith since it's mostly upload capped, a few MB should suffice. The few costs are shared by every customer, and even with honest (read: aggressive) pricing it could make some money for SmiteWorks (assuming they have someone on staff who can manage a server).

damned
January 4th, 2014, 23:16
But for that type of situation, this could be a service SmiteWorks do (and sell). A limited VPN service, very easy to use, that include the appropriate FG port forwarding and does not block or throttle anything. Doesn't need to provide a huge bandwith since it's mostly upload capped, a few MB should suffice. The few costs are shared by every customer, and even with honest (read: aggressive) pricing it could make some money for SmiteWorks (assuming they have someone on staff who can manage a server).

an interesting alternative to this could be a setup where the FG client tunnels its traffic through a hosted server that manages the connections between host and client... eliminating the GM side configurations for people... downside? server down - we're all down... but the GM side configuration is a barrier for some people.

Trenloe
January 4th, 2014, 23:28
I've just finished running a session of my Carrion Crown Pathfinder campaign using a VPN service provider - I had to do this as I am using a 4G wireless hotspot that doesn't have port forwarding.

I worked well - it was completely transparent to the players, they just used the alias as normal to connect.

The one issue I did have was that my VPN IP address changed twice during the session - requiring the players to reconnect. I think that this is more than likely due to my 4G wireless hotspot running on low signal strength (1 bar on the indicator) and that causing the timeout/idle time result that required a re-IP of the connection than with anything to do with the VPN side of things.

So, successful test! :)

Griogre
January 5th, 2014, 19:44
I think Blacky's idea of Smiteworks running a VPN server for a monthly fee is interesting. There's clearly some demand for it both because people don't have access to the router, because they don't want the hassle of setting up a server, or because they travel or sheer convenience. I suspect "aggressive" pricing would be difficult because they would have to have a third party run the server.

Acroyear
January 5th, 2014, 22:25
I would not want Smiteworks running a service like this. Not cost-effective and why would they want to support this!
These services already exist, use 'em.

hawkwind
January 10th, 2014, 15:21
Could you run a game through Tor?

Trenloe
January 10th, 2014, 15:47
Could you run a game through Tor?
I know very little about TOR, from doing a quick internet search - from what I can it is for HTTP communications, I'm not sure if it can do specific ports or protocols other than HTTP. Perhaps someone else might now?!?

Trenloe
January 10th, 2014, 16:00
Looking at the information about TOR here: https://www.torproject.org/about/overview.html.en

In the how it works section it mentions:

Tor only works for TCP streams and can be used by any application with SOCKS support.
This is good - it suggests it would work with Fantasy Grounds.

But the very next paragraph says:

For efficiency, the Tor software uses the same circuit for connections that happen within the same ten minutes or so. Later requests are given a new circuit, to keep people from linking your earlier actions to the new ones.
This could be bad for FG - I don't know how this new circuits every 10 minutes functionality would effect the client-server connection to FG. Would it change the end IP address that the user's were connecting to and hence they'd lose the connection and would have to ask the GM for the new IP address to be able to connect again.

Does the GM even know the end IP address that is being used and so they can give that IP address to the players?

To be honest, it doesn't look promising - I don't think TOR is designed for a server like Fantasy Grounds behind the tunnel.

But, someone who knows more about it might have an idea of a way of making it work.

Trenloe
January 10th, 2014, 16:13
Or, when you mention TOR do you mean the TorVPN provider: https://torvpn.com/information.html

This might well work. Give the free user account a go and see if it does - run the connection test in FG once you're connected to the VPN. The free access only has a 1GB limit, should be more than enough to try it out. Then you'd have to buy additional data quota packages.

Blacky
January 10th, 2014, 17:29
To be honest, it doesn't look promising - I don't think TOR is designed for a server like Fantasy Grounds behind the tunnel.
It's clearly not designed for that. But it still might work, tests needed.

hangarflying
February 16th, 2014, 18:22
FWIW, Hamachi has just done away with its free service.

Trenloe, which VPN service did you use?

Trenloe
February 16th, 2014, 18:35
FWIW, Hamachi has just done away with its free service.

They've done away with LogMeIn Free which is a different product to LogMeIn Hamachi. LogMeIn Free it allowed remote control of desktops. You should still be able to use LogMeIn Hamachi for free (4 connections or less) as I don't believe there have been no changes to this.


Trenloe, which VPN service did you use?
I've used HideMyAss (https://hidemyass.com/) and PureVPN (https://www.purevpn.com/) both of them working well - the prices can change as both of these seem to have varying prices due to occasional special offers, PureVPN is currently available for $50 for 1 year.

damned
February 17th, 2014, 06:19
ive just checked Hamachi and it still looks like the 5 connection (host + 4 players) still looks free: https://secure.logmein.com/products/hamachi/download.aspx

RosenMcStern
February 17th, 2014, 10:24
Yep, hamachi is still free. Moreover, I have successfully run games on Hamachi with more than 4 players by simply using more than one free VPNs. A group of players "sees" the server thru one network, another thru a second network.

Locating a service that does not require the installation of extra software on clients would be a GREAT boon, though.

Griogre
February 17th, 2014, 10:34
Aside from Hamachi, what other free service do you use?

RosenMcStern
February 17th, 2014, 11:40
Sorry, I wasn't clear. I use two different Hamachi VPNs. You cannot have more than 5 members in a single network, but the FG server can be in two networks at the same time. And since the clients need not communicate with one another, this configuration works.

Nickademus
February 17th, 2014, 13:56
That's cheating. I love it!

RosenMcStern
February 17th, 2014, 15:08
It's not cheating. You are not explicitly disallowed to do so. It would not work with other software which relies on peer-to-peer communication and not on client-to-server. Luckily FG is client/server :)

hangarflying
February 17th, 2014, 17:15
Yeah, sorry, when I started getting all the pop ups that said I'd gave to start paying, I assumed it also prevented access for FG.

RosenMcstern: could you please elaborate how you make this work? Does the GM have to install two separate LMI-H, or can he have two networks on one instance?

Nickademus
February 17th, 2014, 17:35
Yes, that information would be a true gem for anyone using Hamachi. Make sure Dulux-Oz sees this so he can include it in his future tutorial about setting up FG on a network.

Did you know Dulux had tutorials (https://www.youtube.com/channel/UC-pNvUFwsrAHTtuQna02FEA/videos?flow=grid&view=1)? Not many people know this. He really needs to learn to advertise more. *smirk*

Trenloe
February 17th, 2014, 18:03
Create 2 networks in 1 installation of Hamachi, give 4 of your players the details (Hamachi network ID (name) and password if you use one) to connect to one and up to another 4 the access details to the second. For example:

https://dl.dropboxusercontent.com/u/39085830/Screenshots/Fantasy%20Grounds/Hamachi%20-%202%20networks.JPG

dulux-oz
February 17th, 2014, 18:10
Did you know Dulux had tutorials (https://www.youtube.com/channel/UC-pNvUFwsrAHTtuQna02FEA/videos?flow=grid&view=1)? Not many people know this. He really needs to learn to advertise more. *smirk*

I will refer you to this post ("https://www.fantasygrounds.com/forums/showthread.php?20010-why-not-more-vtt-gamers-(pathfinder)-want-to-use-fg&p=168244&viewfull=1#post168244) and remind you that I only keep "plugging" them because people keep asking questions which are already answered in them - if people are asking the same questions then it means that they either don't know about the videos, know about the videos and haven't watched them, or are stupid!

As I prefer to believe that people on this board are intelligent, then logically they keep asking the same questions because they DON'T know about the videos, and hence might learn something!

But fine, if board members feel that I'm spamming I'll stop - problem solved!

"Screw you guys, I'm going home!" - Cartman, South Park

And no, I'm not upset, nor do I feel under-appreciated - nor do I want to seen as a "spammer" or a pain-in-the-@rse (especially as I AM a pain-in-the-#rse, just ask my Players) :p

Trenloe
February 17th, 2014, 18:12
damned gives great guidelines on how to setup Hamachi for Fantasy Grounds here: https://www.fantasygrounds.com/forums/showthread.php?20309-GM-Connection-Issues-Tried-Everything-Try-Hamachi

Trenloe
February 17th, 2014, 18:15
... because people keep asking questions which are already answered in them - if people are asking the same questions then it means that they either don't know about the videos, know about the videos and haven't watched them, or are stupid!
It's why so many of my "answers" to questions include links to posts where the question has already been answered or good background info is provided. Most people just don't know where to look for info, but I will admit a small minority seem to not be aware of the "Search" facility... :/

Trenloe
February 17th, 2014, 18:16
And no, I'm not upset, nor do I feel under-appreciated - nor do I want to seen as a "spammer" or a pain-in-the-@rse (especially as I AM a pain-in-the-#rse, just ask my Players) :p
I don't mind the spam - keep doing it. And keep drinking that honey bourbon stuff... :D

Nickademus
February 17th, 2014, 18:25
But fine, if board members feel that I'm spamming I'll stop - problem solved!

"Screw you guys, I'm going home!" - Cartman, South Park

And no, I'm not upset, nor do I feel under-appreciated - nor do I want to seen as a "spammer" or a pain-in-the-@rse (especially as I AM a pain-in-the-#rse, just ask my Players) :p

I'm just teasing you. If I felt the videos weren't worth the spamming I wouldn't join in. And if I had a problem with you or your advertising I wouldn't publicly acknowledge your spamming as I prefer to avoid real conflict.

So spam away. You're making my job easier when I start taking on new players. And this won't be the last time I tag something for future videos (and subsequently spam them myself).

dulux-oz
February 17th, 2014, 18:36
I'm just teasing you. If I felt the videos weren't worth the spamming I wouldn't join in. And if I had a problem with you or your advertising I wouldn't publicly acknowledge your spamming as I prefer to avoid real conflict.

So spam away. You're making my job easier when I start taking on new players. And this won't be the last time I tag something for future videos (and subsequently spam them myself).

Yes, I know - but at the root of every tease, joke, myth, legend, etc, is a grain of truth, and if one person teases me about it then there are others out there who think its true - and as I said, I don't want to be seen as a spammer - I loath spammers, I think they are some of the worst people in the world, only one step above looters, thieves, and lawyers - sorry, that's a slur on lawyers :)

So while I know you're only joking there are others who do think it and who aren't joking - and I don't want to be the one responsible for that.

But, just for you: the link to my Tutorial Videos is in my Sig :p

JeffKnight
October 29th, 2016, 08:28
If you own your own server (or vps) you can use OpenVPN using TAP interfaces (I haven't tried with TUN) as well with iptables like so:

iptables -t nat -A PREROUTING -d x.x.x.x -p tcp --dport 1802 -j DNAT --to-dest z.z.z.z:1802
iptables -t nat -A POSTROUTING -d z.z.z.z -p tcp --dport 1802 -j SNAT --to-source y.y.y.y

where x.x.x.x is a public ip of your server, y.y.y.y is the vpn ip of the server, and z.z.z.z is the vpn ip of where you are running fantasy grounds

Trenloe
October 30th, 2016, 07:23
If you own your own server (or vps) you can use OpenVPN using TAP interfaces (I haven't tried with TUN) as well with iptables like so:

iptables -t nat -A PREROUTING -d x.x.x.x -p tcp --dport 1802 -j DNAT --to-dest z.z.z.z:1802
iptables -t nat -A POSTROUTING -d z.z.z.z -p tcp --dport 1802 -j SNAT --to-source y.y.y.y

where x.x.x.x is a public ip of your server, y.y.y.y is the vpn ip of the server, and z.z.z.z is the vpn ip of where you are running fantasy grounds
Interesting. Can you expand on this please? What additional setup would you need - like what would need to be running/configured on the GM's computer? What else would be needed on the VPS? Where would the VPS be (assuming in some data centre somewhere)?

damned
October 30th, 2016, 16:31
it works similar to the way ive documented
iptables allows you to also listen/forward a port
it would share a lot of common steps - the big difference being this would use a vpn client rather than an ssh client.

Trenloe
October 30th, 2016, 17:04
it would share a lot of common steps - the big difference being this would use a vpn client rather than an ssh client.
Yeah, that's the steps I was trying to get info on (and any other gotchas).

Myrdin Potter
October 30th, 2016, 18:16
I don't currently have an issue at home, but my Asustor NAS is basically a little Debian Linux box and has VPN server and other services as included apps.

I already host teamspeak on it for my game and I may move so I keep track of these options.

I will be staying in hotels in Asia (including China) for the next week, so my tried and true PureVPN with dedicated ip option will be in use again. One day I am going to read through damned's document and see if it is a real option for when I travel.

damned
October 30th, 2016, 22:20
Yeah, that's the steps I was trying to get info on (and any other gotchas).

You need to configure the VPS as a VPN server and then add the iptables entries above.
Then when you vpn in you would get that traffic on tcp1802 redirected to you down the VPN.
I havent tested this but saw lots of info on this when i was setting up my way.

Trenloe
October 30th, 2016, 22:31
You need to configure the VPS as a VPN server and then add the iptables entries above.
Then when you vpn in you would get that traffic on tcp1802 redirected to you down the VPN.
I havent tested this but saw lots of info on this when i was setting up my way.
Yeah, I know the theory - was looking for the actual steps, what to setup, etc.. Similar to the file you did for SSH or, at least, more steps that just "setup a VPN and some ip tables entries".

damned
October 30th, 2016, 23:33
Hey Trenloe - this is a pretty good write up.
https://www.digitalocean.com/community/tutorials/how-to-set-up-an-openvpn-server-on-ubuntu-14-04

JeffKnight
October 31st, 2016, 22:00
Interesting. Can you expand on this please? What additional setup would you need - like what would need to be running/configured on the GM's computer? What else would be needed on the VPS? Where would the VPS be (assuming in some data centre somewhere)?

Root access, of course. OpenVPN server, properly configured (TurnKey Linux has a preconfigured appliance as well as Docker container). OpenVPN client (available from their website). It's pretty easy, and I'd be able to help anyone with config files. And yeah, it needs to run in a datacenter with a public IP. If you really wanted to get technical (like I did), you could buy a domain name and have something like fg.mydomain.com for people to connect to.


it works similar to the way ive documented
iptables allows you to also listen/forward a port
it would share a lot of common steps - the big difference being this would use a vpn client rather than an ssh client.

Yeah, and the difference is mainly speed. TAP interfaces are at least 10x faster than ssh tunnels.

JeffKnight
October 31st, 2016, 22:04
Hey Trenloe - this is a pretty good write up.
https://www.digitalocean.com/community/tutorials/how-to-set-up-an-openvpn-server-on-ubuntu-14-04

Yeah, DigitalOcean is a great company. They have great tutorials for people who don't even buy their droplet VPS (which are pretty good too). If I get time, I can write up a specific tutorial too.

My "backup" server (that I actually pay for - all my other VPS I have from when I worked for another company) is an unmetered VPS through https://afterburst.com/ they are a bit pricier than low-end hosts, but ssd's + unmetered connections are very nice to have.

Gwydion
May 2nd, 2017, 14:32
I thought I'd post my update here instead of the Hamachi thread that I've been posting under. So, I've now tested my PureVPN service with my verizon hotspot as well as my blackberry (yes, go ahead and laugh, a blackberry passport) att hotspot. To set mine up, in the "app settings" of PureVPN, I make sure the selected protocol is "StealthVPN". There are several protocols listed and I tried IKEV (which is the default for my setup), automatic, UDP and TCP and I couldn't get any of the others to work. I use kaspersky antivirus and I had to make sure to change the "public network" for PureVPN to be "trusted network".

Once I log in and launch PureVPN and use United States as the location, I wait until it connects and I see the new ip address at the lower right hand corner of the PureVPN app. Then I launch fantasy grounds and click on "load campaign" and then next to "external" under address information, I click on "click to retrieve". I make sure the external ip address matches the PureVPN ip address and then I click "run test". Success! I've tested on a few networks as I said and it works fine for me. The players just need to connect using the normal table alias. (No need for them to have PureVPN).

So, I've now tried HMA and PureVPN and both seem to work for me. I paid just under $60 for two years of PureVPN ($30/yr) and I did not have to add the static ip address feature although some folks have said they had to add that feature to make it work. I'll keep testing the connection, speed, etc. and post back any other updates I find. Hope this is helpful for you!

Gwydion
May 3rd, 2017, 14:06
Quick update. I asked damned to connect to my table this morning to test things. He was able to connect, but then the VPN dropped (disconnected) on my end and he was disconnected from my table. We tried again and the same thing happened. I'm going to keep testing to see if there is something I'm doing wrong on my end but for now, I'm not certain PureVPN is working for me. HMA still seems fine, though.

damned
May 3rd, 2017, 14:20
its quite possible it the hotspot. they aggregate many, many connections and sometimes thru multiple gateways. you might get routed via a different gateway every few minutes causing the vpn to drop...

Gwydion
May 3rd, 2017, 14:33
its quite possible it the hotspot. they aggregate many, many connections and sometimes thru multiple gateways. you might get routed via a different gateway every few minutes causing the vpn to drop...

Yeah, I think that is it. I also noticed somehow my PureVPN network connection reverted back to "public" in my Kaspersky AV. Might have to check that connection setting each time I connect. I changed it again to "trusted" and then I had GeoQuester connect (from NY) and he got onto my table fine and stayed on for about 5 min before we decided to disconnect. So, I'll keep testing, but I do think it is either the hotspot (signal varying between 2-3 bars as well) or it might have been the Kaspersky setting. It might have disconnected when it saw other traffic on it.

Thanks again for helping me test damned!

Myrdin Potter
May 3rd, 2017, 16:35
It also could be not having a dedicated IP address and someone else connecting to the vpn server could have stepped on the port.

The anti-virus/firewall seems like the best bet, though

Trenloe
May 3rd, 2017, 16:44
It also could be not having a dedicated IP address and someone else connecting to the vpn server could have stepped on the port.
That's not how it works.

Having a dedicated IP address would give you the same VPN IP address every time.

Without a dedicated IP address you are assigned your own VPN IP address dynamically when you connect to the VPN, and will probably get a different one every time. But it is your IP address while you're connected.

Myrdin Potter
May 3rd, 2017, 16:49
Many VPN companies pool IP addresses and have some form of NAT to handle it. PureVPN is the one I use and have recommended it. My experience using it from China was so so without the dedicated IP address and always rocksolid with the dedicated IP option.

Trenloe
May 3rd, 2017, 16:56
Depending on the VPN provider you may need to get an additional service - such as NAT firewall or dedicated IP address. I can't remember who, but another forum member was told by PureVPN that they'd need to purchase the NAT firewall option to allow them to get specific ports through the VPN. But, this isn't something I have needed to do, but that forum member got, I believe, the NAT firewall option for free for a month and it worked for them. So, I think PureVPN has different settings on accounts/VPN locations and you might need to play with VPN settings/location selection to get something that works for you.

Gwydion
May 3rd, 2017, 17:54
Thanks, all. I'm going to keep testing PureVPN while I'm within my 7 day window (as I got the great deal on the 2-yr purchase). If I have problems with it I will probably just add-on the dedicated ip address to see if that fixes it. I'll keep updating here in the event it will help others.

Trenloe
May 3rd, 2017, 18:33
I think that in the end, using a mobile device for your Internet connection will always have the potential for drops - these connections are just not made for hosting servers (which is what the Fantasy Grounds GM application is) and evne under normal operation your IP address on the mobile network can change without warning which causes the VPN to disconnect.

When you reconnect you will more than likely have a different IP address, so the GM has to relaunch FG to register that new IP address with the FG alias server. This is where a dedicated IP address will help - even if you have to reestablish your VPN connection, it should use the same dedicated IP address and so the players might be able to reconnect easily (if it's within the 3 minutes FG retries connections) and the GM shouldn't have to restart their instance of FG.

Gwydion
May 3rd, 2017, 18:46
I think that in the end, using a mobile device for your Internet connection will always have the potential for drops - these connections are just not made for hosting servers (which is what the Fantasy Grounds GM application is) and evne under normal operation your IP address on the mobile network can change without warning which causes the VPN to disconnect.

When you reconnect you will more than likely have a different IP address, so the GM has to relaunch FG to register that new IP address with the FG alias server. This is where a dedicated IP address will help - even if you have to reestablish your VPN connection, it should use the same dedicated IP address and so the players might be able to reconnect easily (if it's within the 3 minutes FG retries connections) and the GM shouldn't have to restart their instance of FG.

Yeah, those are great points. Even adding on another $24/yr ($1.99/mo I think for the dedicated ip), that would still be $54/yr which is worth it for me.

Gwydion
May 4th, 2017, 17:14
Many VPN companies pool IP addresses and have some form of NAT to handle it. PureVPN is the one I use and have recommended it. My experience using it from China was so so without the dedicated IP address and always rocksolid with the dedicated IP option.

I'm reaching out to PureVPN now to see if they will let me test the dedicated IP address for a few days. I tried to connect to my wifi at home last night and use PureVPN and I was able to connect but very quickly the bandwidth was choked off to virtually nothing and then I was disconnected. I went through an FAQ on the PureVPN site and it might be my router firewall or a host of other things that I frankly don't want to mess with as I don't know what I'm doing, but I can follow directions reasonably well....

If I can test the dedicated ip option and that works, I'll probably just pay the extra amount. The minute I start messing with my router firewall is the minute I take down my home internet (again) and my wife and kids will probably not tolerate that a second time. :) Will post back if I get a chance to try the dedicated ip.

Gwydion
May 4th, 2017, 20:33
One more update. So, I went ahead and purchased the dedicated ip address option with PureVPN to check it out. (They made me purchase two years of dedicated ip address since I already purchased a 2yr contract for the base service). I still have until Monday, 5/8 to cancel it all if it doesn't work.

Once I got the dedicated ip email and set it up and connected, everything seemed rock-solid and I could connect using the "automatic" protocol option instead of stealth vpn (which was not an option with the dedicated ip). I had someone connect to fg from an external connection and ran everything from my hotspot and let it run for over two hours without any connection drop. I think I'm going to stay with PureVPN and the dedicated ip address option.

All in I paid $58.56 for the base service and $47.76 for the dedicated ip upgrade all over a two-year period. So, the annual price is $53.16. Not sure how often I will use this, but its worth it to me for the option to run games anywhere and maybe I will use the vpn when I'm traveling just for safer internet surfing!

Finally, I ran some speedtests with and without PureVPN. Without the vpn connected and using my hotspot only I averaged about 9 mbps down and 3.3 mbps up with a 30 ms latency. With the vpn connected I averaged about 11 mbps down and 5 mbps up with a 110 ms latency. Again, I don't consider myself a technical guy by any means, but I don't understand why it would be faster with the vpn connected, but I'm just happy it doesn't seem to degrade at all! The latency I know is 3x longer but I don't see how that should be a huge issue.

Anyway, just wanted to share with others. Feel free to shoot me a note here or via PM if you have questions. I think this project for me is done for now!

Procurator
May 7th, 2017, 06:18
Gwydion, thanks for sharing, I have the same service with options (The 2 year was hard to pass up given my travel schedule). Aside from the "Automatic" selection, do you use a specific "mode", ect for your games. I haven't tried any testing yet as I'm new to FG and the community in large. Was wondering if you had stumbled upon any preferred settings?

Thanks again and thanks to all the tech savvy folks on the thread,


Procurator/Lowly Scribe
ULT Lic Holder
5e DM/Player

LordEntrails
May 7th, 2017, 06:48
Welcome Procurator to the community. Glad to have you with us.

Procurator
May 7th, 2017, 07:28
LordEntrails, thanks, enjoy the program, looking forward to some down time in two weeks to try it out. Great support on these forums, enjoying the community at large.

Gwydion
May 7th, 2017, 13:52
Gwydion, thanks for sharing, I have the same service with options (The 2 year was hard to pass up given my travel schedule). Aside from the "Automatic" selection, do you use a specific "mode", ect for your games. I haven't tried any testing yet as I'm new to FG and the community in large. Was wondering if you had stumbled upon any preferred settings?

Thanks again and thanks to all the tech savvy folks on the thread,


Procurator/Lowly Scribe
ULT Lic Holder
5e DM/Player

Yes, welcome! Once I added the dedicated ip address the automatic option worked fine. I didn't need to change anything. Before I added the dedicated IP address I had to use the stealth vpn mode and nothing else worked for me. Once you add the dedicated iP the stealth vpn option isn't available but the connection has been rock solid since I added the dedicated ip.

Procurator
May 8th, 2017, 16:55
Gwydion,

Thanks.
Update. After about 5 minutes of touring the interface, I set up the dedicated IP, established connection with host, and set to "automatic". The connection over the past 48 hours has been rock solid. I've tested it back home and on the road now over hotel internet; working well under both conditions.

To the community, if you have the means of establishing a subscription with a dedicated IP option (the current 2 year sale sold me); and have use for a VPN for travel and gaming, PureVPN seems very accommodating.

Therefore, I humbly second your PureVPN recommendation.

Trenloe
May 8th, 2017, 17:01
Good news and thanks on reporting findings Gwydion and Procurator.

I must admit I've had few issues with PureVPN and I've been using it for over 3 years.

For those who've looked at HMA (Hide My ***), which has worked in the past, I received an email from them last Friday regarding their new "Service Improvement Programme". On thing they are doing is: "We have also taken the decision to move from having dedicated IPs (one VPN session behind one IP address) to shared IPs (many users behind one IP address). This change will strengthen your privacy by making it harder for anyone to track even your VPN IP."

This obviously has issues with use of Fantasy Grounds, so HMA may cease to be a viable option in the near future. I'll report back on any issues I find once that has rolled out.

Gwydion
May 8th, 2017, 17:13
Gwydion,

Thanks.
Update. After about 5 minutes of touring the interface, I set up the dedicated IP, established connection with host, and set to "automatic". The connection over the past 48 hours has been rock solid. I've tested it back home and on the road now over hotel internet; working well under both conditions.

To the community, if you have the means of establishing a subscription with a dedicated IP option (the current 2 year sale sold me); and have use for a VPN for travel and gaming, PureVPN seems very accommodating.

Therefore, I humbly second your PureVPN recommendation.

Excellent! So glad it is working for you as well.

IrishBouzouki
May 8th, 2017, 23:28
For those who've looked at HMA (Hide My ***), which has worked in the past, I received an email from them last Friday regarding their new "Service Improvement Programme". On thing they are doing is: "We have also taken the decision to move from having dedicated IPs (one VPN session behind one IP address) to shared IPs (many users behind one IP address). This change will strengthen your privacy by making it harder for anyone to track even your VPN IP."
This obviously has issues with use of Fantasy Grounds, so HMA may cease to be a viable option in the near future. I'll report back on any issues I find once that has rolled out.Well, HMA is what I used again recently, with come-and-go speed Verizon LTE. I've already noticed recently the FG connection test will work on one HMA location and not on others. I've already dropped my renewal for HMA anyhow and am looking for something else I can use like that which does not require anything different from incoming FG client connections. So I will be looking for a VPN recommendation if / when HMA stops working anymore. THe VPS idea looked kind of interesting given my situation with LTE, but I have to admit it seems technically daunting for me.

Trenloe
May 8th, 2017, 23:49
So I will be looking for a VPN recommendation if / when HMA stops working anymore.
The posts and discussions on the last couple of pages suggest PureVPN with a dedicated IP address is a reliable solution.

Myrdin Potter
May 9th, 2017, 00:05
I have been using PureVPN as my go to travel VPN (inside China and at places in the USA as well). I have always used the dedicated IP option and it has worked for me.

The advantage to a VPN is that only the game master (host) needs to do anything. Hamachi is free but everyone needs to use it.

Procurator
May 9th, 2017, 15:29
Feel a bit silly for asking this, but for clarification, with a dedicated IP and PureVPN, if I use the (can I use the?) alias generator to provide the players with the necessary log in information, will that alias continue to work for follow on game sessions. I just ask as I was surfing the calendar and noticed server side information posted for future/current games?

Let's clarify my question, with a static IP, is the same alias generated phrase useable between sessions?

Appreciate the time, the learning curve is approaching inflection :) Thanks again!

Myrdin Potter
May 9th, 2017, 15:32
It works for me since the IP address never changes.

Trenloe
May 9th, 2017, 15:44
The alias would work even if your VPN IP address changed (as long as you start FG after the VPN connection so FG can read your VPN IP address). FG registers the alias -> IP address data with a Smiteworks server when the GM starts the campaign.
This is the main reason for the alias functionality - to provide your players with the connection info once (the alias) and they use the alias to connect, no matter if the public IP address of the GM has changed. So you can use the same alias if you're the GM on the VPN, off the VPN, at your friends house, etc., etc..

Procurator
May 9th, 2017, 16:10
As usual, thanks for the quick reply! Clears a bit of the fog up.

seiya5
August 6th, 2017, 06:37
Is it possible for some one to direct me to a step tutorial on how to connect FG through VPN? I just bought a lifetime subs from hotspotshield and would like to see if it even works.
I have typed external address which matches the one from the VPN, however the test still fails.
Thanks for all your help!

Myrdin Potter
August 6th, 2017, 06:46
Typically you need a private IP or sole form of NAT direction so you can open port 1802.

seiya5
August 6th, 2017, 07:40
Do you mean to say not any VPN provider would work bc the ip is not static? I am not sure what you mean.

Myrdin Potter
August 6th, 2017, 08:45
I use PureVPN with a dedicated IP and it works perfectly and all I have to do it turn the vpn on.

Many VPN services share an IP address and do not open Thebport you need.

seiya5
August 6th, 2017, 08:51
I use PureVPN with a dedicated IP and it works perfectly and all I have to do it turn the vpn on.

Many VPN services share an IP address and do not open Thebport you need.

Yes this seems to be the case for me. I'm getting a refund and checking purevpn out. Another you would recommend?

Myrdin Potter
August 6th, 2017, 16:20
Most VPN do not work with their standard package, you need to upgraded to a dedicated IP and even then you need to make sure he port control works.

Once I found PureVPN I did not look further. I use it in hotels and it works well, even in China.

seiya5
August 6th, 2017, 16:26
So I'm looking at a two year plan. Where do I find the dedicated IP additional plan in purevpn?

Trenloe
August 6th, 2017, 16:54
Where do I find the dedicated IP additional plan in purevpn?
It's available under "Add-ons (Optional)" once you click on a payment method.

seiya5
August 6th, 2017, 19:39
Ok so I got the dedicated VPN sign in to the shortcut program. I have made sure that under the windows firewall PureVPN is under allowed APPS both as private and public.
Now I am at the dedicated IP have selected Automatic Protocol. Now what?

Currently I am using windows 10. When I click on the wifi shortcut at the bottom left at the very top it has connect to VPN but it wont log on.
I tried looking up videos and info on their site but can't find what Im doing wrong.

Myrdin Potter
August 6th, 2017, 19:42
You cannot sign on for PureVPN? You will have to follow their instructions on that. You need to use the dedicated ip sign on. Usually all the information is in an email they send to you.

Once vpn is on, you start up Fantasy Grounds and then run the normal connection test. Are you very familiar with FG?

seiya5
August 6th, 2017, 19:44
To be honest I am not familiar with FG but I think i can get it. I simply have to click on external and run the test at that point.
While I do have my dedicated ip, they did not send info on how to use it :S

Myrdin Potter
August 6th, 2017, 19:47
It has been ages since I got my initial signin for PureVPN. I just choose it in the menu of choices in the PureVPN software. Once I am connected and the VPN is active, FG just works, connection test is successful.

PureVPN has active, online support. You can chase them there if you are havin issues with it.

seiya5
August 6th, 2017, 20:10
Ok, I got to get the VPN to work and connect successfully.
On FG the internal ip is the one associated with the vpn dedicated ip. When I run the test however there is a failure. What could be causing this issue?
I honestly felt more comfortable working with the vpn than actual FG as I have no clue where to go from here now.

Myrdin Potter
August 6th, 2017, 20:12
Are you sure you are connected to the dedicated ip? Can you do a screenshot of that and post it here?

seiya5
August 6th, 2017, 20:24
20069

Is it possible that I have to change other settings in purevpn to have this work?

Trenloe
August 6th, 2017, 20:35
Make sure that you start Fantasy Grounds after the VPN has been fully connected and assigned your IP address. Then click External "click to retrieve" entry and check that this matches your VPN IP address.

Gwydion
August 6th, 2017, 20:37
20069

Is it possible that I have to change other settings in purevpn to have this work?
I
Don't want to butt in here as I know Myrdin Potter has you covered but wanted to add one thought. I use PureVPN as well with dedicated ip address and it works well for me. I know you say you allowed PureVPN as a rule in your windows firewall and I apologize if I missed this, but have you made sure there is a rule in your antivirus software as well? If memory serves I had to do that first. i just checked my antivirus and I definitely have a rule set up to allow PureVPN. Hoping that is it!

Myrdin Potter
August 6th, 2017, 20:49
Is the external IP address in FG the same as the VPN?

seiya5
August 6th, 2017, 20:56
So I have quit Steam > connected to purevpn > connect steam > FG > FG test (without pressing external as internal matched vpn) = failure > press exteranal (ip doubled top and bot) = failure

I am currently using Kaspersky antivirus and malwarebyte. I was unaware that I had to tell Kaspersky to allow pure anything.
Also under windows firewall should I leave it checked both as public and private or just public?

Gwydion
August 6th, 2017, 21:01
So I have quit Steam > connected to purevpn > connect steam > FG > FG test (without pressing external as internal matched vpn) = failure > press exteranal (ip doubled top and bot) = failure

I am currently using Kaspersky antivirus and malwarebyte. I was unaware that I had to tell Kaspersky to allow pure anything.
Also under windows firewall should I leave it checked both as public and private or just public?

I don't recall if the rule was setup automatically or if I did it. I have kaspersky as well and when I look under the applications I have a rule allowing pure vpn.

Myrdin Potter
August 6th, 2017, 21:04
What is the protocol that you use to connect the VPN? I used PPTP.

I know that I have seen some posts saying "public" for the network setting can cause issues.

My internal and external IP addresses are different as well. Internal is the router IP address. External is the VPN.

20070

seiya5
August 6th, 2017, 21:15
Is there anyway someone can show me their settings for the manage exclusions or specific trusted application under threat and exclusion menu?
I found this so far but dont know what to deselect or select.

Myrdin Potter
August 6th, 2017, 21:22
I assume that you have FG set as a trusted application and you allow it to see the internet?

You can run updates when the vpn is on and connect to this forum fine when the vpn is on?

seiya5
August 6th, 2017, 21:28
I was using IKEV. I will uncheck the public option from it and try.
Also under the firewall there are Fantasy grounds with pub and priv checked, and fantasygrounds with public checked.
Its wierd to me that both the internal and external were the same, and both are the dedicated ip

I can run updates and connected to this forum when vpn is on.

Myrdin Potter
August 6th, 2017, 21:39
Try PPTP as the protocol.

I am not sure what "public" and "private" means in the context of the setting you are using. I am wondering mostly about why FG has the VPN address for internal and external as that is not what I see at home (where I am now) or when I travel. I use norton and did. It have to make any special settings. My laptop is windows 7.

seiya5
August 6th, 2017, 21:49
I agree that the internal and external being the same is weird. I dont know what do about that specifically. Currently Im uninstalling Kaspersky and seeing if that fixes the problem. If that doesn't work I'll go back and uninstall FG and erase all those windows firewall rules.

Myrdin Potter
August 6th, 2017, 22:04
Did you try PPTP protocol for the vpn?

seiya5
August 6th, 2017, 22:22
Currently I have installed Kaspersky FG and purevpn. delete it all firewall exceptions and reinstalled both FG and purevpn. It's still showed both internal and external as the same IP.

I have also tried just connecting as pptp and still get a failure to connect.

I highly doubt that Malwarebytes would do anything to restrict either FG or purevpn.

And I thought this would be the easy route.

Bidmaron
August 6th, 2017, 22:28
Have you disabled windows firewall? Worth a try

Myrdin Potter
August 6th, 2017, 22:30
I have not heard of anyone having so many issues with this, and I have no idea why internal and external IP address is the same.

If you check internal and external IP address without the vpn on, they are different?

How are you connecting to the internet?

seiya5
August 7th, 2017, 00:32
so what I discovered by turning off windows firewall is that FG will work and connect. The sucky thing is that I haven't a clue what do change in the rules to be able to have it work. Any one else using windowns firewall and not 3rd party?

Myrdin Potter
August 7th, 2017, 00:41
Doesn't your anti-virus program also have a firewall? You may have 2 firewalls competing with each other.

seiya5
August 7th, 2017, 00:46
So I figured it was an issue with windows firewall on both FG and PureVPN after reinstalling turning the wall off and on it gave me the option to have more access on private and public networks.

HOLY CRAP THANK YOU GUYS! This is such a fantastic community!

Myrdin Potter
August 7th, 2017, 04:07
I am very glad this worked out. Sorry you had such a struggle with the firewall. I was an early believer in PureVPN and was worried that so,etching had changed with it. Glad you are connected and can host games again.

seiya5
August 7th, 2017, 04:16
I am very glad this worked out. Sorry you had such a struggle with the firewall. I was an early believer in PureVPN and was worried that so,etching had changed with it. Glad you are connected and can host games again.

How did you know brother don't worry about it it's actually probably a problem on my end the service is great!

Bidmaron
August 7th, 2017, 04:33
We are all just pleased you have it working now. This is a great program and community.

adamyaz
August 16th, 2017, 12:09
I am curious about this solution in regards to getting around port forwarding isues when on public wifi connections. This can bypass port fwding problems? Is there any additiona setup required or does this happen automatically when logging in to FG when using a VPN?

Also, from what I see, these are much cheaper now. Any companies you reccomend?

Thanks!

Trenloe
August 16th, 2017, 14:04
I am curious about this solution in regards to getting around port forwarding isues when on public wifi connections. This can bypass port fwding problems? Is there any additiona setup required or does this happen automatically when logging in to FG when using a VPN?
If you get the right VPN provider (see below) then yes, issues of Port Forwarding on your local network connection are bypassed and move to the VPN provider side. Simply start your VPN connection before starting Fantasy Grounds, so that FG can read the VPN IP address. Then your players connect with the FG alias as usual, the players don't need any additional software or setup.


Also, from what I see, these are much cheaper now. Any companies you reccomend?
PureVPN with a static IP address add-on is known to work well. You don't need to do any additional setup.

adamyaz
August 16th, 2017, 14:20
So as I understand it, as a player only you do not need port fwding open? Only if your hosting?
I am asking to see if I can connect to a game on a public wifi while travelling VS my personal router at my house. Thanks!

Trenloe
August 16th, 2017, 14:22
So as I understand it, as a player only you do not need port fwding open? Only if your hosting?
Correct.

seiya5
August 16th, 2017, 14:23
So as I understand it, as a player only you do not need port fwding open? Only if your hosting?
I am asking to see if I can connect to a game on a public wifi while travelling VS my personal router at my house. Thanks!

That is correct. You only need to forward the port if you are hosting.

IrishBouzouki
August 21st, 2017, 09:27
I have had HMA since early 2016. It used to work. Sometime Spring 2017 it quit working for me.
I got a new Win10 desktop PC in February 2017, but I ran at least a couple of the new PF Kingmaker sessions on this since then and it worked okay, actually considerably better than my old Win7 laptop PC there were no complaints from the players.
But now I fail the connection test and indeed players can not log on to my table in FG.
I'm paying HMA $79us/yr and FG is the only reason I have it. Together with my Ultimate FG lic. And I have hosted about 5 sessions since buying FG ultimate in 2014 and starting HMA in Feb 2016. The HMA sub doesn't run out until Feb 2018. Which is just added aggravation.
A while back in the Spring 2017 I saw somewhere here that HMA was making a change that would prevent it working. Since this happened around when it quit on me I figured it was HMA. But apparently people are still having success with HMA?
I have HMA set for OpenVPN (it also fails with PPTP which is the only other option) and I have tried with a couple location near me in the USA Eastern time zone.
HMA is set for direct connection (no proxy), secure IP bind is disabled, IP address changes are not enabled, load balancing is not enabled
In my windows firewall I have 2 incoming rules enabled related to this... one for TCP port 1802 and one I just added for UDP port 1802
Those are set to allow edge/NAT traversal, restricted to the Fantasy Grounds exe application (also tried without that restriction no difference), allow across all domains and interface types
My ISP is Verizon over an LTE link to a little black box, it uses NAT traversal and dynamic IP with no option to change that or configure port forwarding etc, so the VPN is my way to tunnel thru that.
I run Cat-something Ethernet straight from my PC to said little black box. No WiFi for this.
The Win10 firewall is also set to notify me when an incoming connection is blocked, and I receive no such notifications during the connection test (or any time)
I would think this is a pretty solid indication that the problem is with the VPN, but I am not sure of that
When I click FG retrieve address it does retrieve the correct address shown in HMA. Just the connection test fails.

I'd like to run a bunch of FG games.
Has someone already figured out that HMA no longer works for FG hosting? Or has Verizon just gotten better at foiling its customers attempts to use their network for anything more than email and web browsing?
Any idea what to try to get this to work?

Trenloe
August 21st, 2017, 10:36
HMA will no longer work as they have gone to shared IP addresses. I haven't heard anyone say that they have got it to work and my setup that was working is no longer working.

PureVPN is what people have been using successfully recently.

I'd recommend contacting HMA and asking for a refund of your remaining subscription.

IrishBouzouki
August 21st, 2017, 13:34
What if you do not want to use PureVPN... Does Hamachi still work as of August 2017? Or are there alternatives to PureVPN that are known to work?

LordEntrails
August 21st, 2017, 14:25
Hamachi works, but it requires your players to also use it.

Any VPN that has a dedicated IPv4 and allows port forwarding should work. But I don't recall reports other than PureVPN that people have actually used.

There are instructions around here somewhere on how to lease/rent a personal server and configure a VPN on it. The cost if you find a coupon code can be very enticing if you don't mind installing things yourself.

IrishBouzouki
August 21st, 2017, 14:50
Anyone have a link to the VPS tutorial / instructions?

I will be happy to give that a try, even spend some cash on it, but the issue may be that I am behind NAT and dynamic IP on Verizon LTE so the server has to be a rented server that I can somehow manage to access over Verizon LTE and still make it work.

daina
September 12th, 2017, 08:44
Port forwarding can sometimes be a rather big pain in the butt. Using VPN might be a good solution on this occasion. For it, you have to follow various things as like When testing your port forwarding to your computer make sure to use a good VPN. Such as FrootVPN (https://itday.com/vpn/frootvpn-review-one-of-best-rated-vpns/), NordVPN, IPVANISH, SEFERVPN, ExpressVPN. Because those are very renown VPN at present time. By using these VPNs you can easily figure out you matter. I make a list that of mistakes those we used to do on Port forwarding,

> Wrong IP address in the port forwarding rule.
> Firewall settings in the router.
> Firewalls in Windows, Linux & Mac
>Corrupted/Broken Windows Firewall
> Wrong Connection Type Setting
Always ignore these types of mistakes by using a good VPN service provider it is very easy to do Port forwarding.

Govanon
September 24th, 2017, 02:21
Which VPN service is best to use with FS? My PureVPN is not working properly... Now the external and internal ip number is always the same, no matter what type and connection I choose.
For the record, i'm trying connect from Brazil.

Myrdin Potter
September 24th, 2017, 02:24
I assume you are using the private IP service? And that you contacted PureVPN customer service to ask if they have an issue as they had one in the USA a few weeks ago.

damned
September 24th, 2017, 05:36
IrishBouzouki are you taking about the VPN instructions I created?
https://www.dropbox.com/s/i1mxkdubn8kt46k/Fantasy%20Grounds%20VPN%20Server%20Setup%20-%20draft.docx?dl=0

Trenloe
September 24th, 2017, 05:39
WNow the external and internal ip number is always the same, no matter what type and connection I choose.
Close Fantasy Grounds completely before you connect the VPN. Wait until the PureVPN client registers and IP address and then start Fantasy Grounds - this makes sure it uses the PureVPN IP address for alias connectivity and the connection test.

YAKO SOMEDAKY
September 24th, 2017, 06:29
I've seen a lot of people having trouble logging in to their matches, some people manage to free up port 1802, some are not so lucky and resort to a VPN, but the question is the following with the coming of Fantasy Grounds Unity these problems connection will heal ... or will we still have problems with port 1802?
Would better communication be possible if IPV6 was used instead of IPV4?

damned
September 24th, 2017, 06:31
IPv6 wont change how ports work. It will help those users who have shared IPv4 (mostly Euro but some other places too)...
The Devs are looking at having a brokered option which will solve the 1802/port-forward issue for those that want to use it...
Note this is hearsay and not to be taken as gospel until/unless you see it in action...

YAKO SOMEDAKY
September 24th, 2017, 06:54
Damned I play with Govanon and until about 15 days ago we could play using PureVPN, because the Internet Provider he uses does not release port 1802, but after Fantasy Grounds was upgraded to 3.3.2 we could not get any more connect to the game that Master, because the internal and extensive IP addresses are the same and should be different, since it could pass the external ip generated by PureVPN or Alias and played normally, I would like to know if there is any solution for this kind of problem?

Moon Wizard
September 24th, 2017, 08:01
None of the networking code was changed in v3.3.2, so not sure why it would have changed behavior. Perhaps security software is blocking network access, since the executable was updated?

Regards,
JPG

damned
September 24th, 2017, 10:01
Close FG. Disconnect from VPN. Connect to VPN and wait 2 mins and then load VPN and see if you get the expected IPs.

Bidmaron
September 24th, 2017, 14:19
IPv6 wont change how ports work. It will help those users who have shared IPv4 (mostly Euro but some other places too)...
The Devs are looking at having a brokered option which will solve the 1802/port-forward issue for those that want to use it...
Note this is hearsay and not to be taken as gospel until/unless you see it in action...

What is a brokered solution?

Myrdin Potter
September 24th, 2017, 18:03
For PureVPN, some people were able to use it without buying the private IP option. That seemed to be very server and usage dependent.

You really need the private IP option to be assured it will work.

If you do as suggested here and make sure that you get two IP addresses being reported inside FG, then there might be an issue at the server level for pureVPN and they may need to sort it out. There was a thread about 2 weeks ago about USA servers and the hurricane that hit Houston caused them to need to rebalance and redo some server settings. It is possible that the hurricanes rolling through the Caribbean Islands and Florida may have effected something.

One other possibility - the update may have convinced your anti-virus software or firewall that Fantasy Grounds is a new program and it may be being blocked from connecting to the VPN. Usually that shows up with both internal and external IP addresses being the same.

Finally, if all the IP addresses and everything else works, there is a small potential that the IP range used by PureVPN may have been blocked for spam or other issues by the outside service used by Smiteworks. If you can access the website with the vpn on, that is not as likely, but always possible.

YAKO SOMEDAKY
September 25th, 2017, 01:02
I have a friend who is increasingly frustrated to be able to master in Fantasy Grounds what was to be a leisure is becoming a nightmare .. having to use third party programs ... pay ... to get to play..devido to the problem with the port used and due to the operator does not release it, it is frustrating for him that invested so much money and for people who are left without playing .... and worst of all is that both the incoming ip and the outgoing ip are the same ... and should not be ...
I strongly urge a solution ... since the test indicates success but we can not connect to his game ...
And previously we did and the program used was always PureVPN.
It is frustrating to invest money in something that does not work due to operational restrictions and is an expensive investment both with PureVPN programs and addendums (systems and add-ins) to not be able to use ...

YAKO SOMEDAKY
September 25th, 2017, 01:33
Myrdin Potter when you say a private IP, you think in something like this?
https://www.purevpn.com/dedicated-ip.php
Remember that I am talking from Brazil...

Trenloe
September 25th, 2017, 03:26
since the test indicates success but we can not connect to his game ...
If the connection test works then you should be able to join the game.

Get one of the players joining to open their <FG app data>\console.log file and look for the following:


[25.09.2017 02:22:24] Runtime Notice: Alias translate result = ww.xx.yy.zz
[25.09.2017 02:22:24] Runtime Notice: User 'Player' attempting connection to 'ww.xx.yy.zz:1802' using alias '<your GM's FG alias>'

Where ww.xx.yy.zz is the GM's external IP address (provided by PureVPN). If this is not the same, then try connecting using the PureVPN IP address instead of the alias.

YAKO SOMEDAKY
September 25th, 2017, 04:01
Trenloe unfortunately I can not do this because his frustration was so much that he uninstalled and gave up Fantasy Grounds ... when we tried to connect it was via the IP generated by PureVPN, as well as by the Alias generated by Fantasy Grounds and we did not succeed ...
I use the same Internet Provider as he, but he is from Rio de Janeiro and I from São Paulo and my connection works normally, releasing port 1802 through port forward or through the DMZ.

Trenloe
September 25th, 2017, 04:13
Trenloe unfortunately I can not do this because his frustration was so much that he uninstalled and gave up Fantasy Grounds ...
That's a shame. If they had come to the forums (maybe with your assistance if their English is not so good) for assistance then I'm sure we could have got it working.

YAKO SOMEDAKY
September 25th, 2017, 04:58
I appreciate the attention I send the message to him saying that they are willing to help, I feel guilty in a way, because I was the one who attracted him to FG and he to enjoy the product have to use "external" (PureVPN) and this started to present a problem, until we tried to use Hamachi, but we had problems with the equipment of one of the players, the alternative even paid that was working was PureVPN, thank you and I am ready to help Govanon and the team in tests to allow it to use the Fantasy Grounds application.

daggerfortysix
September 25th, 2017, 13:30
I am going to do purchase the PureVPN because I travel often. When selecting the dedicated IP, do I need the DDoS Protection and NAT Firewall?

Govanon
September 25th, 2017, 13:39
Greetings, gentlemen

I'm the guy who's having severe problems with PureVPN. Before explaining in detail what is happening, allow me to apologize for my rusty English.

I bought an Ultimate Fantasy Grounds license about 2 years ago, at that time my internet operator did not have the Ports closed. I could freely use the Fantasy Grounds, after a while the fowarding adjustments to the infamous 1802 port were necessary.

That year, I had to change the internet operator for a number of reasons, hiring another company. This new internet operator has a policy that was revealed after hiring an obscure and little dishonest policy on access to Ports. The contract expires next year.

Our group tried to use the hamachi and we were not successful. Then it was the turn of other free Virtual Lan solutions that worked for some time. When the company that had one of those Virtual LANs went bankrupt I hired the PureVPN that had been working fine. At that time I must inform you that I live in Rio de Janeiro (capital of the state of Rio de Janeiro and second largest city in Brazil) and Yako in São Carlos (in the interior of the richest state of the country, São Paulo) , internet speed, upload rate and ping are no problems.

It could only get the different IP numbers (internal and external) thanks to servers in Belize, Argentina and, intriguingly, Macao (South China), with an average ping of 130ms.

From a week to now, later, I do not get the appropriate IP's any more, making it impossible for us to play. I looked for solutions in this post and in countless other places in a frustrating combination of research, trial and error.

A large part of the blame comes from the internet operator to which I denounced the Brazilian federal telecommunications authority, which monitors the services of the operators (yes, we have one, with the acronym ANATEL, in English, National Telecommunications Agency). I have little hope that this will be resolved quickly, as my country faces a serious economic and political crisis, aggravated by a possible military coup d'état, so the state organs are somewhat messy. I do not know if you follow the news in this part of the world or what news comes to you.

However, I can not help dispensing some of the blame to the developers of Fantasy Grounds. I explain. We have to admit that there is a major connectivity problem in Fantasy Grounds, otherwise this Thread, as well as others such as Hamachi tutorials, would not exist.

Updates are made, but none towards solving this huge problem. I see that many of us face this problem with Fantasy Grounds. I know that Unity is about to arrive with its one-click connectivity, but I also understand that because of the size of the problem, it takes quite a bit of time to fix it. But I also see that this thread started in 2014. Has there been no effort to minimize this problem since then? As we say here: we have an elephant in the room.

Unfortunately I see no other immediate solution than giving up and uninstalling Fantasy Grounds, even for a while and finding other solutions to gather my friends to play.

It's frustrating.

Thank you very much for your willingness to understand the problem and to help.

Regards,
Marcus "Govanon" Mortati

Myrdin Potter
September 25th, 2017, 14:57
Marcus - do you have the dedicated ip option for PureVPN? Some people were able to get it to work without the dedicated ip option but it was always hit or miss on servers that were not often used.

What internal and external IP address are you getting that are the same? The vpn one or some other network? If not PureVPN IP address then you probably are having a firewall issue after the update as it may have decided that FG is a new program.

Myrdin Potter
September 25th, 2017, 14:59
I am going to do purchase the PureVPN because I travel often. When selecting the dedicated IP, do I need the DDoS Protection and NAT Firewall?

I do not have those options and it has worked fine in China and all over the USA. China has issues occasionally getting the VPN established when the government cracks down on VPN but it usually works again after PureVPN adjusts.

Govanon
September 25th, 2017, 15:02
Myrdin Potter,

From a week to now, I have obtained only the same number of ip, external and internal. I'm going to do a new check on Firewall, I saw it the day before yesterday and the FG was on its list of exceptions.

Thanks.

Myrdin Potter
September 25th, 2017, 15:07
Delete FG from the list and try and re-establish it.

Also, did you buy the dedicated IP address option?

Govanon
September 25th, 2017, 15:13
Delete FG from the list and try and re-establish it.

Also, did you buy the dedicated IP address option?


I'm at work now, when I get home I'll do this Firewall procedure.
My PureVPN has the option of dedicated IP, but I do not remember having contracted this separately.

Andraax
September 25th, 2017, 15:18
However, I can not help dispensing some of the blame to the developers of Fantasy Grounds. I explain. We have to admit that there is a major connectivity problem in Fantasy Grounds, otherwise this Thread, as well as others such as Hamachi tutorials, would not exist.

It's due to a limitation of hosting servers under IPv4. FG is not responsible for the design of the Internet.

Myrdin Potter
September 25th, 2017, 15:18
I'm at work now, when I get home I'll do this Firewall procedure.
My PureVPN has the option of dedicated IP, but I do not remember having contracted this separately.

Without the dedicated IP address option, there is a much less chance of it working and it becomes a game of finding a server without much traffic so you get the port to yourself.

I am on a trip myself now and will be home this evening. Unfortunately I am on Pacific time and we may miss each other. I am just a user like you but I think I was the one the originally recommended PureVPN and I will try and help you get this working.

Govanon
September 25th, 2017, 15:37
Without the dedicated IP address option, there is a much less chance of it working and it becomes a game of finding a server without much traffic so you get the port to yourself.
PureVPN only offers dedicated IP's of UK, Canada, Germany, Malta and Australia.
Said the sales representative.

daggerfortysix
September 25th, 2017, 15:39
I just purchased a US dedicated IP, but had to purchase the option with DDoS. It seems to be working perfectly.

Trenloe
September 25th, 2017, 16:09
From a week to now, I have obtained only the same number of ip, external and internal.
Please provide a screenshot showing this issue. Thanks.

Myrdin Potter
September 25th, 2017, 16:13
PureVPN only offers dedicated IP's of UK, Canada, Germany, Malta and Australia.
Said the sales representative.

They definitely offer USA as well.

When I am in China I connect to my USA dedicated IP address and it works well. My players have reported to me that their download times are faster on the vpn than it is off if it.

Let's first see if we can solve the issue with the repeated ip addresses. When you get home, please post your set up.

For example, are you on a personal LAN connected to a router or do you connect to your internet provider directly. Also the IP address without the VPN on and the address with it on.

daggerfortysix
September 25th, 2017, 16:16
Do I give out the alias or the actual dedicated IP?

LordEntrails
September 25th, 2017, 16:18
On VPN you give out the dedicated IP.

Myrdin Potter
September 25th, 2017, 16:19
You can give out either and it works. Since you always get the same IP address in the dedicated option, you may prefer to use alias unless you have a group of trusted friends as you can change the alias if you have issues with people that leave the game but still come in afterwards.

daggerfortysix
September 25th, 2017, 16:23
Thanks guys! I am almost ready to get back in action as a DM. I'm still working on a few kinks that are purely Mac issues.

Trenloe
September 25th, 2017, 16:35
On VPN you give out the dedicated IP.
To clarify:
- On a stand alone VPN service (like PureVPN) you can use the FG alias for players to connect as the GM's computer will be using the VPN IP address for Internet communications and FG should recognise that and use it for the alias.
- With something like Hamachi for VPN, where the GM's computer has their normal Internet IP address and a different IP address for Hamachi connections, the alias usually can't be used and the Hamachi (VPN) IP address should be used for players to connect.

Govanon
September 25th, 2017, 16:36
Please provide a screenshot showing this issue. Thanks.
Make no mistake, even with a mention of success, players can not connect.

Trenloe
September 25th, 2017, 16:46
Make no mistake, even with a mention of success, players can not connect.
Thanks for posting the screenshot.

Some questions/things to try:

1) Is the 104.243.... IP address the one given by the VPN?
2) Without FG running, go to https://www.canyouseeme.org/ put 1802 in "Port to Check:" field and press the "Check Port" button. What is the result?
3) How many networks do you have on your computer? To see this, go to Windows Network and Sharing Center: Right-click the Network icon in the taskbar notification area then click Open Network and Sharing Center. How many active networks do you have? Are they public or private?

Gwydion
September 25th, 2017, 16:46
Make no mistake, even with a mention of success, players can not connect.

The only time I've seen this happen is with a firewall issue (for me). I have PureVPN and the dedicated ip address option. When I run PureVPN at my office, over the office wifi I do get a success but it won't connect due to firewall restriction in the office. When I change to a hotspot I have I get the success and people can connect. So, just a thought that it is possibly a firewall issue?

Govanon
September 25th, 2017, 16:50
Thanks for posting the screenshot.

Some questions/things to try:

1) Is the 104.243.... IP address the one given by the VPN?
2) Without FG running, go to https://www.canyouseeme.org/ put 1802 in "Port to Check:" field and press the "Check Port" button. What is the result?
3) How many networks do you have on your computer? To see this, go to Windows Network and Sharing Center: Right-click the Network icon in the taskbar notification area then click Open Network and Sharing Center. How many active networks do you have? Are they public or private?

As soon as I get home I can do these tests and show. The IP number is the same as provided by PureVPN.

YAKO SOMEDAKY
September 25th, 2017, 19:15
I am Yako quoted by Govanon, we use the same provider as he said however we are from different regions.
So following the problems I decided to generate a PDF file with the title that I saw that was requested ... remembering that I do not use PureVPN.

Talyn
September 25th, 2017, 19:24
I'm in a similar boat -- I signed up for a month of ExpressVPN to see what the hubbub is all about and hopefully open the possibility of GMing while I'm at work traveling. However, the connection test fails with the VPN enabled. The FG Launcher does detect the new VPN IP just fine, and the router (at home) has the port forwarding set correctly. If I disable the VPN the connect test succeeds.
whatismyip.com also shows the VPN IP. canyouseeme.org also shows the VPN IP but times out trying to get a response from port 1802. So maybe ExpressVPN has their own firewall?

daggerfortysix
September 25th, 2017, 19:33
My PureVPN seems to be working perfectly. I got the NAT firewall protection and the dedicated IP with DDoS protection. I will be doing. out of my gaming on the road using hotel wifi so the added protections may be a benefit. A user from the Fantasy Grounds College Discord server just connected and everything seems to be working perfectly.

Trenloe
September 25th, 2017, 19:40
I'm in a similar boat -- I signed up for a month of ExpressVPN to see what the hubbub is all about and hopefully open the possibility of GMing while I'm at work traveling. However, the connection test fails with the VPN enabled. The FG Launcher does detect the new VPN IP just fine, and the router (at home) has the port forwarding set correctly. If I disable the VPN the connect test succeeds.
whatismyip.com also shows the VPN IP. canyouseeme.org also shows the VPN IP but times out trying to get a response from port 1802. So maybe ExpressVPN has their own firewall?
Most VPN solutions do not allow port forwarding - as they need to share IP addresses for multiple VPN clients. PureVPN is the only one we currently know of that works. HMA used to work, but they changed to shared IP addresses earlier this year.

Ask ExpressVPN direct if they allow port forwarding.

YAKO SOMEDAKY
September 25th, 2017, 20:03
The error of port 1802 tested by the site happened through the fantasy grounds being closed with him open with him success in the test of door 1802.
20722

Myrdin Potter
September 25th, 2017, 23:53
I'm in a similar boat -- I signed up for a month of ExpressVPN to see what the hubbub is all about and hopefully open the possibility of GMing while I'm at work traveling. However, the connection test fails with the VPN enabled. The FG Launcher does detect the new VPN IP just fine, and the router (at home) has the port forwarding set correctly. If I disable the VPN the connect test succeeds.
whatismyip.com also shows the VPN IP. canyouseeme.org also shows the VPN IP but times out trying to get a response from port 1802. So maybe ExpressVPN has their own firewall?

You need a dedicated / private IP. Think of the VPN as no different than an IP giving you a shared IP address unless you pay for your own.

Sometimes you can hop to a server that is not busy and it works but only until others join that server.

I found and tested PureVPN to play while I was at hotels and while I was in China.

I not not port-forward, it just works once connected.

YAKO SOMEDAKY
September 25th, 2017, 23:59
I am posting on behalf of Govanon to inform that the problem has been solved before the operator of internt, through the Brazilian federal telecommunications authority, which monitors the services of the operators (yes, we have one, with the acronym ANATEL, in English, National Telecommunications Agency)
And here is a screenshot that he sent me, thank you for the attention given by the members of the forum.
Thank you on behalf of Govanon and on behalf of Trenloe and Myrdin Potter.

20727

Trenloe
September 26th, 2017, 00:04
I am posting on behalf of Govanon to inform that the problem has been solved...
Great news! :)

Myrdin Potter
September 26th, 2017, 04:28
Happy that it works now. Sorry that he had to go through the hassle but I hope he saw that at least we (the other users and moderators) will try and help.

YAKO SOMEDAKY
September 26th, 2017, 05:44
Of course we have seen, I more than ever since I am always with my eccentric ideas and doubts here in the forum and I am always well received ... but something that we can not deny is that we still have a problem that we hope is only a stain of the past and solved with the appearance of a new version of FG the FG-Unity :)

alfiere_bianco
September 26th, 2017, 19:56
Can i please ask a "guide to Hamachi for dummies"? For work i travel a lot (i'm in Saudi Arabia right now) and i would like to keep playing with my group. But i can't access the hotel's router to open that infamous 1082 port.
I installed Hamachi, but seems not working...maybe because i have no idea on how to use it...

I was bad with networking even at university, that's why i'm asking something like a simple guide on how to use a VPN or alternative sources.

Thankyou so much for the help

Nylanfs
September 26th, 2017, 19:58
With Himachi ALL the players need to have it installed, you probably want a VPN solution.

Also welcome to the forums and FG Community!.

Trenloe
September 26th, 2017, 19:59
Can i please ask a "guide to Hamachi for dummies"? For work i travel a lot (i'm in Saudi Arabia right now) and i would like to keep playing with my group. But i can't access the hotel's router to open that infamous 1082 port.
I installed Hamachi, but seems not working...maybe because i have no idea on how to use it...

I was bad with networking even at university, that's why i'm asking something like a simple guide on how to use a VPN or alternative sources.

Thankyou so much for the help
Welcome to the forums!

Hamachi is a bit different as everyone has to use it - the players and the GM. More information here: https://www.fantasygrounds.com/forums/showthread.php?20309-GM-Connection-Issues-Tried-Everything-Try-Hamachi

alfiere_bianco
September 26th, 2017, 19:59
Thanks for the welcome, i'm really a new user, and i'm just making the first steps inside the game...what do you suggest? is better vpn or hamachi?

Trenloe
September 26th, 2017, 20:05
what do you suggest? is better vpn or hamachi?
Hamachi is free, which is the main advantage. Everyone has to install it, connect first to Hamachi and then to the GM. If there is more than 4 players then the GM must have two Hamachi networks and tell the players which one to connect to. So it can get complex. But, it's free!

With a good VPN, that support port forwarding, only the GM has to connect to the VPN the players don't have to do anything. But, there is a cost, and most VPN providers won't work. PureVPN with a static IP address is known to work OK with Fantasy Grounds and a few people on these forums use it when travelling.

alfiere_bianco
September 26th, 2017, 20:07
Thankyou again, i will give a try with Hamachi, because in SA you can't connect to PureVPN site...yeah, their connection is a lot controlled

Nylanfs
September 26th, 2017, 20:09
Also if you are a player only, you don't need to do anything.

alfiere_bianco
September 26th, 2017, 20:12
unofrtunatly...i'm the master...the planar traveling master

Nylanfs
September 26th, 2017, 20:17
This might be of interest to you then.

https://www.dropbox.com/s/i1mxkdubn8kt46k/Fantasy%20Grounds%20VPN%20Server%20Setup%20-%20draft.docx?dl=0

Myrdin Potter
October 20th, 2017, 03:58
I think I was the original person to recommend PureVPN. I used to live in China and I travel a lot. I tried a few other VPNs, even ones that had dedicated IP addresses. PureVPN was the only one that just worked for me.

I am in China now on a trip. The 5 year big meeting in Beijing is happening now and they always close down VPNs when that happens. PureVPN has a work around and I have it up and working after a quick chat with tech support. Note - chat, as in real time help.

You only need a VPN when using public wifi like at a hotel or if your provider at home shares IP addresses and you cannot reliably port forward. Otherwise most people set the router rules once and then are done. Only matters for the DM.

Trenloe
October 20th, 2017, 05:06
I think I was the original person to recommend PureVPN.
Are you sure? https://www.fantasygrounds.com/forums/showthread.php?20160-Using-a-VPN-Service-Provider-to-get-around-port-forwarding-issues&p=168473&viewfull=1#post168473 ;)

Myrdin Potter
October 20th, 2017, 05:10
No, that is why I said "I think".

:-p

daggerfortysix
October 20th, 2017, 05:26
Either way, you are both bad ***. PureVPN works perfectly for me. thanks to the both of you!

Myrdin Potter
October 20th, 2017, 09:27
I really push the need for a VPN more than many because of frequent stays in hotels and several trips to China a year. China is particularly tough as they are pretty good at blocking VPNs, but so far PureVPN has not let me down.

I could use my NAS to run a VPS , but I prefer having tech support help me when I run into issues. I do run Teamspeak on my NAS and that has not required a vpn connection so far. What I normally do is use my phone or iPad for voice communication and my laptop to DM with via the VPN. I try and keep voice off the vpn if I can.

nicolaskf
March 26th, 2018, 22:07
Hi guys,

Maybe super late to this party. But I have encountered a lot of connection problems. Instead, I took a "free" demo account on Azure (or AWS), and deployed a simple VPN server of my own with "AlgoVPN".

In short, what you need to do is:

## Deploy the Algo Server

1. **Setup an account on a cloud hosting provider.** Algo supports [DigitalOcean](https://m.do.co/c/4d7f4ff9cfe4) (most user friendly), [Amazon EC2](https://aws.amazon.com/), [Google Compute Engine](https://cloud.google.com/compute/), and [Microsoft Azure](https://azure.microsoft.com/).

2. **[Download Algo](https://github.com/trailofbits/algo/archive/master.zip).** Unzip it in a convenient location on your local machine.

3. **Install Algo's core dependencies.** Open the Terminal. The `python` interpreter you use to deploy Algo must be python2. If you don't know what this means, you're probably fine. `cd` into the `algo-master` directory where you unzipped Algo, then run:

- macOS:
```bash
$ python -m ensurepip --user
$ python -m pip install --user --upgrade virtualenv
```
- Linux (deb-based):
```bash
$ sudo apt-get update && sudo apt-get install \
build-essential \
libssl-dev \
libffi-dev \
python-dev \
python-pip \
python-setuptools \
python-virtualenv -y
```
- Linux (rpm-based): See the [Pre-Install Documentation for RedHat/CentOS 6.x](docs/deploy-from-redhat-centos6.md)
- Windows: See the [Windows documentation](docs/deploy-from-windows.md)

4. **Install Algo's remaining dependencies.** Use the same Terminal window as the previous step and run:
```bash
$ python -m virtualenv env && source env/bin/activate && python -m pip install -U pip && python -m pip install -r requirements.txt
```
On macOS, you may be prompted to install `cc`. You should press accept if so.

5. **List the users to create.** Open `config.cfg` in your favorite text editor. Specify the users you wish to create in the `users` list.

6. **Start the deployment.** Return to your terminal. In the Algo directory, run `./algo` and follow the instructions. There are several optional features available. None are required for a fully functional VPN server. These optional features are described in greater detail in [deploy-from-ansible.md](docs/deploy-from-ansible.md).

That's it! You will get the message below when the server deployment process completes. You now have an Algo server on the internet. Take note of the p12 (user certificate) password in case you need it later.

Bidmaron
March 27th, 2018, 02:34
What a remarkable first post, nicolaskf! Welcome to the forums. This seems very helpful.

nicolaskf
March 27th, 2018, 22:46
What a remarkable first post, nicolaskf! Welcome to the forums. This seems very helpful.

Sadly, while all the features are working - the deployment, connecting and using (browsing, videos, even mobile phones and auto-reconnect) - and ports are open in the cloud environments (Azure), for the life of me I can't get the Connection test to Pass...

The port is open, just try a portscan on 51.144.41.194 and you will see 1802 is "Closed" instead of "Timing Out".

How did you guys get PureVPN to work with Fantasy Grounds?

Myrdin Potter
March 27th, 2018, 22:51
The port seems to be open in the dedicated IP option for PureVPN. You probably just need to find the setting.

PureVPN is also constantly playing cat and mouse with China and other places that try and block VPN.

nicolaskf
March 27th, 2018, 23:01
To add more rigor to my plead for help to get this connection up and running:

a) You can download all the config files to access the VPN server here: https://drive.google.com/file/d/1UG53KIEunmXlxMv5O51RVZFGi8Ul4RVD/view?usp=sharing
b) If on a Mac, just use the .mobileconfig file (double-click) and you will automatically configure to use the VPN, the password for the certificate is in file name "certificate password.txt"
c) Just SSH into the server with the code below ( cd into the directory first ): ssh -i configs/algo.pem [email protected]

Bam! you now have a VPN server and SSH access. All games work, except for Fantasy Grounds :(

Update: And yes, if we get the VPN up and running, everyone can use it for gratis, we can make a how-to-configure post later on.

damned
March 27th, 2018, 23:09
To add more rigor to my plead for help to get this connection up and running:

a) You can download all the config files to access the VPN server here: https://drive.google.com/file/d/1UG53KIEunmXlxMv5O51RVZFGi8Ul4RVD/view?usp=sharing
b) If on a Mac, just use the .mobileconfig file (double-click) and you will automatically configure to use the VPN, the password for the certificate is in file name "certificate password.txt"
c) Just SSH into the server with the code below ( cd into the directory first ): ssh -i configs/algo.pem [email protected]

Bam! you now have a VPN server and SSH access. All games work, except for Fantasy Grounds :(

Update: And yes, if we get the VPN up and running, everyone can use it for gratis, we can make a how-to-configure post later on.

I believe you need to add 1802 in a line like this in nicolas.ssh_config


Host algo
DynamicForward 127.0.0.1:1802

nicolaskf
April 1st, 2018, 15:35
Thanks for the input guys. As of now haven't gotten it working yet :( only over LAN.

Will keep trying when I find some time again. Keep you all posted.

Gwydion
April 2nd, 2018, 13:28
Ok. So I got the algo vpn setup and working for windows. Woo hoo! Just wanted to see if I could do it given my lack of technical skills/knowledge. I too can’t get fg to work. I used AWS EC2 as my cloud service. I’m thinking I need to open the port there. I’ve messed around with their security a bit but can’t figure it out. I’m also a little confused by all the ip addresses. When I log into the vpn and open fg my internal up is some 10.0.xxxx number and the external ip is the vpn’s external ip. I tried to add in the code that damned suggested without success. I’ll post some screenshots when I can. I might pm you damned if that is ok. Don’t want u to spend a lot of time but if we can figure this out it’s a pretty cool solution.

Gwydion
April 2nd, 2018, 15:18
Ok. So I got the algo vpn setup and working for windows. Woo hoo! Just wanted to see if I could do it given my lack of technical skills/knowledge. I too can’t get fg to work. I used AWS EC2 as my cloud service. I’m thinking I need to open the port there. I’ve messed around with their security a bit but can’t figure it out. I’m also a little confused by all the up addresses. When I log into he vpn and open fg my internal up is some 10.0.xxxx number and the external up is the vpn’s external ip. I tried to add in the code that damned suggested without success. I’ll post some screenshots when I can. I might pm you damned if that is ok. Don’t want u to spend a lot of time but if we can figure this out it’s a pretty cool solution.

I sent you a pm, damned with the info. I know how busy you are and obviously this is not urgent, just figured if I can help get it work on my end for windows, maybe I can help. nicolaskf, thanks so much for this find! Really cool stuff. Took me a while to figure out how to do it on windows as I have no clue what I'm doing, but it works! Now just need to get FG working.

Couple things I tried as an FYI.

1- Made sure my new algo vpn was a "trusted network" in my kaspersky antivirus (it was public to begin with)
2 - In AWS ECS instance, I added rules to the security group to allow TCP and UDP traffic for port 1802 to any connections.
3 - I added the port forwarding language damned recommended to my ssh config file

Feel like its awfully close, just not quite there!

damned
April 2nd, 2018, 16:29
I sent you a pm, damned with the info. I know how busy you are and obviously this is not urgent, just figured if I can help get it work on my end for windows, maybe I can help. nicolaskf, thanks so much for this find! Really cool stuff. Took me a while to figure out how to do it on windows as I have no clue what I'm doing, but it works! Now just need to get FG working.

Couple things I tried as an FYI.

1- Made sure my new algo vpn was a "trusted network" in my kaspersky antivirus (it was public to begin with)
2 - In AWS ECS instance, I added rules to the security group to allow TCP and UDP traffic for port 1802 to any connections.
3 - I added the port forwarding language damned recommended to my ssh config file

Feel like its awfully close, just not quite there!

You need to allow TCP 1802 traffic FROM other devices.
Im really sorry - I dont have capacity right now to look into this...

Gwydion
April 2nd, 2018, 16:47
No problem at all, Damned!! Thanks for all you do. I'm going to work on it and hopefully between nicolaskf and I we can figure it out.

Gwydion
April 3rd, 2018, 02:59
Thanks for the input guys. As of now haven't gotten it working yet :( only over LAN.

Will keep trying when I find some time again. Keep you all posted.

FYI, I've been researching on the Gitter feed and it looks like other folks report the same issue with setting up their own Minecraft server as an example. People don't seem to be able to get it to work that way. Perhaps the same issue I had with PureVPN before I did the dedicated ip option? I know some VPN's just don't work for this purpose. I'm still happy I went through the process of setting it up! Learned a few things...

damned
April 3rd, 2018, 04:30
FYI, I've been researching on the Gitter feed and it looks like other folks report the same issue with setting up their own Minecraft server as an example. People don't seem to be able to get it to work that way. Perhaps the same issue I had with PureVPN before I did the dedicated ip option? I know some VPN's just don't work for this purpose. I'm still happy I went through the process of setting it up! Learned a few things...

If the MineCraft boys cant get it working it probably cant be done... There may be other restrictions being put onto your Azure instance that are not visible to you.

Gwydion
April 3rd, 2018, 13:27
I agree, Damned! I'm posting a question in the Gitter feed to see if anyone has had success. In the meantime I have a functional VPN for free for a year (I'm using the AWS EC2 free option) that I can use when I want. If I need a VPN for FG I'll just use my PureVPN solution which still works great. Was just seeing if this was another option for folks. Maybe the OP will have better success with this.

Myrdin Potter
April 4th, 2018, 05:31
I love PureVPN. :-)

Gwydion
April 4th, 2018, 11:59
I love PureVPN. :-)

Lol. Me too. Just works!

Samarex
April 8th, 2018, 09:51
I'm currently travelling overseas and I found it quite annoying that I couldn't access many of my US based websites because they could only be accessed from within the UK - Hulu, sections of Netflix, HBO-GO, etc. so I started looking into VPN solutions to make it look like I was still in the US. It turns out there are many "VPN Service Providers" available that allow you to "appear" as if you're in another country - essentially making you have an IP address in another country by using a VPN from where you are currently to an exit point in said country. This has allowed me to access websites and use apps as if I was in the US.

You may be asking "What does this have to do with Fantasy Grounds?" Well, I discovered that this also allows a GM to get around port forwarding issues without the players having to install software as well. Most people who frequent these boards know that most port forwarding issues can be solved by using a VPN application called Hamachi - which usually works fine, but has limitations such as each person has to install the software to be able to connect, and the free version is limited to 5 users.

Using a VPN service provider results in the players not knowing any different and the players don't have to install any software or do anything differently - FG pick up the IP address of the VPN and uses this to update the alias, so the players just connect to the alias as normal and the VPN service provider provides the "tunnel" directly to the GM PC.

The down side? So far I have only found a subscription bases VPN service provider - costing around $50-$60 per year depending on who you go with. This is where Hamachi is better as it is free for 5 connections (including the GM) I believe.

The up side? This allows you to use FG without having to mess around with port forwarding and also where port forwarding is not possible. For example, I will be running a game later today over a 4G wireless access point (EE in the UK if anyone is interested). This wireless access point has not port forwarding possibilities and so I wouldn't be able to run Fantasy Grounds as normal. But, using a VPN service provider allows me to get an external IP address that tunnels directly to my PC - it is this IP address that FG will use for connections, not need for port forwarding as the VPN provides the direct link. Only the GM has to have the VPN configured.

This would also be useful for GMs running a game from a hotel room over the hotel's WiFi and other similar locations - run a game from Starbucks anyone? :)

I thought people would be interested in this as an option for port forwarding issues/travelling restrictions. I'll let you know how I go when I play later today.

One question, Will I need to set anything up on my router?
I have no access to any settings of my router other than the WiFi settings.

Trenloe
April 8th, 2018, 14:00
One question, Will I need to set anything up on my router?
I have no access to any settings of my router other than the WiFi settings.
Nope. That’s why the VPN solution is sometimes needed by people who don’t have access to their router, not just those that can’t do port forwarding. At home, in a hotel, at university, etc., etc..

Trenloe
April 8th, 2018, 14:02
Note - the only VPN service provider we know that definitely works with FG is PureVPN with the add-on dedicated IP address.

Samarex
April 8th, 2018, 14:47
Note - the only VPN service provider we know that definitely works with FG is PureVPN with the add-on dedicated IP address.

Ok I got that tonight. But having a problem with my internet is not working when I establish the dedicated IP address

Myrdin Potter
April 8th, 2018, 15:05
Does your internet not work at all?

Check with PureVPN costlemr servicd if that is the case, they usually respond to me within a minute or two if I type to them.

Samarex
April 8th, 2018, 15:12
Does your internet not work at all?

Check with PureVPN costlemr servicd if that is the case, they usually respond to me within a minute or two if I type to them.

Without PureVPN on yes but when I switch to the Dedicated nothing.

Gwydion
April 8th, 2018, 22:18
Quick update... I just got AlgoVPN working with FG and tested with a few other folks. It works! More to come soon as I get time to post what I did. I know enough to be dangerous now about things like dnat...routing tables... etc.... :)

Thanks again to nicolaskf for this find! It was all him.

Bidmaron
April 8th, 2018, 22:41
Nice work, Gwydion.

Gwydion
April 8th, 2018, 23:05
Ok, so this is way outside of my comfort zone, so feel free to tell me if I did anything stupid.. I'm just glad I got it working! I'll try to do a full writeup, but for now, I'll summarize. First, I followed all the steps nicolaskf posted from the AlgoVPN service in post #176 above. I created mine with a free AW EC2 t2 micro instance. (Free for 12 mos). I then added a custom TCP rule to my amazon security group to allow traffic through port 1802. I tried to add the language damned suggested in post 181 above to my config file. I couldn't get it to work until I did the following:

I logged into my AWS EC2 instance using the shell access that shows up on the "congratulations" screen once you have successfully deployed Algo VPN. For me it was ssh -i configs/algo.pem [email protected]

Once I was logged in, I ran the command ip -4 addr show scope global to see my connections. I saw only "lo" (which I now know is loopback) and "eth0". After a lot of internet research, talking to guys on the algo vpn forum, trial and error, etc which spanned over a week, I finally ran the following commands:

sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 1802 -j DNAT \
--to 10.19.xx.x (where 10.19.xx.x is the ipv4 address that comes up under my Algo VPN when I ran an ipconfig /all while connected to Algo VPN).

sudo iptables -A FORWARD -i eth0 -p tcp --dport 1802 -d 10.19.xx.x -j ACCEPT (where 10.19.xx.x is the same as above, my ipv4 address)

After I ran these commands, I left the ubuntu terminal open and opened a campaign in FG. Once it loaded, I went to canyouseeme.org for the 100th time and checked port 1802 assuming it would fail, but it succeeded! I then had several people outside of my house connect without issue.

So, issues I need to consider. I believe the way I just got it to work will not "persist" each time I launch as I am doing this from the terminal and not modifying the iptable file (all this stuff is new to me). So, I think I need to either do this each time I use AlgoVPN with FG or figure out how to update the iptable on my AWS EC2 instance.

Also, I think that sometimes my ipv4 address changes. So, I think I just need to make sure I run an ipconfig /all when I'm trying to run and FG game with Algo VPN and when I run the commands noted above, make sure I'm using the right ipv4 address.

I did not know a thing about ubuntu or linux before I started this and some might argue I still don't... However, I'm excited I got this working and I'm hoping that for those of you with real tech skills, it will be much easier for you. For now, it seems like I have a free, working VPN solution for a year assuming I don't chew up a ton of bandwidth during games (have no idea how much, but I will test it) and maybe a relatively inexpensive one after a year?

PureVPN is still an awesome solution which I love, but its nice to have options. If anyone has comments/thoughts let me know. This was a great learning experience for me.

Gwydion
April 9th, 2018, 00:04
Did some testing. I closed my terminal and the connection stayed just fine. I also disconnected from AlgoVPN and then reconnected and the forwarding still worked just fine. Maybe its just on a computer reboot that I'll have to type the commands again... We will see..

Gwydion
April 9th, 2018, 12:34
One more quick update. Even after a computer reboot, disconnecting and re-connecting to AlgoVPN, the connection seems to hold and I'm getting a successful test in FG. Yay!

Gwydion
April 9th, 2018, 13:44
I'm an idiot.... Of course it still works.. I haven't yet rebooted my EC2 instance so until I do that the rule should hold.

Gwydion
April 10th, 2018, 13:53
Morning, all! Just another quick update. So, I've now used the Algo VPN with my AWS EC2 instance at home with my laptop and I was just able to test it at my office. So far the port forwarding works perfect in either location. I think the only issue I might have is if the internal ip address assigned to my computer from the Algo VPN service ever changes. If it does, I should be able to just update my iptable rule. Interestingly, I've never been able to get PureVPN to work with Fantasy Grounds at my office unless I was not on my office internet. However, with Algo VPN, it worked fine even on my office internet.

Anyway, hopefully the OP checks back in soon and maybe we can find a way to use this as a backup for some folks? Given it is using port-forwarding, I think this solution will still only work for one person at a time so i think folks will have to set up their own Algo VPN service and cloud server if they want to try it. At least we seem to have found another service that will work!

Gwydion
April 10th, 2018, 17:20
One more update for anyone following this thread. So, I sent Rob2e an email with some simple instructions and my .ps1 file. Within about 10 minutes (or less) he had AlgoVPN installed on his computer. He connected, was assigned the internal 10.xx.xx.1 ip address, tested FG and got a successful connection! I tried to connect at the same time and was assigned a 10.xx.xx.2 ip address so my connection failed which makes sense to me. Can't have us both running a game at the same time as the port forwarding is going to one ip address. Once Rob disconnected, I kept trying to connect to AlgoVPN and kept getting the .2 ip address. So, I rebooted my computer and after that, I was assigned the .1 address and the FG connection test succeeded again.

So, I guess what I'm thinking is that this could be a really good backup solution for a small group of DM's who want to share their login credentials for AlgoVPN? As long as you communicate and don't try to run a game at the same time and only use AlgoVPN for Dm'ing, this could work really well. The reason I say only use it for Dm'ing is if I just log into it to surf the web and get the .1 ip address then if someone else logs in and tries to run a game, they will never be able to get the .1 address as it is already assigned to me. Of course I could update the iptable routing rule to fix that, but that requires more effort and coordination.

I'll give it some more thought, but I think I might see if a couple of the Dm's I know well travel a lot and need this type of solution and I'll let them use this setup and we will just coordinate with each other to make sure we don't log in at the same time. Frankly, I will hardly ever use this as right now as I'm not traveling a lot. More to think about, but really cool.

Gwydion
April 12th, 2018, 17:34
Ok. At some point I will create a new thread on this entitled AlgoVPN so it doesn't get lost. Latest update. With the help of a guy on the AlgoVPN gitter thread who is a rockstar, I was able to go into the code of AlgoVPN and change the vpn network range from 10.xx.xx.0/24 to a single ip address! Now each time I log into AlgoVPN it gives me the same ip address and given I have the rule to portforward that ip address in place, it is working without exception. Also, again, given I've had Rob2e connect and it is working for him (both of us Windows 10) without exception, I think I now have a solution (for free for a year) that could be used for a small group of DM's in case they are traveling or cannot for some reason access their router to port forward. Only caveat is only one of us can be on the network at one time to run a game! Not an issue for me as I won't need to use this often at all. At least it's free until next April when I will re-assess the cost with Amazon AWS EC2.

I need to check the speed I suppose to see if there are any issues, but its definitely ready to go now!

I'll give more thought to how to document how I got everything working as this hopefully will be a solution others can now use. I want to coordinate with the OP, nicolaskf and thank him again as he is the one who found this solution. Also want to see if he wants to start the thread and document himself. Very excited about this.

More soon! Happy Thursday!

Bidmaron
April 13th, 2018, 04:08
This was great work for sure, Gwydion.

Gwydion
April 13th, 2018, 04:16
This was great work for sure, Gwydion.

Thanks Bidmaron. I'm in the process right now of recreating everything from scratch and documenting it so I can put it in a word document on my dropbox account if anyone wants to try to set it up.

PooKie
May 16th, 2018, 01:11
The real number of cases where port forwarding doesn't work is really, really, really low. 99% of the time, reading the manual and setting it up properly solve any issues. Well, except when the internet providing is purposefully hatched and gutted.


Im very sorry, but this is simply not even remotely true. I have had FG for years now, almost 4-5 years I believe. I have tried dozens of different computers on more than a dozen different connections AND connection types within THREE different countries and I have stumbled upon this issue every single time, (Im talking 100.00% of all attempts to create and host a game) despite going through (thoroughly) every bit of information given on the subject. (Note that I have managed to get it working several times, but the problem still appears on "new attempts")

The way it works may be easy for the developers as it puts the general responsibility of game creation in the hands of users and not a load on their end, which is alright in most cases, however, A LOT of people have NO idea what port forwarding is and would probably never figure it out despite endless (and outdated) youtube guides. Some people may not even have access to their router to perform any Port Forwarding. Which rules out a large amount of people willing to play the game.

Luckily, my friend who is a genius with computers managed to figure out that the problem is sometimes within FG itself. (somehow?)
We did an experiement where we set up four different computers on the same network - Two of these with a BRAND new windows install and only the necessary things to get FG to open. I.e. Steam and the game itself. - And the other two computers kept as is.
All end devices attempted to host a game, but with no luck. The connection test shows "Failure".
Well, to begin the whole show, we started doing the regular port forwarding, 1802 is the port. (as mentioned within the game itself)

To our surprise something strange happened. One of four computers managed to actually host the game properly. People were able to join and everything (remember the problem still appeared).
We then tried to remove said computer and try again. (This is the strange part ->) Now one out the three computers were able to host- one of which had no luck in the prior attempt. The other two still had no success.
I assume you can guess what happened when we removed a second one and tried again. (spoiler, it worked).

We then tried to put back all four computers and start over, but this time we tried hosting from a different computer. - It did not work. Despite PortForwarding. Not one of the computers were able to host. (All tried to port forward)

Im not really sure how it all works on the tech side of things, but to my knowledge, there was not a single firewall involved. except the one(s?) in the router being PF'ed.
We did these types of "experiements" over and over again, from different angles and on different times. Countless hours spent on youtube/google etc trying to solve the issue.

It now became apparent to us (the genius mostly) - That the game, or the way the game handles such traffic, is flawed. Its simply putting to much of a hazzle in trying to play a game that requires NOTHING on a serverside part. It is literally pen&paper on your screen.

I really love this game and I have played D&D for about 10 years. Its amazing because it enables people to play without leaving the comfort of their home.
Unfortunately my friends and I have experienced this in the most horrible way. Do one thing and it works perfectly. Do it again - ONE HUNDRED PERCENT - as you did it the last time (remember? it worked so, lets do that again, right?) and now it doesn't work.
There's no logic to it and its simply too frustrating spending hours on solving the issue. I know TONS of people who have simply put the game down and forgot about it, because of this issue.

Im not trying to **** talk the game or anyone. I'm simply stating that "99% success rate" is not even funny... It is so .. SO SO SO far beyond the truth, and saying that it is even remotely close to 99% would be either;

A) a severe case of denial.
B) a perfectly magic setup and sugardaddy'ing the Port Forwarding Gods.

The point is, a brief search on google will completely destroy the notion that it is anywhere near 99% success rate. It is astronomically far from that. Thousands and thousands of people are experiencing this on a daily basis.

I'm very sorry if I have offended anyone - But seeing someone talking so "lightly" and downright wrong about a really ****ing serious issue is upsetting as I have personally dealt with said issue.

Andraax
May 16th, 2018, 01:20
You can only port forward to one computer on a private network at a time. Anyone who knows anything about IP4 should know this.

Most of the time where it works once, but not later is due to the hosting system's IP address changing. Because the port is still forwarded to the old address.

damned
May 16th, 2018, 01:30
Welcome PooKie


Im very sorry, but this is simply not even remotely true. I have had FG for years now, almost 4-5 years I believe. I have tried dozens of different computers on more than a dozen different connections AND connection types within THREE different countries and I have stumbled upon this issue every single time, (Im talking 100.00% of all attempts to create and host a game) despite going through (thoroughly) every bit of information given on the subject. (Note that I have managed to get it working several times, but the problem still appears on "new attempts")

Not many things in the realms of technology stay the same for four years - and the quote above was from 4 years ago.
I help a lot of people get connected and Im my experience of dealing only with those that are having issues getting connected - we still solve it very close to 9/10 times.
However - that is no help to you if you are not able to get it working.
What country are you in? Many countries have a distinct lack of IPv4 addresses and they do additional IP aggregation making Port Forwarding very difficult or even impossible for the end user.


The way it works may be easy for the developers as it puts the general responsibility of game creation in the hands of users and not a load on their end, which is alright in most cases, however, A LOT of people have NO idea what port forwarding is and would probably never figure it out despite endless (and outdated) youtube guides. Some people may not even have access to their router to perform any Port Forwarding. Which rules out a large amount of people willing to play the game.

See this link for various other options: https://www.fantasygrounds.com/forums/showthread.php?43607-Port-Forward-Alternatives
Plenty of people here are also happy to assist.
Yes it is a limiting factor and it wont be addressed until the next game engine is released.



Luckily, my friend who is a genius with computers managed to figure out that the problem is sometimes within FG itself. (somehow?)
We did an experiement where we set up four different computers on the same network - Two of these with a BRAND new windows install and only the necessary things to get FG to open. I.e. Steam and the game itself. - And the other two computers kept as is.
All end devices attempted to host a game, but with no luck. The connection test shows "Failure".
Well, to begin the whole show, we started doing the regular port forwarding, 1802 is the port. (as mentioned within the game itself)

If connecting to a second instance of FG on your own computer use localhost
If connecting to a FG instance on the same LAN/network as you use the Internal IP or local IP address
If connecting to a FG instance on the Internet use the External IP or Alias
If connecting to a FG instance that is on one of these alternative methods use their instructions


To our surprise something strange happened. One of four computers managed to actually host the game properly. People were able to join and everything (remember the problem still appeared).
We then tried to remove said computer and try again. (This is the strange part ->) Now one out the three computers were able to host- one of which had no luck in the prior attempt. The other two still had no success.
I assume you can guess what happened when we removed a second one and tried again. (spoiler, it worked).

We then tried to put back all four computers and start over, but this time we tried hosting from a different computer. - It did not work. Despite PortForwarding. Not one of the computers were able to host. (All tried to port forward)

Port forwarding directs a specific port to a specific IP address.
If you use Plug n Play it will try to set this up for you but it can still only direct it to a single Ip address (computer)
Depending on your PnP device/settings it may handle you swapping hosts quickly or it may not (more likely) and it may even require a reboot to clear its current entries quickly
If you have setup manually you will need to clear entries and then add the new entry


Im not really sure how it all works on the tech side of things, but to my knowledge, there was not a single firewall involved. except the one(s?) in the router being PF'ed.
We did these types of "experiements" over and over again, from different angles and on different times. Countless hours spent on youtube/google etc trying to solve the issue.

It now became apparent to us (the genius mostly) - That the game, or the way the game handles such traffic, is flawed. Its simply putting to much of a hazzle in trying to play a game that requires NOTHING on a serverside part. It is literally pen&paper on your screen.

All windows computers have a built in firewall.
Please make sure that all connections were set as Private as the Public profile will block all incoming connections by default.


I really love this game and I have played D&D for about 10 years. Its amazing because it enables people to play without leaving the comfort of their home.
Unfortunately my friends and I have experienced this in the most horrible way. Do one thing and it works perfectly. Do it again - ONE HUNDRED PERCENT - as you did it the last time (remember? it worked so, lets do that again, right?) and now it doesn't work.
There's no logic to it and its simply too frustrating spending hours on solving the issue. I know TONS of people who have simply put the game down and forgot about it, because of this issue.

Im not trying to **** talk the game or anyone. I'm simply stating that "99% success rate" is not even funny... It is so .. SO SO SO far beyond the truth, and saying that it is even remotely close to 99% would be either;

A) a severe case of denial.
B) a perfectly magic setup and sugardaddy'ing the Port Forwarding Gods.

The point is, a brief search on google will completely destroy the notion that it is anywhere near 99% success rate. It is astronomically far from that. Thousands and thousands of people are experiencing this on a daily basis.

I'm very sorry if I have offended anyone - But seeing someone talking so "lightly" and downright wrong about a really ****ing serious issue is upsetting as I have personally dealt with said issue.

As mentioned above the 99% figure was anecdotal in that users experience/estimation.
I have helped well into triple figures of people get connected and in my experience the number is still 90% and that is of problem cases.
There are approx 4billion IP addresses so even "thousands and thousands" (wherever that number came from) may well be less than 1% - however that isnt really relevent to your case.

If you need some assistance please ask and we will do our best to help.

Trenloe
May 16th, 2018, 05:06
I'm very sorry if I have offended anyone - But seeing someone talking so "lightly" and downright wrong about a really ****ing serious issue is upsetting as I have personally dealt with said issue.
Welcome to the forums PooKie.

I, also, don't want to offend. But... it makes me laugh a little that you choose one single line from a 4 year old post, from the whole of this thread to use as the basis for something that is upsetting you so much. Anyone can post a whole load of crap on the Internet - opinions, data, whatever - and it doesn't mean it's correct or even remotely true. The particular post you reference is from a user who, as you can see from their details to the left of their post, doesn't have a big reputation in the community, nor a large number of posts. So, I most certainly wouldn't take their word as gospel and would definitely not get upset about disagreeing with what they said.

As has been mentioned - the multi computer testing you did is not a valid test - port forwarding can only work to one computer at a time within your network. Which your tests actually proved - i.e. only one computer at a time passed the connection test. As an FYI - only the GM need to have port forwarding, players don't need it at all.

I appreciate your post was probably more out of frustration than anything else.

My recommendation: let us know if you have any specific issues in future. And the active, more knowledgeable, members of this community will endeavor to help you.

Again, welcome to the community. You don't have to try to work these things out on your own - let us know specifically what issues you have and we'll try to help! We all just want to game...

Trenloe
May 16th, 2018, 05:15
@PooKie - there is good news! The fact that you could get connection test successes on some of the PCs means that it should be pretty straightforward to get you working as a GM. Pick the one computer that you want to be your GM instance and get that setup. That's all you need to do - player computers don't need the connection test to work. Let us know if you need clarification or assistance in doing this.

Alexsand73
July 3rd, 2018, 03:36
Does this instructions works for a Window PC? Thanks

IrishBouzouki are you taking about the VPN instructions I created?
https://www.dropbox.com/s/i1mxkdubn8kt46k/Fantasy%20Grounds%20VPN%20Server%20Setup%20-%20draft.docx?dl=0

damned
July 3rd, 2018, 04:06
It does work for Windows PC but you need to setup an external server outside...

Id look at the threads linked from here and see which one you want to pursue.
https://www.fantasygrounds.com/forums/showthread.php?43607-Port-Forward-Alternatives

catenwolde
July 4th, 2018, 20:01
Hi - I'm working through my options to avoid port forwarding with a vpn, and was wondering if someone could sum up why the dedicated ip option is important. Is it because the ip of the dm might change during a session, causing the players to disconnect? Wouldn't that be avoided by the players using an alias to connect? Or ... would there still be a momentary disconnect even then? Is the disconnect short and manageable? Thanks!

Myrdin Potter
July 4th, 2018, 20:17
Basically, without dedicated IP, you are virtually sharing the same address and ports while with dedicated IP you are vitually alone on the IP address.

If the server you are on is not busy, the program does work at times without the dedicated option but once the server gets busy, the NAT messes up the ports.

catenwolde
July 4th, 2018, 20:32
Thanks for the quick reply. Since our games will be international (Europe/USA) I suppose lag and stability will be important issues. It seems NordVPN would be the better option without a dedicated IP, but PureVPN has the better dedicated IP pricing, which is why I wanted to be clear.

Gwydion
July 4th, 2018, 20:35
Also, if it’s only for fg you can use algo vpn. Free for a year with Amazon aws. I can send u info if you are interesting in trying mine. Might be tomorrow since I’m out of town but it works great. I love pure vpn as well.

Myrdin Potter
July 4th, 2018, 20:59
You can pick where the dedicated IP is (mine is houston and works well when I am in China). FG does not rely on fast twitch where Ling really matters.

I have a link to pureVPN in the signature to my posts.

(Note to self - wear your reading glasses while posting publicly)

damned
July 5th, 2018, 00:01
The reason the dedicated IP is usually needed is that with a shared IP you often cannot guarantee access to the specific port - TCP 1802 - that Fantasy Grounds requires.

catenwolde
July 5th, 2018, 10:24
Thanks for all the replies - you've all been very helpful, especially on a holiday! I just have one more question about the use of dedicated IP's. Since there is no option to choose an IP in my current country of residence (Finland), but the other gamers will likely mostly be in the USA, does it make any difference if I choose a European (say, UK) versus an American IP? Does anyone know if you can change the country of your dedicated IP in PureVPN?

damned
July 5th, 2018, 12:07
Latency is not really an issue for Fantasy Grounds. Its not a first person shooter where milliseconds of difference mean life or death.

Trenloe
July 5th, 2018, 18:08
It seems NordVPN would be the better option without a dedicated IP, but PureVPN has the better dedicated IP pricing, which is why I wanted to be clear.
Just as a FYI : I don't recall anyone reporting that NordVPN has worked for Fantasy Grounds GMing.

NordVPN's website says they don't currently support port forwarding: https://support.nordvpn.com/#/Getting-Started/1047408432/Do-you-offer-port-forwarding.htm

catenwolde
July 5th, 2018, 18:48
Fantastic follow-up. I had already decided that PureVPN was the way to go, but good to know NordVPN's limitations.

catenwolde
July 6th, 2018, 19:23
FYI, not only is the dedicated IP a $2/month add-on, but port forwarding is another $1/month add-on.

EDIT: Hmm ... if port forwarding is a dedicated add-on, which they specifically describe as used for internet gaming, does that functionality make the dedicated IP redundant?

Gwydion
July 6th, 2018, 19:35
FYI, not only is the dedicated IP a $2/month add-on, but port forwarding is another $1/month add-on.

Wait... You shouldn't need the port forwarding if you have the dedicated IP add-on. I've had Pure VPN for a year and a half or so with only the dedicated IP and it has worked just fine for me.

Myrdin Potter
July 6th, 2018, 19:39
FYI, not only is the dedicated IP a $2/month add-on, but port forwarding is another $1/month add-on.

EDIT: Hmm ... if port forwarding is a dedicated add-on, which they specifically describe as used for internet gaming, does that functionality make the dedicated IP redundant?

I have always just used the dedicated IP address and not bought the port forwarding. I personally think that you will get a more reliable connection with the dedicated Ip (it is always the same so you can use it instead of the server alias if you want to). You can try portforwarding. PureVPN has been good in the past for refunds.

catenwolde
July 6th, 2018, 20:03
Thanks again for the quick replies. I think my confusion stemmed from not understanding that the PureVPN port forwarding add-on simply allows you to use normal router port forwarding with its VPN - I though it was a sort of added functionality that enabled its own type of port forwarding (if that makes sense). At least, that is how I understand it after reading this: https://www.purevpn.com/blog/what-is-port-forwarding-scty/

You know, I started playing D&D with the Holmes Blue Book and cut-out chits ... we're not in Kansas anymore kiddies! ;)

Myrdin Potter
July 6th, 2018, 20:18
That was the first D&D book (boxed set) that I bought, but I got the dice in mine. :-)

pfrandsen
July 7th, 2018, 15:46
I picked up Pure VPN (good sale right now) do I now have to purchase the static IP add on too?

Myrdin Potter
July 7th, 2018, 15:48
Yes. The dedicated IP option is the proven way to get it to work.

pfrandsen
July 7th, 2018, 16:30
I am running in dedicated ip mode in PureVPN. still getting connection failure. any suggestions?

Myrdin Potter
July 7th, 2018, 16:34
The test fails? Or someone tries to connect and it fails?

You need to check the network settings (private vs. public). And your anti-virus software / firewall.

Make sure the VPN is running before you open FG. Look at the IP addresses reported on the main screen.

pfrandsen
July 7th, 2018, 16:41
test fails. network is private. FG allowed through AVG and Defender

Gwydion
July 7th, 2018, 17:21
test fails. network is private. FG allowed through AVG and Defender

For avg did you set the rule to five bars to allow incoming and outgoing? It will only work if you set to five bars.

Gwydion
July 7th, 2018, 17:27
I might have my antivirus mixed up. Just make sure you allow incoming connections.

pfrandsen
July 7th, 2018, 17:29
For avg did you set the rule to five bars to allow incoming and outgoing? It will only work if you set to five bars.

it was 5 (otherwise autodecide) changed it to just make it 5

Trenloe
July 7th, 2018, 17:50
test fails. network is private.
Once the VPN connects, make sure the VPN network connection shows as private.

Then start up FG once the VPN has assigned the IP address. Check that the load campaign screen shows the external IP address as the same as the VPN.

pfrandsen
July 7th, 2018, 20:27
Here is where I am at :
Set up my PureVPN to operate on a PPTP protocol. Have a set IP that matches both the internal and external ip's in the FG campaign load screen. FG is running through AVG security at 5 bars and is going through windows defender. Pure VPN is set to Private. Test still fails. Please help this is SOOOO frustrating trying to get connected!!

Gwydion
July 7th, 2018, 20:44
Is the fg rule in defender and avg for fantasy grounds.exe? Make sure it is. And make sure In windows defender the network is showing as private or trusted or whatever the defender setting is to say it is a home network. If that all has been done try automatic protocol in pure vpn. I’m not at home so can’t check my vpn protocol.

pfrandsen
July 7th, 2018, 21:28
checked all that, still no connection

Gwydion
July 7th, 2018, 23:30
When I get home I we’ll see what else I can come up with and post here.

pfrandsen
July 7th, 2018, 23:31
appreciate it, thanks

Gwydion
July 7th, 2018, 23:52
Ok. I'm starting to look now. Also, feel free to pm me in discord as well. You can join my channel if you want to text chat in more real time. I can't talk live but I can text chat.

https://discord.gg/MZ4B74

You can direct message me there if you want. First thing I noticed is my dedicated ip for PureVPN is set to SSTP for the connection. I will keep looking and let you know what else you find.

Bidmaron
November 9th, 2018, 01:54
Living at a hotel for 3 out of 4 weeks, so I bough PureVPN w/ dedicated IP option. Internet and all working great, but connection test fails. I am set to SSTP protocol. I have no firewall on Parallels, and when I am home on my wireless router port forwarding works great without anything abnormal. Any ideas? I tried the port forwarding, and it says I have to buy another option on PureVPN for that. This thread claims you shouldn't need anything but dedicated IP option.

Myrdin Potter
November 9th, 2018, 02:00
Where is this test? At home?

Are you running the windows version or the Mac version? I am not familiar with the internal workings of the Mac running 2 OS at the same time.

You are connecting to the dedicated IP, right? Usually there is a server just for that.

Bidmaron
November 9th, 2018, 02:15
Myrdin, I am at the hotel now. I knew I couldn't host a game without a VPN due to inability to port forward on hotel's router, so I bought PureVPN with Dedicated IP option.

I can't bring my desktop PC on my trips, so I have to use my Mac. With my Mac running Windows 7 on Parallels, I host games all the time at home, so it isn't a Parallels problem I don't think.

I know you do it on a PC, but my connection fails every time, with or without the VPN running.

Myrdin Potter
November 9th, 2018, 02:31
I use a windows laptop when I travel. I use the dedicated ip server, connect and get the IP and then I start up Fantasy Grounds and it just works.

I am out at dinner now and on my phone but I remember someone else having to do some setting to get the windows and Mac network stacks to see each other properly.

There have been people with your set-up here discussing it before, and it did end up working.

Have you confirmed that you have the expected ip and your vpn connection is working?

Bidmaron
November 9th, 2018, 02:35
I just checked, and the external ip blank in the game host section does indeed show my dedicated ip from PureVPN.