wherbert100's profile

Frequent Visitor

 • 

17 Messages

Monday, August 16th, 2021 7:28 AM

Closed

advanced security allow access

Hi, I have a UPnP device that I would like to allow access to from outside networks. The documentation here: https://internet.xfinity.com/more/help/articles/Frequently-Asked-Questions#xfi-advanced-security states: 

Can I use Advanced Security while having port forwarding or DMZ enabled?

If Advanced Security detects a known threat targeted for the device with Port Forwarding, DMZ settings enabled, or UPnP open ports, it will block all traffic coming from its open ports as a measure of protection until the threat is averted. If you are unable to access a device from outside your home network, you have two options:

  1. Allow Access – Go to the Connect section in the Xfinity app or xFi website, select Advanced Security and then select the device you want to provide access to. Follow the instructions to Allow Access. We recommend that you only use Allow Access when you are confident about who is accessing the device from outside the home network. Note that the Allow Access feature will only permit access to the specific device you choose on the specified port using a specific source IP address for 30 days from the time you enable it.

However, there are no devices listed when I go to Connect->Advanced Security. The device in question is, however, listed along with all my other network hosts from the main Connect tab. This is annoying as I like the idea of having the Advanced security turned on but I must have UPnP working from this device so it can open ports when needed. Also, adding port forwarding rules via Connect seems to be out of the question since this host has a static IP far outside of my configured DHCP pool and frankly would be too much work to change even if I wanted to use static DHCP. Since, it seems, you cannot add port forwarding rules for hosts that DO NOT use DHCP. I don't understand why this limitation is in place. 

thanks

Official Employee

 • 

1.9K Messages

3 years ago

Hi, @wherbert100. Thank you for creating this post, so we can help provide some clarity. I understand you are running into an obstacle when following the "Allow Access" portion of these steps. I also see you can't set up port forwarding given the situation. I know you've tried a few times, but you have not found a way to get this done. I get you like the peace of mind that comes along with the xFi Advanced Security feature which is completely understandable. Have you attempted to disable this feature while testing things out? Did you see any change to the options available? 

Frequent Visitor

 • 

17 Messages

@XfinityVianney Yes, disabling advanced security allowed my UPnP device to work as expected. Until recently that is. Something had changed in November and my UPnP devices no longer open the ports I need.  

Official Employee

 • 

1.4K Messages

Hello @wherbert100! Nice to hear from you again! I'm sorry to hear you're having issues again with your ports, but you have definitely come to the right place for assistance! If you could send our team a private message with your full name, the name listed on the account (if different), and the service address associated with your account, I'd be more than happy to look into this for you!

 

To send a Private Message, please click on the chat icon in the top-right corner of the screen, next to the bell icon, and then type or select "Xfinity Support" to initiate a live chat.

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Expert

 • 

108.3K Messages

3 years ago

@wherbert100 @XfinityChelseaB 

Please post any possible solutions for the issue here in the open forums so that all readers here may benefit from the exchange / info. This is in keeping with the spirit for which these public help forums were originally intended. Thank you.

forum icon

New to the Community?

Start Here