It too me a while to work out why my Nextcloud stuff wasn’t working on my phone. It wasn’t until I went to http://duckdns.org on mobile data I saw the block. I had changed ISP from one with IPv6, which I had setup, to an ISP without it, and thought it might be that. But it was just coincidence.

I’ve written to O2 but I doubt they will change anything, so I’ll be changing network.

So heads up UK O2 self hosting people!

    • Appoxo@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      9 months ago

      Save the children
      Piracy concerns
      Laws
      Someone didnt get paid.

      Pick at least one.

      In all seriousness: I don’t know.

    • Supermariofan67@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 months ago

      Lots of malware gets hosted using dynamic DNS domains, so they (or more likely some bot) probably saw the domain frequently showing up in malicious activity and blocked it without understanding that it itself isn’t the source of the malicious activity.

  • socphoenix@midwest.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    9 months ago

    T-mobile was doing this in the US but only blocking certain ports when talking to my home server, might try putting it on a non-standard port as well and see if you can access the service then.

    • jabjoe@feddit.ukOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 months ago

      Oh I know some ports are ok. My SSH and WireGuard get through. Port 80 is redirected to a block page place holder and 443 is interfered with so SSL fails.

      • Droolio@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 months ago

        Wouldn’t you be on CGNAT though? How are they blocking it - at the DNS level? Have you tried a CNAME record that points your own domain to the actual duckdns domain? Just curious how/why they might be doing this.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    4 months ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    CGNAT Carrier-Grade NAT
    DNS Domain Name Service/System
    HTTP Hypertext Transfer Protocol, the Web
    HTTPS HTTP over SSL
    IP Internet Protocol
    NAT Network Address Translation
    PIA Private Internet Access brand of VPN
    SSH Secure Shell for remote terminal access
    SSL Secure Sockets Layer, for transparent encryption
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)

    [Thread #341 for this sub, first seen 9th Dec 2023, 20:15] [FAQ] [Full list] [Contact] [Source code]

  • antsu@lemmy.wtf
    link
    fedilink
    English
    arrow-up
    1
    ·
    9 months ago

    O2 has an on-by-default security filter that blocks all sorts of “bad stuff”. For me, it was preventing connecting to any PIA VPN servers. Ping their customer support and they can disable it for you.

  • Lemmchen@feddit.de
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    9 months ago

    If it’s just a DNS block, you could use a different DNS server. You should do this anyway in my opinion.

    • jabjoe@feddit.ukOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 months ago

      It’s not the DNS server. I’m sure of this because Termux uses a different DNS server but does the same. I also tried setting my phone to use OpenDNS directly. I’m pretty sure they are inspecting the DNS traffic. Exactly so changing DNS server doesn’t help.

      I don’t see a problem when using IP directly. I mean the IP is static, so I could must buy a domain, but I’d also have to piss about with my setup.

      • Lemmchen@feddit.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 months ago

        Modern Android versions can use DoH (DNS over HTTPS) which can not be intercepted. If you don’t have this option or are not sure how to configure it, you could use the Quad9 app to enable secure DNS. This way you can make sure it is not related to DNS. Frankly, I can’t imagine they are blocking the IPs of the DuckDNS servers directly.

  • jabjoe@feddit.ukOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 months ago

    Just a follow up to this.

    So I never ended up contacting O2 to say “please stop this”, I just used Wireguard to home and ignored it. Until the local Morrison’s wifi started doing the same thing but worse and I couldn’t event Wireguard round it.

    So I finally just bought a domain and setup my Apache to redirect the old duckdns to the new domain.

    So far this all seams to be working great.

    • jabjoe@feddit.ukOP
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      9 months ago

      O2 didn’t until recently. EE does’t currently (wife’s network)