49

Egress Hairpinning

I run a couple servers inside my network, mostly relying on a reverse-proxy to accept connections on TCP 443 and proxy the connections to the right internal server. I don't run separate internal v. external DNS. Instead, I have a more typical setup where I define an external DNS server in eero, then the eero includes its address as the DNS server in all DHCP addresses, and forwards the requests.

 

As a result, though, I can't access my server by [subdomain].[domain].com while *inside* my eero network. I have to instead use DNS shortnames. This is annoying for a number of reasons. 

161 replies

null
    • dbmet2
    • 6 yrs ago
    • Reported - view

    Very sad this still isn't supported. Every other router supports this but not eero. Sure sounds like one developer engineer somewhere who doesn't believe in this feature so they won't include it. 

    • go_robot_go
    • 6 yrs ago
    • Reported - view

    dfsutherland Thanks for sharing this for those who have an immediate need to temporarily address a major shortcoming of eero.

    That said, eero engineers, don't mistake this for a solution. This is something that is beyond the abilities of your core market, and something that many of us will refuse to do on principle, because it's providing functionality that eero should have provided from the beginning.

    For what it's worth, I've determined that the Netgear Orbi *does* support NAT loopback. I figure that they'll have sales on Orbi near the holidays, so eero has approximately five to six months to fix this mess before I jump ship.

    • Konolua
    • 6 yrs ago
    • Reported - view

    Actually almost everything supports NAT Loopback/NAT Redirection/Hairpinning/so forth, so anyone should be able to easily find an alternative. Ha ha.

    Personally, I went the more expensive route and couldn't be happier. I went Ubiquiti and deployed 2 APs with their USG. At $320, my mom's house has 2 APs and the USG router and she's never had faster speeds on every sq ft of her property. I did the UAP-AC-HD so my network cost $750, but I have 75 active devices and the same results. I never got over 50Mbps down and 35Mbps up on Eero, but I now get 82Mbps/120Mbps. Honestly, I even get faster WAN speeds via ethernet for some reason over every other router I have tried. I had spent $600 on Eero since I bought more access points, but I returned them all within the time frame. The other poor folks on this thread didn't have that opportunity. I was fortunate.

    I still follow this thread since I set up systems for other people as a side job, and it's sad to think this hasn't been addressed.

    • dfsutherland
    • 6 yrs ago
    • Reported - view

    Eero Engineers & go_robot_go 

    go_robot_go said:
    That said, eero engineers, don't mistake this for a solution. This is something that is beyond the abilities of your core market, and something that many of us will refuse to do on principle, because it's providing functionality that eero should have provided from the beginning.

     Yes, I made this work. But I've been programming since the 1970s, and on the Internet since the old Arpanet had three nodes, so I'm not exactly your core market... except that I'd rather spend a little more to avoid having to mess with issues like this. That's what I thought I was buying! I was only partly correct. 

    If I was helping family or friends, the Egress hair-pinning issue would have led to an instant return! I'm just barely willing to do the additional work I described above for myself—and that only because it worked perfectly on the first try. I would be utterly unwilling to do this extra work as volunteer support for someone else.

    The primary reason for paying premium prices for devices like the Eero is to get a good-performing network that "just works" with absolute minimum fiddling. Even with Apple making it easy, setting up an internal DNS server is clearly incompatible with absolute minimum fiddling. And with the vast majority of competing devices providing this functionality, you really, really should have provided it from the beginning.

    • ziptbm
    • 6 yrs ago
    • Reported - view

    Did anyone with a Synology NAS figure out how to configure the DNS Server app properly as a workaround here?   Messed a bit with the settings, but can't find the magic config that allows my domain name (or even the DDNS name) to be accessible from within my network.  It's crazy that this still is not supported.

    • derelk
    • 6 yrs ago
    • Reported - view

    +1 for NAT loopback/hairpinning. It's really sad that you don't support this when every cheapo $50 router has for 15+ years. Makes me regret my purchase, looking at Google's now instead.

    • PageRR
    • 6 yrs ago
    • Reported - view

    This is a repost from another commenter that I totally agree with. "+1 for NAT hairpin.  It is ridiculous to require either an internal DNS server or additional hardware (separate router) to enable this functionality.  I bought Eero because I was tired of having a router I needed to reconfigure, troubleshoot & restart all the time, and refuse to add that back in to the mix.  

    The smart home becomes dumb, and the camera system becomes overly complex for any non technical person (my wife) to connect to." 

    • jsclayton
    • 6 yrs ago
    • Reported - view

    +1 for the feature that, as others have pointed out, almost every other router supports. I'm otherwise happy with the Gen 2 hardware, especially the beacons, but now I have to setup an internal DNS server to access my computers, cameras, and other smart devices the same at home as away.

    • jdd68
    • 6 yrs ago
    • Reported - view

    Another vote for NAT hairpin.  If it is such a security risk, why does every other router manufacturer have it enabled.  I cannot return my eeros as they are 6 months old.  I would like to, after seeing the company fail to enable this feature despite about 100 replies to this thread.

    I was having trouble connecting to my iMac 2017 inside of my home wifi when using Screens Connect.  Had to contact tech support at Edovia, who sent me over to this thread.  If Bonjour stops working (for whatever reason) then the secondary connection method Screens uses is refused by eero router because of this hairpinning issue.

    So, eero----please get it together and enable this.

     

    Thanks

    • GiancarloGomez
    • 6 yrs ago
    • Reported - view

    Another vote from me as well! I wish I would have read this before buying, took a lot for me to finally give in and get rid of my Apple Extreme Base station setup. 

     

    Please eero, add this feature ASAP, I am on the fence and really considering just returning them.

      • Konolua
      • 6 yrs ago
      • Reported - view

      GiancarloGomez I'd suggest returning them. You could always buy them again. Try AmpliFi HD. Very very highly rated. Personally I went Ubiquiti AP and I couldn't be happier. You could use your Apple router and get two or three UAP-AP-Pro devices for cheaper than Eero and have FAR better coverage.

       

      AmpliFi is easier to deploy though. 

       

      Good luck!

      • GiancarloGomez
      • 6 yrs ago
      • Reported - view

      Thank you Konolua 

      I did consider AmpliFi and Orbi during my purchase and went with Eero because I bought the latest version and I preferred them aesthetically. But I think I might just go thru the return and replace nightmare.

      • Luc
      • 6 yrs ago
      • Reported - view

      GiancarloGomez Eero left this thread a while ago. They'll never implement this feature. Just return them while you can!

      • GiancarloGomez
      • 6 yrs ago
      • Reported - view

      Luc Thanks Luc, I am looking at an Orbi review and I have always liked Netgear, so I think I might go that way.

    • GiancarloGomez
    • 6 yrs ago
    • Reported - view

    Off to BestBuy to pick up my Orbi and sending these Eero's back today. What a shame.

      • russwittmann
      • 6 yrs ago
      • Reported - view

      GiancarloGomez I went with google wifi and it works great.  I returned my units right after I saw that this thread was many months old.  I wish eero the best though, its just not a product for me.

    • jt777
    • 6 yrs ago
    • Reported - view

    Go to the Netgear Orbi forum and see how that is going...from there to here...

    • Konolua
    • 6 yrs ago
    • Reported - view

    Amazon has the AmpliFi HD on sale: https://goo.gl/2A1Rrz

    Here is the UAP-Pro: https://goo.gl/DFPzVn

    And Google WiFi is on sale too!!!!: https://goo.gl/uji3Yf

    I have not heard the best stuff about the Orbi, though performance wise, it seems to be solid.

    • Arvoreen
    • 6 yrs ago
    • Reported - view

    One more +1 for this feature.  It is really hard to believe that it isn't supported yet, even though the cheap ass d-links & linksys routers do....

    • Jayva2002
    • 6 yrs ago
    • Reported - view

    +1. This is a basic feature needed for any router.  Please implement. Thanks!

    • aharrod
    • 6 yrs ago
    • Reported - view

    +1.  Only issue as far as I can tell.  I have 45 day return where I purchased, so going to monitor this thread closely.

      • usr2284a
      • 6 yrs ago
      • Reported - view

      aharrod  this thread is almost a year old.  They have no plans to add it.  It won’t be added in the next 45 days, that’s for sure.

    • dcarr
    • 6 yrs ago
    • Reported - view

    +1!  This seems like a major omission for a router with home automation in it's infancy.  This missing feature is becoming more and more important by the day.  Eero, please add this feature ASAP!

    • go_robot_go
    • 6 yrs ago
    • Reported - view

    Just came back to say that the wait for hairpinning has become too much for me, and I ended up replacing my eero system with something that cost less and gives me not only hairpinning, DMZ, and QoS, but also gives me better coverage and throughput than eero did. I'll be resetting my eero units and selling them off to someone else who demands far less from their wireless router.

      • Honus
      • 6 yrs ago
      • Reported - view

      go_robot_go Love to hear what you ended up going with.

Content aside

  • Status Implemented
  • 49 Votes
  • 2 yrs agoLast active
  • 161Replies
  • 11147Views
  • 66 Following