EQII and Firewalls

No holds barred discussion. Someone train you and steal your rare spawn? Let everyone know all about it! (Not for the faint of heart!)

Moderator: TheMachine

Post Reply
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

EQII and Firewalls

Post by Rivera Bladestrike »

Alright, I just started trying to download EQII and its being a major pain in the ass. I live on a campus and I just read that EQII doesn't work with campus firewalls or something along those lines.
Sony Online Entertainment does not support the use of firewalls and proxies, including cable/DSL NAT routers, campus and office networks, or any type of Internet connection sharing services. However, in an effort to assist you in configuring your systems on your own, we would like to provide the following information which may help you in setting up your firewall to work with EverQuest II.
I've done router configurations by changing the UDP and TCPs but I don't have anything like that on my computer.

Pisses me off cause I have the whole weekend to play and I just got it and AS USUAL something ALWAYS fucks it up and I wind up spending tireless hours working on this shit.

So any help is much appreciated!
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
Zaelath
Way too much time!
Way too much time!
Posts: 4621
Joined: April 11, 2003, 5:53 am
Location: Canberra

Post by Zaelath »

To paraphrase; Sony isn't going to spend hours helping you work out why you can't get your POS firewall to work with EQ. If your employer/school/mother wants to block EQ, tough shit. This is not our problem, and we're not going to support it. However, none of that means you can't use EQ behind NAT connections or firewalls.
May 2003 - "Mission Accomplished"
June 2005 - "The mission isn't easy, and it will not be accomplished overnight"
-- G W Bush, freelance writer for The Daily Show.
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

That can't be the answer though, to cut off every single kid in a college campus would be ridiculous.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
Zaelath
Way too much time!
Way too much time!
Posts: 4621
Joined: April 11, 2003, 5:53 am
Location: Canberra

Post by Zaelath »

Rivera Bladestrike wrote:That can't be the answer though, to cut off every single kid in a college campus would be ridiculous.
They're not. If your campus doesn't allow the traffic, your campus is cutting you off. If you have a normal NAT/firewall connection, which allows all outgoing traffic, you won't have an issue.
May 2003 - "Mission Accomplished"
June 2005 - "The mission isn't easy, and it will not be accomplished overnight"
-- G W Bush, freelance writer for The Daily Show.
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

I know people who are playing other MMORPGs around here though...
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
Mr Bacon
Way too much time!
Way too much time!
Posts: 2108
Joined: September 27, 2002, 4:57 pm
Location: Down the street
Contact:

Post by Mr Bacon »

Talk to them and say 'hey what do i do?' and you'll probably find the answer. just ask.


P.S. There's heavy firewall crap here on my campus but I connected to EQ2 fine.
miir and I are best friends. <3
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

Talk to who? EQII guys or my university tech?

I was thinking of talking to my computer science professor after class on tuesday (hes a big gamer too)...
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
Neost
Almost 1337
Almost 1337
Posts: 911
Joined: July 3, 2002, 1:56 pm
Gender: Male
XBL Gamertag: neost
Wii Friend Code: neost
Contact:

Post by Neost »

Normally any firewall/proxy setup that allows internet access will allow outbound IP's to establish a session and any incoming traffic associated with that outbound session is allowed through.

So it's like if you send a request out to login to EQ, it allows return traffic from the login server because you initiated the conversation, there is an expected traffic flow back to you.

Then, once you authenticate to the login server, the EQ client initiates a conversation with your world server (or whatever), so once again the campus firewall would allow traffic back to your PC.

If you know anything about networks, you might try running ethereal on your local box while you connect and then check the packet capture to see if you are seeing the responses all the way back to your pc.

That way you know if the issue is with the network between you and EQ or local to your pc.
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Actually on the campus I work at, the university is blocking some TCP and UDP ports that are commonly associated with virus traffic. At one point, they had TCP 5000 blocked, which killed Yahoo instant messenger and Lineage.

As far as your statement that they can't block something... LOL (I'm laughing at you here, but not really in a mean spirited way so don't take it personally).

They absolutely can. Many universities are completely shutting off all P2P apps, as well as a lot of known virus ports. They're not doing it specifically to block their students from playing games etc. But mostly to reduce the traffic load, stay out of trouble with those enforcing the DMCA (Digital Millineum Copyright Act), and keep the university network running for its intended purpose... education.

The best thing to do is to find out what TCP/UDP ports EQ2 uses to connect to the servers, and then go ask your student help desk/network help desk whether or not those ports are being blocked. There's a chance they're blocking a port you need for something that's no longer a threat, and maybe they can turn it back on for you.
Oh, my God; I care so little, I almost passed out.
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

I meant EQII blocking anything not the univeristy. I ran the ethereal program, and not one packet was capture with and without the firewall on in my computer. So I'm betting on the uni's firewall, which i had suspected mostly.

They have a number of things here:

EverQuest II LaunchPad and Patch Servers
A TCP connection is initiated from the LaunchPad client port > 1023 to patch.station.sony.com port 7000.

A UDP connection is initiated from the LaunchPad client port > 1023 to sdlaunchpad1.station.sony.com and sdlaunchpad2.station.sony.com port range 3016-3021 and 9700-9703.

EverQuest II Patch:

A TCP connection is initiated from the EverQuest II client port > 1023 to patch.everquest2.com port 7010.

EverQuest II Game Client
UDP connections are initiated from the EverQuest II client port >1023 to servers on UDP ports 9100, and UDP ports in the range 32800-33000

Additionally, ICMP messages type 0 (echo reply), 3 (unreachable), 8 (echo request) and 11 (expired) should be permitted bi-directionally between the client PC and the EverQuest II servers.

EverQuest II Servers Subnets

There are multiple IP addresses for the Patch and LaunchPad clusters, and they may change as the network demands, so check often using a DNS lookup tool if you provide a specific firewall rule for these services. The EverQuest II server IP addresses are currently in these subnets: 64.37.158.*, 199.108.2.*, 199.108.12.*, 199.108.202.*, 199.108.203.*, 195.33.135.*
I'm not the best at this networking stuff, i only know what I had to learn the hardway cause my computer never fucking work the way they're supposed to, and I wind up spending 4 hours or more on something angry and pissed off. But as far as I know, I look into my firewall and I can't open up a lot of these ports that they're asking here. Like my router back at home had a easy configuration window, but I don't know what the hell I'm doing here.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Wouldn't surprise me at all to find out they're blocking ICMP in one direction or another.

There are quite a few DOS style attacks that use ICMP.

The rest of it basically just says they use ephemeral port numbers which is no great suprise.
Oh, my God; I care so little, I almost passed out.
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

the only place I have to change the UDP and TCP is in the firewall I got with Service Pack 2, and it doesn't allow ranges, so I just typed the lowest of the two. I know its horribly wrong, but I got no idea what else.

My only savior is acquiring FarCry just a few minutes ago.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Just disable your firewall completely and test it. Don't even bother trying to set a range until you know your firewall is the problem.
Oh, my God; I care so little, I almost passed out.
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

I already tried that.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

If you disabled your firewall entirely, the problem is within your university's network, and no amount of playing with your firewall will resolve it.
Last edited by noel on October 23, 2004, 5:38 pm, edited 1 time in total.
Oh, my God; I care so little, I almost passed out.
User avatar
Lohrno
Way too much time!
Way too much time!
Posts: 2416
Joined: July 6, 2002, 4:58 pm
Location: California
Contact:

Post by Lohrno »

I wonder if it's possible to use some proxy tricks...

-=Lohrno
User avatar
Mr Bacon
Way too much time!
Way too much time!
Posts: 2108
Joined: September 27, 2002, 4:57 pm
Location: Down the street
Contact:

Post by Mr Bacon »

Check with that professor or the other students playing mmog's (which is who i was referring to above)
miir and I are best friends. <3
User avatar
Kaldaur
Way too much time!
Way too much time!
Posts: 1850
Joined: July 25, 2002, 2:26 am
Gender: Male
XBL Gamertag: Kaldaur
Location: Illinois

Post by Kaldaur »

Rivera, I have the same problem due to my college network. Unless I am consistently interacting with the world (changing direction, saying something, using new techniques) then I lag due to the network. Combine that with Antonica lag, and it's very hard for me to play. I'm currently "negotiating" (see threatening) with ITS to reopen the ports, and a few of them are being opened up. The problem is EQ2, from my understanding, connects to random ports every time it establishes a connection, so opening a few ports here and there won't solve the problem.
User avatar
murr
Almost 1337
Almost 1337
Posts: 525
Joined: July 5, 2002, 5:55 pm
Location: Chapel Hill, NC

Post by murr »

Just for reference, by default, SP2 (or the firewall, at least) disables ICMP. But it doesn't look like that is the problem.
Murr - Fires of Heaven - Black Dragonflight
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

Thanks for the help, i'll talk to my professor, he should know, he knows just about everything about the campus' network.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
Xanastik Fox
Gets Around
Gets Around
Posts: 54
Joined: October 28, 2002, 11:03 pm

Post by Xanastik Fox »

Copy/Paste from betaboard

Sony Online Entertainment does not support the use of firewalls and proxies, including cable/DSL NAT routers, campus and office networks, or any type of Internet connection sharing services. However, in an effort to assist you in configuring your systems on your own, we would like to provide the following information which may help you in setting up your firewall to work with EverQuest II.

EverQuest II LaunchPad and Patch Servers
A TCP connection is initiated from the LaunchPad client port > 1023 to patch.station.sony.com port 7000.

A UDP connection is initiated from the LaunchPad client port > 1023 to sdlaunchpad1.station.sony.com and sdlaunchpad2.station.sony.com port range 3016-3021 and 9700-9703.

EverQuest II Patch:

A TCP connection is initiated from the EverQuest II client port > 1023 to patch.everqeust2.com port 7010, and ablpatch.everquest2.com port 7010.

Everquest II Game Client
UDP connections are initiated from the EverQuest II client port >1023 to servers on UDP ports 9100, and UDP ports in the range 32800-33000

Additionally, ICMP messages type 0 (echo reply), 3 (unreachable), 8 (echo request) and 11 (expired) should be permitted bi-directionally between the client PC and the EverQuest II servers.

EverQuest II Servers Subnets

There are multiple IP addresses for the Patch and LaunchPad clusters, and they may change as the network demands, so check often using a DNS lookup tool if you provide a specific firewall rule for these services. The EverQuest II server IP addresses are currently in these subnets: 64.37.158.*, 199.108.12.*, 199.108.13.*, 199.108.202.*, 199.108.203.*, 195.33.135.*
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

Yeah, I already quoted that above, will talk to the network administrator and my professor on tuesday about it, possibly offer donuts in return of access to crack.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

Awesome! Wooohoo! They had me set up a VPN and now I can get into EQII!
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Did they tell you what/why they were blocking something?

I'm curious from a professional standpoint. If you can find out, I'd appreciate it.

Thanks in advance.
Last edited by noel on October 26, 2004, 3:06 pm, edited 1 time in total.
Oh, my God; I care so little, I almost passed out.
User avatar
Rivera Bladestrike
Way too much time!
Way too much time!
Posts: 1275
Joined: September 15, 2002, 4:55 pm

Post by Rivera Bladestrike »

They didn't tell me why they were blocking it, but they said that it was "impossible" for them to change any of the firewall's ports.
My name is (removed to protect dolphinlovers)

Rivera / Shiezer - EQ (Retired)

What I Am Listening To
Post Reply