Can't access Paperless-ngx via VPN
from StreetKid@reddthat.com to selfhosted@lemmy.world on 10 Dec 13:00
https://reddthat.com/post/55887254

Hi, I have a problem accessing Paperless-ngx when I’m connected to my home network from a VPN. I’ve tried to make a simple sketch of my setup: Phone --> Wireguard --> Public Internet --> Unifi Wireguard server --> Home Network

Paperless-ngx is hosted on my server at 192.168.1.10:8000 But I can easily access all other services hosted on my server (192.168.1.10), e.g. homer (:8888) and Immich (:8080). It is just Paperless-ngx which doesn’t work.

When at home and connected to my home WiFi I can also access Paperless-ngx.

Anyone having ideas to figure out, what is wrong in my setup? Or how to debug?

#selfhosted

threaded - newest

Brkdncr@lemmy.world on 10 Dec 13:08 next collapse

Ping,Tracert,Knock on the port with Telnet.

I’m guessing firewall rules related to your vpn.

StreetKid@reddthat.com on 10 Dec 13:29 collapse

Ping and traceroute are both successful. The IP is not the issue (I think), as all other services on the same server are working fine According to unifi firewall logs, nothing gets blocked when I attempt to access Paperless-ngx.

Brkdncr@lemmy.world on 10 Dec 17:38 collapse

Can you hit the port?

frongt@lemmy.zip on 10 Dec 13:09 next collapse

What’s in the logs?

StreetKid@reddthat.com on 10 Dec 13:31 collapse

Nothing in Unifi firewall logs nor Paperless-ngx logs. I’m using standard zones based a firewall rules in Unifi. And I looked through the firewall rules, and I don’t find anything related to port 8000.

StreetKid@reddthat.com on 10 Dec 13:49 next collapse

It must be a Paperless-ngx specific issue. Stopped Homer service available on :8888 and changed Paperless-ngx to be served on :8888 and it still doesn’t work. This rules out firewall and network issues as Homer was accessible on this port.

oxfordcoma@lemmy.world on 10 Dec 14:27 next collapse

I’m not familiar with paperless but do you have PAPERLESS_BIND_ADDR set? maybe try to set it to 0.0.0.0

spaghettiwestern@sh.itjust.works on 10 Dec 18:49 collapse

Your WG network is a separate subnet. Add it to PAPERLESS_ALLOWED_HOSTS to allow access.

StreetKid@reddthat.com on 10 Dec 21:26 collapse

Without having time to test it yet, I think this is the issue.