Can't access Paperless-ngx via VPN
from StreetKid@reddthat.com to selfhosted@lemmy.world on 10 Dec 21:00
https://reddthat.com/post/55887254

Hi, I have a problem accessing Paperless-ngx when I’m connected to my home network from a VPN. I’ve tried to make a simple sketch of my setup: Phone --> Wireguard --> Public Internet --> Unifi Wireguard server --> Home Network

Paperless-ngx is hosted on my server at 192.168.1.10:8000 But I can easily access all other services hosted on my server (192.168.1.10), e.g. homer (:8888) and Immich (:8080). It is just Paperless-ngx which doesn’t work.

When at home and connected to my home WiFi I can also access Paperless-ngx.

Anyone having ideas to figure out, what is wrong in my setup? Or how to debug?

#selfhosted

threaded - newest

Brkdncr@lemmy.world on 10 Dec 21:08 next collapse

Ping,Tracert,Knock on the port with Telnet.

I’m guessing firewall rules related to your vpn.

StreetKid@reddthat.com on 10 Dec 21:29 collapse

Ping and traceroute are both successful. The IP is not the issue (I think), as all other services on the same server are working fine According to unifi firewall logs, nothing gets blocked when I attempt to access Paperless-ngx.

Brkdncr@lemmy.world on 11 Dec 01:38 collapse

Can you hit the port?

frongt@lemmy.zip on 10 Dec 21:09 next collapse

What’s in the logs?

StreetKid@reddthat.com on 10 Dec 21:31 collapse

Nothing in Unifi firewall logs nor Paperless-ngx logs. I’m using standard zones based a firewall rules in Unifi. And I looked through the firewall rules, and I don’t find anything related to port 8000.

StreetKid@reddthat.com on 10 Dec 21:49 next collapse

It must be a Paperless-ngx specific issue. Stopped Homer service available on :8888 and changed Paperless-ngx to be served on :8888 and it still doesn’t work. This rules out firewall and network issues as Homer was accessible on this port.

oxfordcoma@lemmy.world on 10 Dec 22:27 next collapse

I’m not familiar with paperless but do you have PAPERLESS_BIND_ADDR set? maybe try to set it to 0.0.0.0

spaghettiwestern@sh.itjust.works on 11 Dec 02:49 collapse

Your WG network is a separate subnet. Add it to PAPERLESS_ALLOWED_HOSTS to allow access.

StreetKid@reddthat.com on 11 Dec 05:26 collapse

Without having time to test it yet, I think this is the issue.