Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: kvk2026.quickconnect.to
I ran this command: N/A
It produced this output: No response from the destination server. Please try again later.
My web server is (include version): ?
The operating system my web server runs on is (include version): DSM 7.4
My hosting provider, if applicable, is: Summit Broadband
I can login to a root shell on my machine (yes or no, or I don't know): Yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): N/A
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): ?
Using my Ubiquiti equipment, after a recent update from the ISP, I have been put on CGNAT. So no port forwarding and I get the above message. If I use the ISP supplied router, I am not on CGNAT. I can port forward but get the above results. I have little control over their router and have found no way to get a certificate from you for my quickconnect and my DDNS through Synology.
Because as I understand it quickconnect is a connectivity service they provide. They manage the certs and comms between a user-agent (like a browser) and your system. I don't believe you would use a Let's Encrypt cert and not sure you even can given the nature of quickconnect.
For example, that kvk2026 domain name is currently served by CloudFront which is an AWS Service. This is probably the underlying tech that Synology uses for this. Synology is the best place for your problem.
Thanks for your reply. This is my 3rd Synology that I've had since 2014. I've always been automatically provisioned with a Let's Encrypt quickconnect certificate through their GUI. With this new Synology, I cannot get a certificate for either the quickconnect or the DDNS through Synology, getting the same error message for both.
I have called them. I could barely understand the individual I spoke with. I was able to gather that his answer was that you can connect to your new NAS, so what is the problem? I bailed out, seeing that I was getting nowhere.
I can submit a trouble ticket with Synology and that may be a better option.
I don't see any Let's Encrypt cert issued for that domain name in the past year.
The error you show isn't coming directly from Let's Encrypt. It sounds more like an outbound connection problem rather than inbound. If so that's likely some kind of comms, firewall, or config problem on your end. For Synology domain names they usually use a DNS Challenge so even if LE that wouldn't be sending your system any validation requests.
I have seen references to a DNS Challenge in some of my searches. That's beyond my scope of knowledge and don't misunderstand, I am not asking for an explanation. Thanks for your help MikeMcQ. I appreciate the quick replies.
How Quickconnect works is the kvk2026.quickconnect.to (hosted by Synology) tries to detect connectivity, and redirect to either kvk2026.<code>.quickconnect.to, if they decided to route through tunnelling servers (again hosted by Synology), or e.g. 192-0-2-1.kvk2026.direct.quickconnect.to, if direct connectivity possible.
So, the certificate seems to be fine. What you should focus on is to configure your Unifi router, so you don't get CGNAT. Contact your ISP for help. Firewall rules might also be in a way too. This is out of scope of this forum, though.
Thanks for the reply. I now have a ticket ongoing with Synology in regards to the certificate. I can't associate it with any service without it being present in the nas. It's out there but only they can tell me how to get it where it needs to be. It's good to know that it's been provisioned.
The "quickconnect" certificate can only be used with several (not all) Synology services. If you want to use with websites or Docker, you'll need to use DDNS and have routeable IP.
Scratch that. Seems <ip>.<username>.direct.quickconnect.to simply points at public IP.
Reading docs, it also mentions the "relay service" is a toggle in settings. Go check it out whether you disabled it.
Had a similar issue many years ago which turned out to be an ISP issue.
They had put me on CGNAT (Carrier-Grade NAT), which meant I had a public IPv4 address and no inbound port forwarding.
Got it working in the end. But I came here to ask if you have tried a service such as Tailscale instead of QuickConnect? I switched this year from QuickConnect to TS and found the setup and integration very simple.
CGNAT is my issue also. My ISP informed me of some overnight "maintenance" and the next day I eventually noticed that my WAN IP was in the 100.xxx.xxx.xxx range - CGNAT. Port checker websites confirmed it for me yesterday. I did a bit of switching out hardware between what my ISP supplied and my own yesterday seeing if I could circumvent it. That, because with my ISP hardware in place, It showed that I had an IP in the 66.xxx.xxx.xxx range. That's the short version of a long story.
I have played around with Tailscale in the past. My Ubiquiti gateway has Teleport built in which functions very similar and that may be what I end up using. I am going to explore the cost of a static IP with my ISP. Who knows, I may be willing to pay for one.
Good to hear you're getting there.
Just FYI on the TailScale install. Although connections run over https://, you'll see insecure messages in the browser.
You probably already know this as you seem more technical than me but in casem here's the info: