Q: Ports suddenly appearing as closed when they are open.
Hi all,
I recently set up a Server on 10.11. I am using Profile Manager and VPN form outside the network.
I forwarded all the necassary ports, and that all worked fine, then about a week later Profile Manager stopped appearing under 'Reachable'. I checked the ports with canyouseeme.org and they were reported as 'closed'. They are open on the firewall.
Then a week later VPN dropped from 'Reachable'.
I ran some packet captures and found that the traffic was going into the LAN and being rejected by the server.
Can anyone think of any suggestions on why the traffic is being rejected?
Thank you.
iMac, OS X El Capitan (10.11.4), Server
Posted on Apr 20, 2016 7:55 AM
Lots of possibilities. I would initially do a port-scan test on your LAN to the server, if this shows the ports are indeed closed it would likely be down to an issue on the server itself, if the ports are shown as open which as you say the services work on the LAN is likely to be the case then it would suggest the problem is either not on the server itself or the server is configured to only allow traffic from the LAN. Network Utility can do simple port-scans.
- Check the network settings on the server, especially the default gateway
- Check the port forwarding rule in your router is still pointing to the correct destination, as your server should have a static IP address in theory it should but it is worth checking
- Check to see if the Firewall is turned on in System Preferences -> Security & Privacy, if on you could temporarily turn it off to test
- Check to see if the Adaptive Firewall (not the same as above) is turned on, see How to enable the adaptive firewall on OS X Server - Apple Support again if it is on try turning it off temporarily
- Check to see if the pf firewall is running, again temporarily disable if running, the process for enabling pf under El Capitan seems to be more complex and Apple's instructions wrong due to SIP, see https://groups.google.com/forum/#!topic/macenterprise/AI5KYpPugRY
- If the Profile Manager server is also a VPN server you might have followed a setup like the one provided by MacMiniVault see https://github.com/MacMiniVault/Mac-Scripts/blob/master/vpnscript/vpnscript-READ ME.md this adds a VLAN to the server and in order for that to work also setups network forwarding rules, this could have upset things and certainly also requires adding a Static IP route to your router
Posted on Apr 21, 2016 6:25 AM
