VPN & Firewall - does not work together

When I turn the firewall on using my local network using the automatic setting "Block all incoming connections", I still can use the machine to surf the net, use sharing services, etc. etc.

If I connect to a dial-up service like HDSPA/UMTS with Firewall on, everything is ok too.

But if I am now connecting to my company network using VPN (PPTP, built in client), the machine refuses to connect to my DNS server. I can ping a Machine inside the VPN Network - including the DNS Server, but all DNS lookups are refused.
The DNS server is inside the VPN. The /etc/resolv.conf is correct. VPN is set to "Send all traffic over the VPN".

The only quick way to solve this, was turing the firewall off.

I do not understand why this does not work as advertised. A DNS lookup is no "incoming" Connection.

Even, if I suspect it is not a big risk to have the firewall off when I turn off all sharing services, it is safer to have it on, if I use unknown networks.

And even, If I have to turn off the Firewall, it must be possible to do that on a per Network connection base.

A normal user is not able to decide, when to turn the FW off or on. If he decides to turn it on, he should still be able to acess the net.

Dual 2GHz G5

Posted on Nov 12, 2007 2:59 AM

Reply
5 replies

Nov 12, 2007 3:55 AM in response to DaddyPaycheck

I am using the build in Firewall of the OS.

From my point of view, If I have a connection to the remote Network using VPN, and if I can ping a device inside, which is the case, the Firewall seems to be configured correct for VPN.

What happens here, is, that the OSX 10.5 Firewall blocks outgoing connections, which it should not do in any case.

Nov 12, 2007 4:48 AM in response to DaddyPaycheck

To make PPTP work, you need to allow outgoing traffic to port 1723, also GRE Protocol 47 must be allowed.
But, again:
I can establish a connection. This is not the problem.
If the 10.5 Firewall would not allow this traffic, then, no Connection can be established.
The VPN Device is a draytek 2910. It works with all other client, so, I know I can trust it.

After the connection has been established, The 10.5 Firewall must allow outgoing connections TCP & UDP to port 53 to query the DNS server.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

VPN & Firewall - does not work together

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.