Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Lion Server VPN, Can Connect Locally, Not Remotely

I have both Lion and Lion Server installed on my Core 2 Duo iMac, mainly because I want the VPN feature of Server.


I configured everything correctly for the VPN, and can connect to it with no problems from my iPhone and iPad when I am within my own LAN (the server and the iPhone/iPad are on the same IP range and subnet).


I also used the automatic config within the Server app to configure my AirPort Extreme N Base Station. Looking at the Port Mapping section of my ABS from within AirPort Utility, I do in fact see that VPN Service (L2TP) is configured with the following UDP ports: 500, 1701 and 4500. Those ports ARE pointing to the iMac that is running the VPN server. Firewall on that iMac is turned OFF.


However, I am unable to connect my iPhone to the VPN Server using my Public IP address. I have tried it from within my network (out of network to internet the back), from my Verizon MiFi or from my iPhone's 3G connection (well, in my area it is still Edge). The iPhone simply sits on "Connecting" for a few seconds, then an alert comes up stating "The L2TP-VPN server did not respond. Try reconnecting. If the problem..." yadada.


I AM, however, able to get Web Sharing to work via my Public IP address, as well as VNC.


I also cannot connect to the VPN via the Public IP with other devices like my iBook, PowerBook G4, Windows 7 PC, or iMac G5. They ALL CAN connect via the local network 10.1.x.x IP address.


Am I missing something here? I did all of the automatic configurations, and all of the ports appear to be properly open.

iMac, Mac OS X (10.7)

Posted on Jul 20, 2011 9:59 AM

Reply
70 replies

May 4, 2012 7:27 AM in response to JWCombs65

I'm running Lion Server 10.7.3, and it is connected to an AEBS running 7.6.1. I have forwarded the VNC port on my AEBS, so I can screen in and watch my server as I try to connect. I open vpnd.log in Console, and when I try to connect, there is no activity in that log file, suggesting that my request never even makes it to the server.


According to the Server App, VPN is on (it has a green light) and is configured for L2TP.


Here are my network settings in Server Admin:

User uploaded file


FYI: I am using dyn.com to map a domain to my router's public facing IP.


Any help is greatly appreciated!

May 4, 2012 8:03 AM in response to JWCombs65

VPN (L2TP)

Public UDP:500,1701,4500

Private UDP:500,1701,4500


VPN (PPTP):

Public TCP: 1723

Private TCP:1723


I am looking at the Mobile Me tab in Airport Utility and it's empty, so I assume that is correct. System Preferences on the server shows Back to My Mac is disabled (because an iCloud account is active). I am looking at iCloud in System Preferences and Back to My Mac is unchecked there.

May 4, 2012 8:30 AM in response to Dan Pouliot

Those are the right ports...and I know it shouldn't make any difference, but what worked for me was deleting the existing mappings that matched yours and creating new ones using the ones named "OS X Server VPN -".


Since you mention the MobileMe tab I have to assume your not using the latest Airport Utility. Get version 6 and delete the existing mappings. The new mappings in which each port has it's own individual mapping will then be availiable to select.


User uploaded file

May 4, 2012 9:23 AM in response to JWCombs65

I have both Airport Utilities, I figured I needed the old one to see mobileme.

Interesting that the new utility has "Mac OS X Server VPN" as choices for port mappings, that is news to me!


Out of curiosity, when I select "Mac OS X Server VPN - L2TP" it auto-populates only 1701. I am adding 500 and 4500. I hope that is right. (I wish they would make the port mapping pane in the network tab more than 2 rows high!)


Updated router, still no luck. as an added measure, I created a new VPN.mobileconfig from the server, and installed it on my remote Mac. I got the same "The L2TP-VPN server did not respond." and no new entries in vpnd.log. It would be nice if the AEBS had a log that I could see if the request made it that far.

May 4, 2012 2:40 PM in response to Dan Pouliot

The http://macminicolo.net/lionservervpn instructions I think is a good starting point for setting up your VPN but it is a little dated since the new Lion server (10.7.3) is a little different in some spots. All in all though it is a great reference and the rest is up to you. The following pic is what I have opened on my router, keep in mind I pay for a static IP so the ports are not blocked by my cable provider.


User uploaded file

Lion Server VPN, Can Connect Locally, Not Remotely

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.