4 Replies Latest reply: Jan 8, 2014 2:08 PM by jypsilantis
dieseldennis Level 1 Level 1 (0 points)

how do i configure my new airport extreme to make it connect to my vpn directly...... so all incoming and outgoing data is sent to the vpn. thx. the guy at the store it was possible...... but i cannot see how yet.

  • Tesserax Level 8 Level 8 (49,860 points)

    The AirPort Extreme is a VPN "passthrough" device. It is neither a VPN server or VPN end-point. In order to use VPN with your Extreme you would, as a minimum, need a VPN client on your computer and a VPN server at the desired location to connect to.

  • dieseldennis Level 1 Level 1 (0 points)

    I want to use it as a tunnel. Must I jailbreak it? Any other way? I would like to set it up simular to a ddwrt setup.

  • Tesserax Level 8 Level 8 (49,860 points)

    A tunnel is the same as passthrough. There is nothing to jailbreak.


    As far as DDWRT, the AirPorts are not a DDWRT-supported device. Sorry!

  • jypsilantis Level 1 Level 1 (0 points)

    I can successfully established a tunnel to my endpoint device behind Airport's firewall (an Astaro firewall), by either opening up the relevant VPN ports or (more simply) making the Astaro the "default device" for any unsolicited incoming connections.


    However, the tunnel is unusable because it is not possible to establish static routes on the Airport. VPN tunnels on the Astaro allocate addresses on specific subnets to the endpoints, and these subnets are (bu necessity) different to the default LAN subnet that the Airport implements. I can see incoming communications (remote machine->tunnel->Airport->Astaro->node on the LAN) but the LAN node has no way of communicating back, because it does not know that it needs to route the reply back via the Astaro, instead of the Airport.


    It follows that the only way to allow full communication over VPN is to set up static routes on the Airport describing the Astaro's VPN subnets, and routing to those subnets via the Astaro.


    I believe that this is a generic issue, not necessarily limited to Astaro. Other VPN endpoints and servers would no doubt suffer the same problem.


    I am sure that the Airport is capable of static routes, being based on the BSD networking and firewall kit, but for some reason Apple has not exposed this as a configuration option.


    I have a number of clients who operate small home offices and require VPN access, some of which already use Airport. I cannot recommend Airport for their installations because of this shortcoming, and in some cases it has been necessary to decommission the Airport infrastructure and use Cisco/Linksys instead. It is very unfortunate because in all other respects, Apple has done its usual excellent job in making the system easy to administer and maintain.


    Apple, please, PLEASE, PLEASE implement static routes  as an "Advanced" configuration option for all Airport devices! This should be a relatively simple thing to do.