eribble

Q: VPN giving me fits.  Help.

Had to do some things with my trudty mac mini that forced me to just start fresh with the OS install.  I am trying to get the VPN services back up and not having any luck. 

 

I am able to connect to the VPN from inside my home, but when coming from the outside, no luck.

 

What are the things I can troubleshoot?  When I connect internally, I can verify the traffic is routed through the server and out to the internet.  I watch the logs and see myself connect.  I have forward the proper ports (500, 1701 and 4500) to the internal IP.  When I try to connect to the server from the outside (via my iPhone) nothing hits the logs.  I use the no-ip dydns service and am able to hit the web server using the no-ip address, so I know I'm showing up out on the internet.

 

Since I am showing up on the logs when trying to access from the outside, I figured it was a port forward issue, but I verified everything is on the airport extreme (and was in there prior to the reinstall).

 

So I'm sort of at a loss...  Any ideas?

Mac mini, OS X Server

Posted on Oct 13, 2013 3:30 PM

Close

Q: VPN giving me fits.  Help.

  • All replies
  • Helpful answers

Page 1 Next
  • by Linc Davis,

    Linc Davis Linc Davis Oct 13, 2013 5:55 PM in response to eribble
    Level 10 (208,037 points)
    Applications
    Oct 13, 2013 5:55 PM in response to eribble

    To run a public VPN server, you need to do the following:

    1. Give the gateway either a static external address or a dynamic DNS name. The latter must be a DNS record on a public DNS registrar, not on the server itself. Also in the latter case, you must run a background process to keep the DNS record up to date when your IP address changes.

    2. Give the VPN server a static address on the local network, and a hostname that is not in the top-level domain "local" (which is reserved for Bonjour.)

    3. Forward external UDP ports 500, 1701, and 4500 (for L2TP) and TCP port 1723 (for PPTP) to the corresponding ports on the VPN server.

    4. Configure any firewall in use to pass this traffic.

  • by eribble,

    eribble eribble Oct 13, 2013 7:08 PM in response to Linc Davis
    Level 2 (220 points)
    Oct 13, 2013 7:08 PM in response to Linc Davis

    OK, so doing some more investigating, something is hosed on the port forward side.  L2TP isn't working, but PPTP is.  Also, while looking into things more, the server admin port of 311 isn't working either, but NOTHING changed on the airport extreme from a day or two ago to this morning.  Could seomthing be screwed up on the server?  Again, I know the port forwarding is done right, but when I watch the logs, nothing shows up on the L2TP connection.  And when I check with an external URL to see if the ports are open, it says they are closed.

     

    Some do work, like 80 and 443 and 1723.  But 311, 500, 1701 and 4500 are not!

     

     

    hmmmm

  • by haykong,

    haykong haykong Oct 13, 2013 8:08 PM in response to eribble
    Level 1 (119 points)
    Oct 13, 2013 8:08 PM in response to eribble

    Eribble,

     

     

        There's only a few possiblities for your situation since you mentioned a few days ago VPN was working outside and now it's not working from outside, but only internally on your network.

     

    1) possibility that your airport extreme settings are somehow corupted. Do you have another wireless router to test with?

     

     

    2) What kind of broadband do you have? cable? dsl? residental type? sometimes  residental services from certain ISP do certain port blocking. ... My money is on this perhaps... but who knows...

     

    3) I presume you tried rebooting both your airport extreme and ds/cable modem?

  • by eribble,

    eribble eribble Oct 14, 2013 6:20 AM in response to haykong
    Level 2 (220 points)
    Oct 14, 2013 6:20 AM in response to haykong

    Hey there.  I've tired everything.  Power cycled both the router and cable modem (comcast) and also asked comcast to cycle it on their side.  I am wondering if this something on the mac mini side of things?  I need to poke around more, but I'm super clueless right now. 

  • by haykong,

    haykong haykong Oct 14, 2013 8:49 AM in response to eribble
    Level 1 (119 points)
    Oct 14, 2013 8:49 AM in response to eribble

    I doubt that it has anything to do with your macmini side, but however  we still have to cover all possible problems.

     

    At this point I'm presuming you are using Mac OS 10.8.5 server right?

     

    If you have the adaptive firewall on now.. try turning it off. ... you never know if the server tried to protect itself from the outside.

     

    If that doesn't work, then it's not the adaptive firewall.

     

    By any chance you have another router to test with even a older router like linksys wrt54g.... the reason why I ask is you can always load up on certain wireless routers more advanced software like dd-wrt which gives you more configuration options which can be useful for testing things out.

  • by piperspace,

    piperspace piperspace Oct 14, 2013 8:52 AM in response to eribble
    Level 2 (305 points)
    Oct 14, 2013 8:52 AM in response to eribble

    Just a shot in the dark - but check the time on your devices.

     

    I use OpenVPN and sometimes have trouble with certificate validation when my clocks are wrong. 

  • by eribble,

    eribble eribble Oct 14, 2013 11:18 AM in response to haykong
    Level 2 (220 points)
    Oct 14, 2013 11:18 AM in response to haykong

    I do have another router.  I have two in fact.    Both previous versions of the Airport Extreme.

     

    This may take me some time to get to, as this will require uncabling, moving, etc.  Grrrrrr

  • by eribble,

    eribble eribble Oct 22, 2013 7:46 PM in response to eribble
    Level 2 (220 points)
    Oct 22, 2013 7:46 PM in response to eribble

    Still having this issue having upgraded to Mavericks Server today.   Is anyone having any similar issues?

  • by grumpytorpor,

    grumpytorpor grumpytorpor Oct 22, 2013 11:58 PM in response to eribble
    Level 1 (0 points)
    Oct 22, 2013 11:58 PM in response to eribble

    I am seeing *exactly* the same problem.  I had VPN service working just fine on ML Server for over a year.  I update using the Mavericks GM and it won't work.  Or rather, I can connect internally with OS X (ML) and iOS 7 - no problem.  Connecting through my firewall won't work.  I see the connection attempt in the server logs, but it times out.

     

    I've tried a clean reinstall and manually rebuilding the VPN settings and then today reinstalled the release versions of the OS and server app clean - just in case there were differences from the GMs.  Problem persists.

     

    Given the errors in my logs, I would guess that Apple has made port changes to the connection process, but I'm using clients that work just fine with SL and ML VPN servers, so there shouldn't be any changes there.  It's quite puzzling.

  • by grumpytorpor,

    grumpytorpor grumpytorpor Oct 23, 2013 12:20 AM in response to eribble
    Level 1 (0 points)
    Oct 23, 2013 12:20 AM in response to eribble

    Additional details: My normal router for this network runs DD-WRT, but I've just reproduced the issue with the same port forwarding settings using both an Airport Express and a Sonicwall TZ205, so it's nothing to do with a specific firewall.

  • by eribble,

    eribble eribble Oct 23, 2013 3:28 AM in response to grumpytorpor
    Level 2 (220 points)
    Oct 23, 2013 3:28 AM in response to grumpytorpor

    Ah ha, so there is an issue with Mavericks.  Good (unfortunately) that someone else is experiencing the same problem.  I've also noticed port 311 is behaving the same way.  I've been digging through various things and have come up empty.  Interestingly, PPTP works just fine from the outside, so at least I can still get in via that method.

  • by ajmf,

    ajmf ajmf Oct 23, 2013 6:37 AM in response to eribble
    Level 1 (0 points)
    Oct 23, 2013 6:37 AM in response to eribble

    Hi there,

     

    Same problem here... work's with ML on iMac, but doesn't work in Mavericks on MacBook Pro.

    Waiting for updates (hope so...).

     

    Best Regards,

    Armando Fernandes

  • by haykong,

    haykong haykong Oct 23, 2013 8:02 AM in response to eribble
    Level 1 (119 points)
    Oct 23, 2013 8:02 AM in response to eribble

    Eribble,

     

          Bear in mind that you now added another variable to your problem since your VPN stopped working in mountain lion server through WAN connection, but  worked fine through LAN connection.

     

    Now you might have also introduced another new problem adding on top of your existing problem.

     

     

    Did you ever try swapping in routers before the upgrade?

     

    Did you try turning off adaptive firewall before the upgrade?

     

    At this point you added another issue by upgrading which is not good.

  • by Engender,

    Engender Engender Oct 23, 2013 1:13 PM in response to eribble
    Level 1 (15 points)
    Oct 23, 2013 1:13 PM in response to eribble

    Make sure that Back to My Mac is still turned off, if that is still an option in Mavericks. If you have Back to My Mac turned on at either your Airport or your Mac, your VPN won't be able to reach the server.

     

    I haven't yet upgraded to Mavericks, but it wouldn't surprise me if Mavericks automatically turned that option on when it was off under ML.

Page 1 Next