You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Post Mavericks (server) upgrade, vpn has stopped working. Any suggestions?

I upgraded by Mac mini server to Mavericks (including the server update). Now the VPN has stopped working. Pre update I used the vpn for my MacBook Air, iPad and iPhone. Now nothing works. I've checked my router (Apple) and it appears to be set up appropriately to pass VPN traffic. Any ideas?

Mac Mini Server, Mac OS X (10.6.3)

Posted on Oct 23, 2013 12:52 AM

Reply
113 replies

Oct 27, 2013 7:43 PM in response to denningsrogue

Here is how I got it working:


1. Turn on "Open Directory" and set it up.

2. Add a new user - where it says "Local Only" change it to "None- Services Only"

Thats it...


To complete client VPN setup the easy way

3. Goto VPN and click "Save Configuration Profile"

4. Open the VPN configuration file you just saved on the client and then enter in the new username


This worked for me on the LT2P+PPTP settings...

Oct 27, 2013 8:48 PM in response to cq_

I got my hopes up but now I just have this error in addition to the Phase 1 retransmit BS:


Finder[1116]: Error enumerating (null): The file \u201cBackups.backupdb\u201d couldn\u2019t be opened because you don\u2019t have permission to view it.


Thanks for the suggestions though- it drives me insane to know that someone has this working but I cannot get it working even after a clean install. I wonder what I am doing wrong here...

Oct 28, 2013 7:27 AM in response to cq_

cq_ wrote:


Here is how I got it working:


1. Turn on "Open Directory" and set it up.

2. Add a new user - where it says "Local Only" change it to "None- Services Only"

Thats it...


To complete client VPN setup the easy way

3. Goto VPN and click "Save Configuration Profile"

4. Open the VPN configuration file you just saved on the client and then enter in the new username


This worked for me on the LT2P+PPTP settings...

Can you please detail how you did this?

Thanks.

Oct 28, 2013 8:58 AM in response to Mike Lee7

Hi Guys,


I just wanted to weigh in. Having similar problems to everyone else.


Cannot connect to L2TP from outside. BTMM is disabled everywhere. At this point I assume it is something Apple needs to fix.


However, another issue I have is that on the internal network, when i try to connect to my VPN using L2TP and the credentials of a "Local User" it connects and works fine.


If i connect with a "Local Network User" i get the error in my logs:

: sent [CHAP Failure id=0xfc ""]

: CHAP peer authentication failed for <user here>


Under open directory in Console i get the following error:

Node: /LDAPv3/127.0.0.1, Module: AppleODClientPWS - unable to open connection to Password Server - unable to connect to server "127.0.0.1"


All other services work fine (ical, mail, address book, etc).


Something i am missing? Have you guys encountered this?

Oct 28, 2013 10:01 PM in response to denningsrogue

A bit of a "me too" post. Seeing the same things; however from what I've researched, authentication problems might cause an IKE Phase 1 failure, so I wonder if the PTPP auth errors and L2TP connection errors aren't going back to the same root cause.


Whatever the case is, Apple needs to fix it already. I wonder sometimes if Apple tests such edge functionality sufficiently before releasing - I didn't see anything about it during the Mavericks beta phase, which is worrisome. Very basic regression testing would have caught this.

Oct 28, 2013 10:34 PM in response to Choddy1

Hey again,


Just wanted to share what i did to fix my issue (not the outside l2tp vpn issue, but the authentication failures on l2tp). The problem was my password server for open directory was not started.


http://support.apple.com/kb/TS3036


All I needed to do was start it:


sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.PasswordService.plist


And instantly my network users are now being authenticated via l2tp logins and all is well in the world.


Except of course the outside access via l2tp.

Oct 28, 2013 10:47 PM in response to denningsrogue

Spoke to Apple Enterprise Support this morning and they are aware of the issue now. We spent about 2 hours troubleshooting and trying everything the tech could think of, in the end he gathered logs from my server. At this point they are leaning towards an issues with NAT and Mavericks Server. They're working on it, most likely be addressed in an update to the Server app. Just wanted to share.

Oct 29, 2013 12:56 PM in response to denningsrogue

Reading from you guys let me know that I am not alone! I have exactly the same issue about the VPN server after upgrading to Mavericks so I am not going to repeat.


However, now I am on business trip in China (Ningbo, Zhejiang) and despite of having no luck to connect to the VPN server in Hong Kong, I suddenly were able to connect to the VPN server (which was left running when I left yesterday) from time to time. Connection is not 100% as there are only at times when I can connect with my MBP and iPhone 5.


So I am very puzzled about the current status of the VPN server flaws now. I am very frustrated with CrApple, too, especially that I did also have my Mail app keep crashing after the upgrade that I still have to look for a solution.


Just to much trouble to upgrade from ML to Mavericks! I am lossing trust in CrApple, despite my latest investment in another MBA a few days ago.... :-(

Oct 30, 2013 2:45 AM in response to Choddy1

Hello there as well,


I've the same issue and I investigate the problem. The reason why it does not work is, that the racoon (IKE Daemon) does not accept connections on port 4500 (IKE for NAT-T) if the source port is random generated.


Since Mavericks and IOS7 the source port from the client is no longer 4500, this lead to this problem (except you have a old VPN connection already setup bevor you update to IOS7 on your Phone).


If you are in the same network like your server, the IKE NAT-T is not used. In this case the regular port 500 (IKE) is used, and this works as expected. At the moment we have to wait if the problem is fixed by Apple.


There are two possibilities, they can adjust the clients or the server configuration. However if you want to use VPN with OS X native methods, use PPTP. This is not affected but of course it provides no Layer 2 Tunneling.


Regards,

Daniel

Post Mavericks (server) upgrade, vpn has stopped working. Any suggestions?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.