Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Some VPN routes not respected by clients?

I'm currently trying to secure access to the server by only allowing VPN traffic through the NAT.


Ideally I would like traffic to this server IP be routed through the VPN rather than internet, but everything else (like google, youtube) would go through their own ISP.


In the server app I have configured the following routes:

User uploaded file

so 10.1.1.0/24 being the subnet the server is on, and 14.199.232.0/21 being the public IP of the NAT server (router).


When client mac connects the routes are populated to the destination mac,

User uploaded file


And when I perform traceroute to Google DNS (8.8.8.8 and 8.8.4.4), the mac does route traffic through VPN.


The problem is: the mac does not route 14.199.232.0/21 traffic to VPN, instead it goes via the internet.


Traceroute to 8.8.8.8

(Server on 10.1.1.0/24, Client on 10.10.1.0/24)

User uploaded file


Traceroute to server IP (within 14.199.232.0/21)

(Server on 10.1.1.0/24, Client on 10.10.1.0/24)

User uploaded file



I have tried turning VPN off and on, restarting both server and client mac, reconfiguing the mac, no joy.


Wondering anyone has any ideas?

Mac mini, OS X Mavericks (10.9), with Server.app

Posted on Mar 25, 2014 6:54 AM

Reply
2 replies

Mar 25, 2014 1:05 PM in response to burnduck

It is not your specfiic problem but 8.8.8.8/255.255.255.255 as an example is a single computer. For those unaware this is one of Google's free DNS servers with 8.8.4.4 being the other Google DNS server address.


Having these routes only means any DNS lookups via these servers will be routed via your VPN link, it will not cause YouTube etc. traffic to br routed via your VPN link.


YouTube uses multiple servers and multiple IP addresses, some of them are as follows.


208.65.153.238

208.65.153.251

208.65.153.253

208.117.236.69

So YouTube traffic will not be routed via your VPN as things stand.

Some VPN routes not respected by clients?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.