Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Unable to set up VPN server

I am unable to properly set up and access a VPN server. Help is much appreciated.


Setup

Server: 2009 MBP, 15", 8 GB ram; OSX 10.10.5 ; Server.app 4.1.5.

Client: 2015 MBP retina, 13"; OSX 10.10.5

Router: 2009 Time Capsule (firmware 7.6.4)


Using Airport Utility (6.3.5), I have given the server a reserved IP and forwarded ports 500, 1701, 1723 and 4500 to that IP (and also 22 for SSH).

I have set up a DDNS for the server (using MAC address of wireless card, which I am using for now).

Using Server.app I have set up the VPN to allow only my user access. There's a green dot on the Services>VPN item in the sidebar, but in Server><computer_name> in Overview:Server:Internet it says Reachable at 87.––.––.––. (–– is my redaction), no services available.


With the url for my DDNS, I can log in to the server using ssh, which I take to mean that I am on the right track.


But when trying to connect to the VPN (having set the same URL as hostname), I get no response from the server and hence no connection.


I have tried verifying the port openness using http://www.yougetsignal.com/, but this is apparently unable to reach any port, perhaps this is a clue.


I don't really have any prior networking experience. What could I be doing wrong?

Posted on Aug 30, 2015 7:14 AM

Reply
15 replies

Aug 30, 2015 11:12 AM in response to Linc Davis

Thank you for the suggestion, Linc.


I did not have the option, though. I found it using Airport Utility 5.6.1 (http://coreyjmahler.com/2013/10/24/airport-utility-5-6-1-on-os-x-10-9-mavericks/). The option is now also available in Airport Utility 6.3.


Setting "Block incomming IPv6 connections" gives the option to "Allow incoming IPSec authentication". The time capsule is now blinking amber, with the message: "IPv6 Relay Error".

Outbound activity seems to function as normal, but there is no change in VPN.

Aug 31, 2015 12:19 PM in response to Linc Davis

I am unsure which logs would be helpful.


I tried a traceroute, and it turns out I was mistaken about how the routing worked, when I said that ssh worked.

When I said that, I was on a different network, but that was the guest network provided by the time capsule. When entering the ddns-adress, I thought it would have to make a loop over the internet. Traceroute tells me I was wrong.

When I try the same thing over my cellphone, ssh also stops working.


Can something be deduced from this?

Sep 1, 2015 5:23 AM in response to m3dusa

Some ISP's statefully block UDP datagrams at the headend that don't follow a reciprocal outgoing packet, unless you pay for business-class service. Incoming L2TP VPN connections would then also be blocked. That's what seems to be happening. If UDP is blocked, you may be able to connect with PPTP, which uses TCP rather than UDP.

Unable to set up VPN server

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.