Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

VPN Status: Available - Reachability unknown

I'm currently running OS X 10.10.5 (Build 14F27) and recently installed OS X Server 5.0.4 (15S2259)


I've enabled several several services, in particularly the VPN service in order access this server from the internet while away from the office. All of the other enabled services seem to be working fine except for the VPN. The Status reads:


Status: Available - Reachability unknown

Permissions: All users, All Networks


If I attempt to connect to the VPN from the local network, I connect fine, without any errors. However, when I attempt to connect from my iPhone 6 Plus using my Carriers connection, the following pop-up error is received:


VPN Connection

The L2TP-VPN server did not respond.

Try redonecting. If the problem

continues, verify your settings and

contact your administrator.

________________________________


OK


When I check on the Server Overview Page within the server app, The Host Name is set correctly and the status indicator is green, as well as the Computer Name and Internet. However, when I select the Reachability Details, the status is Enabled and the following services are listed: DNS, FTP, Profile Manager, Remote Login (SSH), Screen Sharing, Server Administrator, and Websites .. However the VPN service is not listed. Shouldn't it be? And if so, how?


When I check on my AirPort Time Capsule Settings, The Public Service VPN is one of the services listed.


I'm at a loss, and I'm not sure what I'm missing here, but I really need help resolving this VPN Configuration Issue so I can connect to the VPN over the Internet.


Thanks,

Jim

Mac mini, OS X Yosemite (10.10.5), OS X Server 5.0.4

Posted on Sep 26, 2015 12:53 PM

Reply
3 replies

Aug 24, 2017 11:27 PM in response to rosielee41

Hi, I just want to chime in because my problem is so similar:

You write: “the VPN seemed to periodically stop working unless I reset the software (always when I was out and needed access!)“


The only thing: I never used 3rd party software, only Server (Currently 5.3.1) and the problem has been there from day one.


I really feel like the ‘3600seconds timeout bug’ in older OS X versions.

That had to do with PPTP I remember and there was a workaround altering a .conf file in /var/racoon or something.


Haven’t figured it out yet. Have you?

Sep 26, 2015 3:42 PM in response to AdCrimson

To run a public VPN server behind an NAT gateway, you need to do the following:

1. Give the gateway either a static external address or a dynamic DNS name. The latter must be a DNS record on a public DNS registrar, not on the server itself. Also in the latter case, you must run a background process to keep the DNS record up to date when your IP address changes.

2. Give the VPN server a static address on the local network, and a hostname that is not in the top-level domain "local" (which is reserved for Bonjour.)

3. Forward external UDP ports 500, 1701, and 4500 (for L2TP) and TCP port 1723 (for PPTP) to the corresponding ports on the VPN server. The Server app can set this up for you if you have an Apple router.

If your router is an Apple device, select the Network tab in AirPort Utility and click Network Options. In the sheet that opens, check the box marked

Allow incoming IPSec authentication

if it's not already checked, and save the change.

There may be a similar setting on a third-party router.

4. Configure any firewall in use to pass this traffic.

5. Each client must have an address on a netblock that doesn't overlap the one assigned by the VPN endpoint. For example, if the endpoint assigns addresses in the 10.0.0.0/24 range, and the client has an address on a local network in the 10.0.1.0/24 range, that's OK, but if the local network is 10.0.1.0/16, there will be a conflict. To lessen the chance of such conflicts, it's best to assign addresses in a random sub-block of 10.0.0.0./0 with a 24-bit netmask.

6. "Back to My Mac" is incompatible with the VPN service. It must be disabled both on the server and on an AirPort router, if applicable.

7. Bonjour will not work over an L2TP or PPTP VPN. To make services accessible through the tunnel, you need a working DNS service.

Where applicable, services such as Mail must be configured to listen on the netblock assigned to VPN clients.

8. If the server is directly connected to the Internet, rather than being behind NAT, see this blog post.

Oct 7, 2015 12:58 AM in response to Linc Davis

I have the very same problem, although I suspect I may be partially responsible. Initially I had a VPN server setup using 3rd party software (VPNEnabler) which worked OK. However, the VPN seemed to periodically stop working unless I reset the software (always when I was out and needed access!), so I purchased Server. I deleted VPN Enabler (but not sure I did this "cleanly") and proceeded to attempt to setup Server.


Bottom Line: I can't connect from anywhere externally (I have verified all of the relevant steps in your helpful reply above) and I get the same error message as the same post in the Server-Services-VPN tab. The most odd thing is that I don't seem to be able to turn the VPN off either. When I move the slider, it simply comes back on. I have also tried command line tools to stop the VPN, but that doesn't work either. This leads me to suspect that I have corrupted something, somehow.


User uploaded file

Any advice would be gratefully received and I'm happy to post further screen shots as required

VPN Status: Available - Reachability unknown

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.