You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Airport time capsule / Sonicwall VPN Compatibility

Hello-

We have an enterprise level Dell Sonicwall appliance at our office that we use as a firewall as well as for VPN access to the network from the outside. I run the Sonicwall Mobile VPN client on a Macbook, Mac Mini as well as my iphone and ipad from home. This VPN client has always been spotty at best when used behind my Airport Time Capsule at home. I recently switched from Cox cable modem to ATT Fiber and now cannot connect to the VPN at all when the airport is in the equation. I can connect using VPN client successfully when connected directly to the ATT modem but not when the airport is between ATT modem and computer or device.


Our IT staff opened a ticket with Sonicwall who did a "Packet capture". During the "Handshake" operation the Airport was blocking up to 80 packets that are necessary to establish the connection. Any thoughts on why or how to further troubleshoot?


Best,

NOLA

Posted on Nov 9, 2017 1:30 PM

Reply
Question marked as Top-ranking reply

Posted on Nov 10, 2017 11:30 AM

Ok.. There are definitely issues with the TC. Unfortunately we are given so little in terms of router controls and logging that discovering the problem is near impossible and fixing it more so.


Apple designed the airport routers long before fibre became popular and there are issues for lots of people.

IPv6 can also be part of the problem.. and Cox is well known for having issues with airports.

But the Airport itself also has WAN port issues with some modems and routers. There are just too many variables.. the TC can sit nicely in your network as Wireless Access Point. It will still do Time Machine backup.. although the setup for that can be tricky. The express can still extend.


Main thing is to get your VPN running.

10 replies
Question marked as Top-ranking reply

Nov 10, 2017 11:30 AM in response to B_NOLA

Ok.. There are definitely issues with the TC. Unfortunately we are given so little in terms of router controls and logging that discovering the problem is near impossible and fixing it more so.


Apple designed the airport routers long before fibre became popular and there are issues for lots of people.

IPv6 can also be part of the problem.. and Cox is well known for having issues with airports.

But the Airport itself also has WAN port issues with some modems and routers. There are just too many variables.. the TC can sit nicely in your network as Wireless Access Point. It will still do Time Machine backup.. although the setup for that can be tricky. The express can still extend.


Main thing is to get your VPN running.

Nov 9, 2017 3:25 PM in response to B_NOLA

The modem is an AT&T fiber modem (no longer w/ cox). It's an ARRIS BGW210-700

Ok, that "modem" is actually a combination modem and wireless router. If you have the Time Capsule (TC) connected to it by Ethernet AND the TC is still in its default configuration ... a wireless router, you have two routers in series which is known as a "Double NAT" condition. In order for your VPN client to communicate to the Sonicwall VPN, it would have to navigate through both of those routers.


Typically, you would want the downstream router, in this case the TC, to be reconfigured as a bridge. This will disable the TC's NAT service and remove the Double NAT condition. With this done, only the Arris gateway device would require to be configured for the VPN client for opening the appropriate port to use SSL VPN. That should be TCP port 443.


To reconfigure the TC as a bridge, you would use the AirPort Utility, as follows:

  • Run the AirPort Utility.
  • Select the TC, and then, select Edit.
  • Click on the Network tab.
  • Change the Router Mode option to: Off (Bridge Mode)
  • Click on Update, and allow the TC to restart.

Also, please see additional comments from my network engineer: "The only difference is that instead of blocking request what looks like is happens is after the SonicWALL VPN client sends the ACK to the SonicWALL it responds back and there is no answer form the client when it is behind the Airport for about 80 packets. It eventually starts respond again but cannot connect."

Yes, this would be typical of having the VPN client behind two NAT firewalls. Feel free to pass on what I provided you about the double NAT condition.

Nov 9, 2017 3:10 PM in response to Tesserax

I'm not sure that there's a model number. It's a recent generation (maybe 2 year old) Airport Time Capsule running version 7.7.8 up to date firmware.


The VPN client software is Sonicwall Mobile Connect version 5.0.0 (5013)


The modem is an AT&T fiber modem (no longer w/ cox). It's an ARRIS BGW210-700,


Also, please see additional comments from my network engineer: "The only difference is that instead of blocking request what looks like is happens is after the SonicWALL VPN client sends the ACK to the SonicWALL it responds back and there is no answer form the client when it is behind the Airport for about 80 packets. It eventually starts respond again but cannot connect."

Nov 9, 2017 4:14 PM in response to B_NOLA

Yes, it should. The Apple base stations, to the best of my knowledge, only had issues with VPNs that used the IPSec security protocol ... which are typically used with L2TP type VPNs ... even though Apple claimed that they do support IPSec as a passthrough device. Regardless, that does not pertain to SSL VPNs that is used by the Sonicwall appliance.

Nov 10, 2017 9:36 AM in response to LaPastenague

Thank you all, I will try it over the weekend. To further complicate the matter, my MacBook Air will intermittently connect to the VPN successfully when connected directly to the TC via 5GHz wifi. When I'm connected via an Airport express at the other side of my house, it will not connect. The airport express is connected to the TC via Cat5e cable to extend the network.

Airport time capsule / Sonicwall VPN Compatibility

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.