Airport Extreme 802.11ac VPN Passthrough (IPSec, PPTP, and L2TP)

Hi There,
I just got an Airport Extreme 6th Gen and set it up in a breeze using Airport Utility on Mavericks. It was actually too simple to configure but I cannot connect to our company's VPN using Cisco IPSEC. I can't find any settings within Aiport Utility that says about VPN Passthrough. My router mode is in DHCP and NAT mode by the way.
Have anyone experienced this issue and solved it? I know our VPN is working since I upgraded from a Cisco SMB router and if I plug it back in I can connect to it.
Any help will be much appreciated.
Thanks!

What modem is the AE plugged into and is it a router as well??
The AE cannot handle vpn passthrough easily if you have double NAT.. well it just won't work.
If you are using a PC it also may not work because it will need upnp which airport does not provide. Manually forward the ports but it will only work if the AE is the one and only router in the network.
You may still have issues.. as port 500 could well be used by the AE with btmm.. you will need to not use btmm to use ipsec .. but I haven't explored it fully.

Similar Messages

  • I just purchased a new airport extreme 802.11ac I set it up and runs fine when i put my mac to sleep i come back and it can not find my airport i have to restart

    I PURCHASED THE NEW AIRPORT EXTREME 802.11AC I SET IT UP AFTER I PUT MY MAC TO SLEEP I COME BACK AND IT SAYS CAN NOT FIND AIRPORT EXTREME I HAVE TO RESTART AND IT FINDS IT.

    Try the following, in order, until (hopefully) resolved:
    1a. Delete Preferred Network(s)
    System Preferences > Network > Wi-Fi > Advanced > Wi-Fi tab
    Under "Preferred Networks," delete the network(s) you regularly use from the list.
    1b. Delete AirPort Keychain Entries
    Launch the "Keychain Access" application located in Applications/Utilties.
    In the windows on the left side: Select login for Keychains and "All Items" for Category.
    Click on the "Kind" filter at the top, and look for any "AirPort network password" entries...and delete them.
    1c. Add Preferred Network(s)
    System Preferences > Network > Wi-Fi > Advanced > Wi-Fi tab
    Add the preferred network(s) using the "+" button.
    Restart or log out then back in.
    2. Move System Configuration Files
    (Note: You will have to reestablish your network connections settings.)
    Go to /Library/Preferences
    Move the SystemConfiguration folder to the desktop.
    Restart your Mac. (Note: OS X will rebuild the files that are now sitting on your desktop. If this doesn't resolve the issue, you can move the folder back to it's original location.)

  • Allowing IPSec PPTP, and L2TP passthrough for VPN Access

    Does anyone know where you can allow VPN Passthrough in the Airport Extreme? I am not able to connect to work using the Nortel VPN client, however when using my Linksys (where I have configured IPSec, PPTP and L2TP) it works fine.

    I have the exact same problem with my work windows machine. I temporily got it working by setting the default NAT address to the IP address of my work laptop.
    This is not an acceptable long term solution for me. I will have to return the airport extreme and go back to linksys myslef if it cannot be resolved.

  • Airport Extreme 802.11ac manual DHCP range

    I have one of the new Airport Extreme 802.11ac units, and am running airport utility 6.3 on my server.
    I am trying to setup my network but I would like my own DHCP range instead of 10.0 or 192.168 - I would like to add 10.20,  This way it wont conflict with my other network for work which has 10.0 and my IP TV Network which is 192.168.  I would like to add a manual address for my home netwok so I can add a vpn to avoaid the conflits.
    Is there anyway of adding my own DCHP range in the new extreme?
    Thanks
    Greg

    It isn't possible to change the first two octet values other than what apple has already allowed.. ie 10.0, 172.16 or 192.168
    That is how Apple build their stuff.
    I have no idea if this would work.. but someone else suggested the idea.. export the configuration of the AE .. you will find that is available via the top menu.. then open the xml file that is produced and do a search and replace for 10.0 to 10.20 or whatever you want.. save the file.. and import it back to AE.. it is crude windows sort of operation but it worked to change dhcp messages for the poster.

  • Trying to Port Forward Airport Extreme 802.11ac using Airpot Utility 6.3.2

    Hello kind experts. I am finally getting around to replacing my old BEFSR81 Cisco Router with an old Time Capsule attached with the Airport Extreme 802.11ac.  The BEFSR81 also had 8 ports, so I have 8 hardwired locations throughout the house.  I have a couple of IP cameras for which it was easy to port forward on the Cisco (just click on the port range forwarding tab, type the start/end ranges (which are identical) and the assigned IP address).  Everything has been working well for years.  Here's what I wish to do with the new setup: Cable Modem -> Airport Extreme -> Dumb gigaport switch with the hardwires connected to it.
    When I go to Airport Utility (6.3.2) -> Network Tab -> Port Settings -> "+", the following comes up:
    Firewall Entry Type (Defaulted to IPv4 Port Mapping)
    Description (5 pull down choices)
    Public UDP Ports : _________
    Public TCP Ports: __________
    Private IP Address (I take it that is where I enter the IP address for each camera, e.g. 192.168.1.xxx)?
    Private UDP Ports: __________
    Private TCP Ports: __________
    I am obviously not a technophile, especially when it comes to networking, but was able to create my old setup.
    Any advice on whether or not my configuration is appropriate and what exactly I need to put in the port fields would be greatly appreciated!
    Thanks in advance!

    To successfully access an IP camera on the local network from the Internet, the following basics need to be taken care of:
    Install the camera(s) and verify that you can access them from the local network.
    Configure port mapping/forwarding on your router. Typically, IP cameras require at least two ports: 1) A web port for administering the camera; Usually TCP port 80, and 2) A streaming port to broadcast the camera video feed; Usually UDP port 9000. Note: You should check with your camera's documentation for the exact ports required.
    If the camera is attached to a computer, you will need to configure the computer's firewall to open the same ports as in step 2 above.
    Verify that your modem is in bridge mode, i.e., if the modem provides NAT & DHCP services, turn them off.
    Test your network. Use CheckIP to determine your router's current WAN-side (public) IP address. Then, from a remote location (not from a computer on the local network), use the DynDNS Open Port Tool to verify that the required ports are open. Success is an "Open" response from the Tool.
    Check out the following AirPort User tip for configuring port mapping on an AirPort base station.

  • Airport Extreme 802.11AC + 5th Gen and guest network access

    I have the current gen Airport Extreme 802.11AC with a 5th Gen extending the network. With this setup, I am unable to login using our guest network setup. I have tried using guest network with a password and one without but its the same results. When a guest logins, it stuck attempting to login with no error messages.
    So is it possible to have this configuration and still have guest network access?

    Please review what I said originally.......that the guest network function on the AirPort Extreme is designed to work with a simple modem......so the AirPort acts as the main router for the network..
    Another way of saying the same thing is that the AirPort needs to be "in charge" of your network for the guest feature to work correctly. The AirPort cannot be in charge if it is connected to another device that is already configured to be the main router on your network.....your Actiontec modem/router.
    The Actiontec device combines the functions of a separate modem and a separate router in one package. This type of device is known as a modem/router, or also known as a gateway.
    Some folks call a modem/router or a gateway......a modem. So, things can get confusing.
    I do not know if it is possible for the Actiontec device that you have to be configured to act as a simple modem.....so the routing functions of the device are completely turned off. (Turning off the wireless on the Actiotec does not turn off the routing function).
    If you turn off the wireless on the Actionec, it becomes a modem and a wired router. And that wired router is still in charge of your network.
    The guest network feature will not work correctly unless the AirPort is in charge of your network.
    My suggestion was for you to ask your Internet Service Provider (ISP), if they could supply you with a simple modem.  That is all that you need. You don't need two routers....and the Actiontec that you have now is not allowing the guest feature to work correctly.

  • I have airport extreme 802.11AC as a base that connect to Cable modem. How can I connect D-link DIR-655 to AE to utilize as an extender or repeat?

    Hello-
    I have wireless router Airport Extreme 802.11AC that connect direct to Cable modem...how can I setup the D-Link DIR-655 wireless router to AE and act as extender or repeater?. Thanks in advance.

    Apple has done their best to install proprietary software in their wireless routers that is designed to only allow other Apple routers to repeat or extend the network wirelessly.
    So, the chances are extremely small that a D-Link....or another other router for that matter.....could be configured to do what you ask.
    There are no settings on an AirPort Extreme that would allow a D-Link device to extend the network, so all that you can do is experiment with different settings on the D-Link device to see if it might be possible for it to extend the network.
    A post on a D-Link support forum might be a good idea to see if any D-Link specialists have some ideas on this topic.
    Good luck.

  • I have an 2tb time capsule 802.11n Wi-Fi base station can I use this as an external hard drive and use a new airport extreme  802.11ac Wi-Fi for my wifi?

    I have an 2tb time capsule 802.11n Wi-Fi base station can I use this as an external hard drive and use a new airport extreme  802.11ac Wi-Fi for my wifi?

    You can use the 2 TB Time Capsule as a network drive. That means that it must connect to one of the Ethernet LAN <--> ports on the new AirPort Extreme, or connect to the network using wireless.

  • Do I need to get all new hardware to enjoy benefits of New Airport Extreme 802.11ac protocol?

    Do I need to get all new hardware to enjoy the benefits of new Airport Extreme 802.11ac protocol?

    You will need hardware capable of using 802.11ac, which at present is limited to the new MacBook Air models.

  • Extended Airport Extreme 802.11ac - Slow Wi-Fi

    Hi All..
    I have a rather frustrating scenerio here and could do with a few pointers as things arn't going my way
    I recently purchased two new AP 802.11ac for my home network, setup as follows: -
    Sky Modem 20Mbps
    IP 192.168.0.1
    DHCP
    Ethernet
    Airport Extreme 802.11ac (Downstairs) Version 7.7.1
    Static IP 192.168.0.20 - Reserved at Modem
    DNS 192.168.0.1 - Not sure if this should point to modem, advice here if possible
    DNS 8.8.8.8
    Wirless on, secured by WPA2, also guest network
    Ethernet
    Airport Extreme 2010 (Downstairs) Version 7.6.4
    Static IP 192.168.0.40 - Reserved at Modem
    DNS 192.168.0.1 - Not sure if this should point to modem, advice here if possible
    DNS 8.8.8.8
    Wireless
    Airport Extreme 802.11ac (Upstairs) Version 7.7.1
    Static IP 192.168.0.30 - Reserved at Modem
    DNS 192.168.0.1 - Not sure if this should point to modem, advice here if possible
    DNS 8.8.8.8
    Wirless set Extending the above network, secured by WPA2, also guest network
    Ethernet
    iMac 27" 2011 (Upstairs)
    Static IP 192.168.0.31 - Reserved at Modem
    DNS 192.168.0.1 - Not sure if this should point to modem, advice here if possible
    DNS 8.8.8.8
    Running OSX Server 2.2.1 (169)
    So.. I understand there are many many factors here but my issues are that the iMac (Server) downloads at the expeteced rate of 19Mbps, however anything on wirless pulls around 4Mbps at best and file transfer between the iMac and Macbook Pro (Wireless) not really happening.. This is also the case for all other clients connected to the Wireless networks (5GHz, 2.5GHz and Guest).. In fact, guest network has no connection at all...
    I don't think that any of my devices has the AC ability if that matters..
    Further details from 'Option + Wi-Fi Icon' on Macbook Pro :-
    PHY Mode 802.11m
    Channel 100 (DFS, 5 GHz)
    Security: WPA2 Personal
    RSSI -70
    Transmit Rate: 108
    MCS Index: 11
    I appreciate this is probably an odd setup, but any help would be appreciated..

    Ok... netspeed just resolved itself across the wirless back up ro 19Mbps..
    However, file transfer between the iMac and Wireless Macbook is around 5Mbps only, any ideas?
    Any feedback on the dns would also be appreciated though!

  • Airport utility 6.3.4 can not find my airport extreme 802.11ac

    Sometimes the program loses contact with Airport Extreme 802.11ac with firmware 7.7.3 The internet is OK and the internettlight is green but the software seems not to find my Airport Extreme 802.11ac. The curios thing is that the airport utility app on my Iphone will find the Airport Extreme and from here I can restart it - which (obvious) solves the problem - for some time
    Probably a known problem!

    The problem is with Yosemite. We have seen many posts from users with "disappearing" AirPorts, but unfortunately there does not appear to be a reliable solution at this time.
    Some users have reported that turning off the Firewall on their Macs has helped with this issue. Not sure if you want to try this, and we are not really recommending that you do this, but it might be worth a try if it is important for you to be able to "see" the AirPort Extreme in AirPort Utility from your Mac.
    Another check that you can perform that might help is to see if your Mac has been bitten by the Yosemite "naming" bug. To do this, open System Preferences (gear icon on the dock) and then open Sharing.  Check to make sure that the name of your Mac is displayed correctly.  If you see a (2), (3), (4) etc added to the name of the Mac, edit the name to correct it and restart your Mac.
    You may need to check this daily as when you have the bug, the "naming" will likely continue until we get a fix.

  • Airport Extreme 802.11ac and USB disk failure

    hi,
    Had an Airport Extreme 5th gen with a USB disk attached for over a year of which my Mac was using Time Machine and creating backups no problem, didnt skip a beat.
    Just bought a new Airport Extreme 802.11ac, attached the same USB disk and Time Machine works once or twice then fails saying it cant find the disk. True enough if I open finder and try and find the disk its not listed.
    Opening the airport utility it shows the disk attached. If I reboot the Airport Extreme the disk shows up again in finder for a short period of time.
    Looks like they released a firmware update 7.7.1 which was supposed to fix this but it seems in my case it hasnt. Even factory reset after the update but no joy.
    Normal wireless activities like internet access etc are fine.
    Not sure if anyone else has experienced this yet? If not I guess ill try a non self powered disk or something, either that my AE is faulty.
    thanks
    matt

    My experience with the 802.11ac extreme with 7.7.1 firmware suggests Time Machine doesn't work when the name assigned to the device (not the SSID) contains a period, which the out-of-the-box name does.
    Out-of-the-box, with the default device name still assigned, I could not get Time Machine to recognize the remote disk on multiple 10.8.4 Macs until I created an empty folder on it. Yet once registered with Time Machine, backups never occurred to the disk--TM status was always "waiting". The server name displayed in TM had the period in "802.11ac" escaped with a backslash (i.e., "802\.11ac").
    I renamed the extreme, but used a name that still contained a period. The same difficulty was encountered registering the disk with TM. Once registered, TM status for the disk was still "waiting".The server name again had the period escaped with a backslash.
    Finally, I just removed the period from the name. Registering the disk with TM then occurred normally and backup began immediately.
    (In an earlier case with the 7.7.0 firmware, I had no trouble registering and backing up to an 802.11ac Time Capsule that had previously been given a name without a period in it.)

  • AirPort Extreme 802.11ac boosted w/ 802.11n Express?

    for the past year or so I have had a perfect set up that has worked wonderfully. It was an airport extreme hardwired to two different airport expresses. I had a perfect set up all three devices had the exact same Wi-Fi name and all three supported 802.11n. So why ruin a good thing? Well here's why…
    recently we have obtained some new Apple devices such as new iPhone sixes and also new MacBook air is. All of our new devices are capable of supporting 802.11ac. So now I have decided to purchase the new airport extreme sixth generation which supports this new protocol of 802.11ac.
    My question is this, if I have my main airport extreme configured the same way I used to have it, but now I have airport expresses that do not support this new 802.11ac protocol, am I doing myself a disservice? The boosters are located on our third level in the master bedroom where where most of the surfing is done with the newer 802.11ac devices.
    with the brand-new sixth generation extreme located in my basement, most of the house is covered however in the furthest rooms, such as the master bedroom, I have an airport express hardwired and functioning fine. But my question is this how can I be sure that the MacBook air is that support 802.11 ac are actually staying connected to the basement brand-new sixth generation airport extreme instead of the closer proximity airport express?
    I wish that my airport express is also supported the new protocol so that I can be sure that my entire house is covered by 802.11ac. There's nothing wrong with using 802.11n, but the reason I purchased the new extreme router was to take advantage of the faster and stronger signal of 802.11ac.
    The airport expresses that I am running in my house are the newer white ones that looks to be the same shape as an Apple TV. These are not the ones with the FlipOut prongs that plug directly into the wall but instead they are the ones that have a regular power cord and it look like small little hockey pucks. Well, squares versions of hockey pucks that is.
    this entire post was verbally dictated using my iPad air, so hopefully I have caught all of my typos or incorrect wording. But I think you can get the general just of my question here. I was hoping I would not need to use the airport expresses to boost the signal, but I think my home might be too big for one single router located centrally in my basement. I have it as Close to the ceiling as I could get it so the second floor is completely covered and most of the upper floor is covered and the entire basement is covered of course. It's just a few rooms that are above the garage and a few further rooms such as kids bedrooms and very important, the master bathroom. We all know how important that is. Thanks in advance to anybody who can help me with this issue.

    if I have my main airport extreme configured the same way I used to have it, but now I have airport expresses that do not support this new 802.11ac protocol, am I doing myself a disservice?
    Yes and no.
    Yes, if you want "ac" capable devices in a remote location near the AirPort Expresses to connect at "ac" levels......because they won't.
    No, if you need the extra range provided by the Express, and don't mind that the "ac" devices connect at slower "n" speeds through the AirPort Express.
    But my question is this how can I be sure that the MacBook air is that support 802.11 ac are actually staying connected to the basement brand-new sixth generation airport extreme instead of the closer proximity airport express?
    You can't, if all the AirPorts are producing a signal with the same wireless network name......since the MacBook Air will connect to the wireless access point with the strongest signal.....not the AirPort with the fastest signal.
    IF....you assigned a different name to the wireless network that the Express devices were creating....then....you could "point" the MacBook Air at the basement AirPort network created by the AirPort Extreme 802.11ac down there.....but chances are, the MacBook Air will never connect at "ac" levels since they are carried on the 5 GHz band, which is much weaker than the 2.4 GHz signals.
    In other words, 5 GHz "ac" signals are pretty much "same room" or "line-of-sight" signals. 5 GHz just won't penetrate walls and other obstructions nearly as well as slower, but much stronger 2.4 GHz signals.
    The bottom line.....if you want the MacBook Air to connect at "ac" level speeds in the remote location, you will need another AirPort Extreme 802.11ac product in place of at least one AirPort Express, maybe both.

  • Is it best to extend a Wifi network using Airport Extreme 802.11ac or Express ?

    I previously asked this question with a different emphasis here:
       https://discussions.apple.com/message/24347878#24347878
    so have re-worded to be more relevant to the subject.
    I have a brand new Airport Extreme 802.11ac which I am now using as my network hub and I would like to extend the network wirelessly.
    Is there a benefit to extending the network via another Airport Extreme 802.11ac versus a (cheaper) Airport Express ?
    I do not have any 802.11ac clients yet, but likely will do within the expected lifespan of the routers and thus would rather buy another Extreme now if it meant extending the best signal strength.
    Per my previous post i would ideally extend using my old Edimax BR-6675nD 450Mbps 2.4GHz/5GHz, however this has been problematic and some previous posts imply that mixing Apple and non-Apple routers is not recommended, if this is not correct please do let me know.
    Thanks in advance.

    Is there a benefit to extending the network via another Airport Extreme 802.11ac versus a (cheaper) Airport Express ?
    Four possible benefits, which may or may not be benefits to you:
    1) A second Extreme will extend the faster "ac" speeds of the main AirPort Extreme, while the Express will not.
    2) A second Extreme uses Gigabit Ethernet ports....ten times faster than the Express....if you plan to connect devices using an Ethernet connection
    3) The USB port on the AirPort Extreme will accept a hard drive while the Express will not
    4) The AirPort Extreme has a much better antenna arrangement than the Express, which will provide greater coverage even if "ac" wireless is not used
    On the other hand, if you do not need "ac" wireless to be extended, you only plan to use the Express to extend the wireless, and the Express will be located where it can receive a strong wireless signal, then you might save a bit of money going with an AirPort Express.
    So, in questions about what would be "best", there are rarely simple answers that apply to all users. The question really is which is "best" for you. Adding another AirPort Extreme would be a no brainer for me, but perhaps not for you.
    i would ideally extend using my old Edimax BR-6675nD 450Mbps 2.4GHz/5GHz, however this has been problematic and some previous posts imply that mixing Apple and non-Apple routers is not recommended
    It is always the best idea to use products from the same manufactuer for the same purpose throughout the network. Obviously, an Apple AirPort Extreme will be compatible with another AirPort, while a third party device may or may not be.

  • Airport Extreme 802.11ac showing scattered websites

    Recently I've replaced my linksys to airport extreme 802.11ac. Many of the websites are downloading with lazer sharp speed but few websites are shown in scattered manner and few others are just not opening at all. What can be the problem?

    These situations are difficult to sort out.
    What modem and broadband do you have?
    Is the modem also a router?
    Is the AE in bridge or router mode?
    What device is displaying the webpages..? Have you cleared the cache of the browser?
    Is the AE or the computer getting the correct DNS address? Test by manually changing the dns in the computer to 8.8.8.8 which is the public google one.
    Then there are really nasty ones.. MTU issues.. these are really tough.

Maybe you are looking for

  • Transporting an ABAP query from DEV to QAS/PRD

    Hi all, I am trying to modify an existing query in DEV and move it to QAS and then to PRD. After making the changes in DEV, there was new transport request created, in which I had the changes for the query and in se93, i changed the name of the prog

  • Form Layer 2 to Layer 3 on Distribution and Access

    Hi, Our LAN topology have Core "L3" , Ditribution "L2" and Access "L2". We want to get rid of spanning tree by moving from layer 2 to layer 3 on Access and Distribution layers. My questions is: 1) Any advice/document on this? 2) in the access switche

  • Extreme image distortion in compressor preview

    Running FCP 4.5 on a dual 2.5 G5, w/ 4 gigs of RAM. I'm trying to export an 18 min. project to Compressor, using the mpeg2-60 min encoder(tried both fast and high quality) but when I inspect it in the preview, some of my video has been squeezed to a

  • Adding a field in movement 561 with transaction MB1C

    Hi! I would like to add a field (FISTL - found center) for movement type 561. I went in OMJJ and made field FISTL mandatory. The thing is that if I use MIGO and movement 561, the field is available and it's working corectly. What I would like is to u

  • Is complex type request supported by web service data set?

    I just installed OBIEE 11g and tried to create data models with web services. It works fine for web services that takes simple data types and returns complex data types. But if the request to the web service is a complex type, it doesn't work. On the