HT200188 NAT from KB/ht5215 broken in ML 10.8.2?

We've been using NAT with Lion Server and ML Server as described in the KB article but this config has broken on of our servers with the 10.8.2 / Server 2.1 (and 2.1.1) update. Basically, the pfctl lauch daemon won't load (exited with code: 1). Has anyone else seen this in their setups? Better yet, has anyone found a solution to this problem?
Here's a bit of diagnostics with pfctl:
bash-3.2# pfctl -vvv -s info
No ALTQ support in kernel
ALTQ related functions disabled
Status: Disabled                              Debug: Urgent
Hostid:   0xc1eda31d
Checksum: 0x00000000000000000000000000000000
State Table                          Total             Rate
  current entries                        0              
  searches                               0            0.0/s
  inserts                                0            0.0/s
  removals                               0            0.0/s
Source Tracking Table
  current entries                        0              
  searches                               0            0.0/s
  inserts                                0            0.0/s
  removals                               0            0.0/s
Counters
  match                                  0            0.0/s
  bad-offset                             0            0.0/s
  fragment                               0            0.0/s
  short                                  0            0.0/s
  normalize                              0            0.0/s
  memory                                 0            0.0/s
  bad-timestamp                          0            0.0/s
  congestion                             0            0.0/s
  ip-option                              0            0.0/s
  proto-cksum                            0            0.0/s
  state-mismatch                         0            0.0/s
  state-insert                           0            0.0/s
  state-limit                            0            0.0/s
  src-limit                              0            0.0/s
  synproxy                               0            0.0/s
  dummynet                               0            0.0/s
Limit Counters
  max states per rule                    0            0.0/s
  max-src-states                         0            0.0/s
  max-src-nodes                          0            0.0/s
  max-src-conn                           0            0.0/s
  max-src-conn-rate                      0            0.0/s
  overload table insertion               0            0.0/s
  overload flush states                  0            0.0/s
bash-3.2# pfctl -v -n -f /etc/pf.conf
scrub-anchor "/*" all fragment reassemble
nat-anchor "/*" all
rdr-anchor "/*" all
anchor "/*" all
dummynet-anchor "/*" all
Loading anchor com.apple from /etc/pf.anchors/com.apple
scrub-anchor "/*" all fragment reassemble
nat-anchor "/*" all
rdr-anchor "/*" all
anchor "/*" all
anchor "/*" all
anchor "/*" all
anchor "/*" all
Loading anchor com.apple/100.NATRules from /etc/pf.anchors/NATRules
nat on en0 inet from 192.168.42.0/23 to any -> (en0) round-robin
pass on lo0 inet6 from fe80::1 to any flags S/SA keep state
pass inet6 from ::1 to any flags S/SA keep state
pass inet from 127.0.0.1 to any flags S/SA keep state
pass inet from 192.168.42.0/23 to any flags S/SA keep state
Loading anchor com.apple/400.AdaptiveFirewall/ from /Applications/Server.app/Contents/ServerRoot/private/etc/pf.anchors/400.AdaptiveFirewall
table <blockedHosts> persist file "/var/db/af/blockedHosts"
block drop in quick from <blockedHosts> to any
launchctl doesn't throw an error when you unload then reload /System/Library/LaunchDaemons/com.apple.pfctl.plist but it does write an error to syslog:
Sep 27 13:50:37 localhost com.apple.launchd[1] (com.apple.pfctl[47]): Exited with code: 1
Any ideas? This was working with 10.8.1 but broke with 10.8.2 and Server.app 2.1.x
Thanks,
Miles

Solved:
http://support.apple.com/kb/TS4418

Similar Messages

  • Is it possible to get data from a smashed/broken iPod touch 4th gen?

    Is it possible to get data from a smashed/broken iPod touch 4th gen?

    - If when you connect the iPod to your computer it appears in iTunes then you can make a backup and then restore another iPod or other iOS device from that backup.
    - Otherwise you will have to go to a data recovery company.
    - When I go to the YouTube link I can't get the video to play.

  • Is there any way to get all my stuff transfered from my old broken iphone to a new one

    is there any way to get all my stuff transfered from my old broken iphone to a new one

    Guess you have your answer.  Maybe next time you'll read the User Guide and use the phone as recommended so this doesn't happen again.

  • MS NLB with ASA and Static NAT from PUP to NLB IP

    Hi all,
    I am trying to get MS NLB up and running.  It is almost all working.  Below is my physical setup.
    ASA 5510 > Cat 3750X >2x ESXi 5.1 Hosts > vSwitch > Windows 2012 NLB Guest VMs.
    I have two VMs runing on two different ESXi hosts.  They have two vNICs.  One for managment and one for inside puplic subnet.  The inside puplic subnet NICs are in the NLB cluster.  The inside public subnet is NATed on the ASA to a outide public IP.
    192.168.0.50 is the 1st VM
    192.168.0.51 is the 2nd VM
    192.168.0.52 is the cluster IP for heartbeat
    192.168.0.53 is the cluster IP for NLB traffic.
    0100.5e7f.0035 is the cluster MAC.
    The NLB cluster is using MULTICAST
    I have read the doumentation for both the ASA and CAT switch for adding a static ARP using the NLB IP and NLB MAC. 
    For the ASA I found
    http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/mode_fw.html#wp1226249
    ASDM
    Configuration > Device Management > Advanced > ARP > ARP Static Table
    I was able to add my stic ARP just fine.
    However, the next step was to enable ARP inspection.
    Configuration > Device Management > Advanced > ARP > ARP Inspection
    My ASDM does not list ARP Inspection, only has the ARP Static Table area. Not sure about this.
    For the CAT Switch I found
    http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_example09186a0080a07203.shtml
    I added the both the ARP and Static MAC.  For the static MAC I used the VLAN ID of the inside public subnet and the interfaces connected to both ESXi hosts.
    On the ASA I added a static NAT for my outside Public IP to my inside pupblic NLB IP and vise versa.  I then added a DNS entry for our domain to point to the outside public IP.  I also added it to the public servers section allowing all IP traffic testing puproses.
    At any rate the MS NLB is working ok. I can ping both the Public IP and the Inside NLB IP just fine from the outside. (I can ping the inside NLB IP becuase I'm on a VPN with access to my inside subnets)  The problem is when I go to access a webpade from my NLB servers using the DNS or the Public IP I get a "This Page Can't Be Displyed" messgae.  Now while on the VPN if I use the same URL but insied use the NLB IP and not the Public IP it works fine. 
    So I think there is soemthing wrong with the NATing of the Public to NLB IP even tho I can ping it fine.  Below is my ASA Config. I have bolded the parts of Interest.
    Result of the command: "show run"
    : Saved
    ASA Version 8.4(4)9
    hostname MP-ASA-1
    enable password ac3wyUYtitklff6l encrypted
    passwd ac3wyUYtitklff6l encrypted
    names
    dns-guard
    interface Ethernet0/0
    nameif outside
    security-level 0
    ip address 198.XX.XX.82 255.255.255.240
    interface Ethernet0/1
    description Root Inside Interface No Vlan
    speed 1000
    duplex full
    nameif Port-1-GI-Inside-Native
    security-level 100
    ip address 10.1.1.1 255.255.255.0
    interface Ethernet0/1.2
    description Managment LAN 1 for Inside Networks
    vlan 2
    nameif MGMT-1
    security-level 100
    ip address 192.168.180.1 255.255.255.0
    interface Ethernet0/1.3
    description Managment LAN 2 for Inside Networks
    vlan 3
    nameif MGMT-2
    security-level 100
    ip address 192.168.181.1 255.255.255.0
    interface Ethernet0/1.100
    description Development Pubilc Network 1
    vlan 100
    nameif DEV-PUB-1
    security-level 50
    ip address 192.168.0.1 255.255.255.0
    interface Ethernet0/1.101
    description Development Pubilc Network 2
    vlan 101
    nameif DEV-PUB-2
    security-level 50
    ip address 192.168.2.1 255.255.255.0
    interface Ethernet0/1.102
    description Suncor Pubilc Network 1
    vlan 102
    nameif SUNCOR-PUB-1
    security-level 49
    ip address 192.168.3.1 255.255.255.0
    interface Ethernet0/1.103
    description Suncor Pubilc Network 2
    vlan 103
    nameif SUNCOR-PUB-2
    security-level 49
    ip address 192.168.4.1 255.255.255.0
    interface Ethernet0/2
    shutdown
    no nameif
    no security-level
    no ip address
    interface Ethernet0/3
    shutdown
    no nameif
    no security-level
    no ip address
    interface Management0/0
    nameif management
    security-level 100
    ip address 192.168.1.1 255.255.255.0
    management-only
    boot system disk0:/asa844-9-k8.bin
    ftp mode passive
    clock timezone PST -8
    clock summer-time PDT recurring
    same-security-traffic permit inter-interface
    same-security-traffic permit intra-interface
    object network Inside-Native-Network-PNAT
    subnet 10.1.1.0 255.255.255.0
    description Root Inisde Native Interface Network with PNAT
    object network ASA-Outside-IP
    host 198.XX.XX.82
    description The primary IP of the ASA
    object network Inside-Native-Network
    subnet 10.1.1.0 255.255.255.0
    description Root Inisde Native Interface Network
    object network VPN-POOL-PNAT
    subnet 192.168.100.0 255.255.255.0
    description VPN Pool NAT for Inside
    object network DEV-PUP-1-Network
    subnet 192.168.0.0 255.255.255.0
    description DEV-PUP-1 Network
    object network DEV-PUP-2-Network
    subnet 192.168.2.0 255.255.255.0
    description DEV-PUP-2 Network
    object network MGMT-1-Network
    subnet 192.168.180.0 255.255.255.0
    description MGMT-1 Network
    object network MGMT-2-Network
    subnet 192.168.181.0 255.255.255.0
    description MGMT-2 Network
    object network SUNCOR-PUP-1-Network
    subnet 192.168.3.0 255.255.255.0
    description SUNCOR-PUP-1 Network
    object network SUNCOR-PUP-2-Network
    subnet 192.168.4.0 255.255.255.0
    description SUNCOR-PUP-2 Network
    object network DEV-PUB-1-Network-PNAT
    subnet 192.168.0.0 255.255.255.0
    description DEV-PUB-1-Network with PNAT
    object network DEV-PUB-2-Network-PNAT
    subnet 192.168.2.0 255.255.255.0
    description DEV-PUB-2-Network with PNAT
    object network MGMT-1-Network-PNAT
    subnet 192.168.180.0 255.255.255.0
    description MGMT-1-Network with PNAT
    object network MGMT-2-Network-PNAT
    subnet 192.168.181.0 255.255.255.0
    description MGMT-2-Network with PNAT
    object network SUNCOR-PUB-1-Network-PNAT
    subnet 192.168.3.0 255.255.255.0
    description SUNCOR-PUB-1-Network with PNAT
    object network SUNCOR-PUB-2-Network-PNAT
    subnet 192.168.4.0 255.255.255.0
    description SUNCOR-PUB-2-Network with PNAT
    object network DEV-APP-1-PUB
    host 198.XX.XX.XX
    description DEV-APP-2 Public Server IP
    object network DEV-APP-2-SNAT
    host 192.168.2.120
    description DEV-APP-2 Server with SNAT
    object network DEV-APP-2-PUB
    host 198.XX.XX.XX
    description DEV-APP-2 Public Server IP
    object network DEV-SQL-1
    host 192.168.0.110
    description DEV-SQL-1 Inside Server IP
    object network DEV-SQL-2
    host 192.168.2.110
    description DEV-SQL-2 Inside Server IP
    object network SUCNOR-APP-1-PUB
    host 198.XX.XX.XX
    description SUNCOR-APP-1 Public Server IP
    object network SUNCOR-APP-2-SNAT
    host 192.168.4.120
    description SUNCOR-APP-2 Server with SNAT
    object network SUNCOR-APP-2-PUB
    host 198.XX.XX.XX
    description DEV-APP-2 Public Server IP
    object network SUNCOR-SQL-1
    host 192.168.3.110
    description SUNCOR-SQL-1 Inside Server IP
    object network SUNCOR-SQL-2
    host 192.168.4.110
    description SUNCOR-SQL-2 Inside Server IP
    object network DEV-APP-1-SNAT
    host 192.168.0.120
    description DEV-APP-1 Network with SNAT
    object network SUNCOR-APP-1-SNAT
    host 192.168.3.120
    description SUNCOR-APP-1 Network with SNAT
    object network PDX-LAN
    subnet 192.168.1.0 255.255.255.0
    description PDX-LAN for S2S VPN
    object network PDX-Sonicwall
    host XX.XX.XX.XX
    object network LOGI-NLB--SNAT
    host 192.168.0.53
    description Logi NLB with SNAT
    object network LOGI-PUP-IP
    host 198.XX.XX.87
    description Public IP of LOGI server for NLB
    object network LOGI-NLB-IP
    host 192.168.0.53
    description LOGI NLB IP
    object network LOGI-PUP-SNAT-NLB
    host 198.XX.XX.87
    description LOGI Pup with SNAT to NLB
    object-group network vpn-inside
    description All inside accessible networks
    object-group network VPN-Inside-Networks
    description All Inside Nets for Remote VPN Access
    network-object object Inside-Native-Network
    network-object object DEV-PUP-1-Network
    network-object object DEV-PUP-2-Network
    network-object object MGMT-1-Network
    network-object object MGMT-2-Network
    network-object object SUNCOR-PUP-1-Network
    network-object object SUNCOR-PUP-2-Network
    access-list acl-vpnclinet extended permit ip object-group VPN-Inside-Networks any
    access-list outside_access_out remark Block ping to out networks
    access-list outside_access_out extended deny icmp any any inactive
    access-list outside_access_out remark Allow all traffic from inside to outside networks
    access-list outside_access_out extended permit ip any any
    access-list outside_access extended permit ip any object LOGI-NLB--SNAT
    access-list outside_access extended permit ip any object SUNCOR-APP-2-SNAT
    access-list outside_access extended permit ip any object SUNCOR-APP-1-SNAT
    access-list outside_access extended permit ip any object DEV-APP-2-SNAT
    access-list outside_access extended permit ip any object DEV-APP-1-SNAT
    access-list outside_cryptomap extended permit ip object-group VPN-Inside-Networks object PDX-LAN
    pager lines 24
    logging asdm informational
    mtu outside 1500
    mtu Port-1-GI-Inside-Native 1500
    mtu MGMT-1 1500
    mtu MGMT-2 1500
    mtu DEV-PUB-1 1500
    mtu DEV-PUB-2 1500
    mtu SUNCOR-PUB-1 1500
    mtu SUNCOR-PUB-2 1500
    mtu management 1500
    ip local pool Remote-VPN-Pool 192.168.100.1-192.168.100.20 mask 255.255.255.0
    no failover
    icmp unreachable rate-limit 1 burst-size 1
    icmp permit any outside
    icmp permit any Port-1-GI-Inside-Native
    icmp permit any MGMT-1
    icmp permit any MGMT-2
    icmp permit any DEV-PUB-1
    icmp permit any DEV-PUB-2
    icmp permit any SUNCOR-PUB-1
    icmp permit any SUNCOR-PUB-2
    asdm image disk0:/asdm-649-103.bin
    no asdm history enable
    arp DEV-PUB-1 192.168.0.53 0100.5e7f.0035 alias
    arp timeout 14400
    no arp permit-nonconnected
    nat (Port-1-GI-Inside-Native,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (DEV-PUB-1,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (DEV-PUB-2,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (MGMT-1,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (MGMT-2,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (SUNCOR-PUB-1,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (SUNCOR-PUB-2,outside) source static any any destination static VPN-POOL-PNAT VPN-POOL-PNAT
    nat (DEV-PUB-1,outside) source static DEV-PUP-1-Network DEV-PUP-1-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    nat (DEV-PUB-2,outside) source static DEV-PUP-2-Network DEV-PUP-2-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    nat (MGMT-1,outside) source static MGMT-1-Network MGMT-1-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    nat (MGMT-2,outside) source static MGMT-2-Network MGMT-2-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    nat (Port-1-GI-Inside-Native,outside) source static Inside-Native-Network Inside-Native-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    nat (SUNCOR-PUB-1,outside) source static SUNCOR-PUP-1-Network SUNCOR-PUP-1-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    nat (SUNCOR-PUB-2,outside) source static SUNCOR-PUP-2-Network SUNCOR-PUP-2-Network destination static PDX-LAN PDX-LAN no-proxy-arp route-lookup
    object network Inside-Native-Network-PNAT
    nat (Port-1-GI-Inside-Native,outside) dynamic interface
    object network VPN-POOL-PNAT
    nat (Port-1-GI-Inside-Native,outside) dynamic interface
    object network DEV-PUB-1-Network-PNAT
    nat (DEV-PUB-1,outside) dynamic interface
    object network DEV-PUB-2-Network-PNAT
    nat (DEV-PUB-2,outside) dynamic interface
    object network MGMT-1-Network-PNAT
    nat (MGMT-1,outside) dynamic interface
    object network MGMT-2-Network-PNAT
    nat (MGMT-2,outside) dynamic interface
    object network SUNCOR-PUB-1-Network-PNAT
    nat (SUNCOR-PUB-1,outside) dynamic interface
    object network SUNCOR-PUB-2-Network-PNAT
    nat (SUNCOR-PUB-2,outside) dynamic interface
    object network DEV-APP-2-SNAT
    nat (DEV-PUB-2,outside) static DEV-APP-2-PUB
    object network SUNCOR-APP-2-SNAT
    nat (SUNCOR-PUB-2,outside) static SUNCOR-APP-2-PUB
    object network DEV-APP-1-SNAT
    nat (DEV-PUB-1,outside) static DEV-APP-1-PUB
    object network SUNCOR-APP-1-SNAT
    nat (SUNCOR-PUB-1,outside) static SUCNOR-APP-1-PUB
    object network LOGI-NLB--SNAT
    nat (DEV-PUB-1,outside) static LOGI-PUP-IP
    object network LOGI-PUP-SNAT-NLB
    nat (outside,DEV-PUB-1) static LOGI-NLB-IP
    access-group outside_access in interface outside
    access-group outside_access_out out interface outside
    route outside 0.0.0.0 0.0.0.0 198.145.120.81 1
    timeout xlate 3:00:00
    timeout pat-xlate 0:00:30
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
    timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
    timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    timeout floating-conn 0:00:00
    dynamic-access-policy-record DfltAccessPolicy
    user-identity default-domain LOCAL
    http server enable
    http 192.168.1.0 255.255.255.0 management
    http 192.168.1.0 255.255.255.0 outside
    http 10.1.1.0 255.255.255.0 Port-1-GI-Inside-Native
    http 192.168.180.0 255.255.255.0 MGMT-1
    http 192.168.100.0 255.255.255.0 Port-1-GI-Inside-Native
    no snmp-server location
    no snmp-server contact
    snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart
    class-map inspection_default
    match default-inspection-traffic
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum client auto
      message-length maximum 512
    policy-map global_policy
    class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect rsh
      inspect rtsp
      inspect esmtp
      inspect sqlnet
      inspect skinny 
      inspect sunrpc
      inspect xdmcp
      inspect sip 
      inspect netbios
      inspect tftp
      inspect ip-options
      inspect icmp
      inspect icmp error
    service-policy global_policy global
    prompt hostname context
    call-home reporting anonymous
    call-home
    profile CiscoTAC-1
      no active
      destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
      destination address email [email protected]
      destination transport-method http
      subscribe-to-alert-group diagnostic
      subscribe-to-alert-group environment
      subscribe-to-alert-group inventory periodic monthly
      subscribe-to-alert-group configuration periodic monthly
      subscribe-to-alert-group telemetry periodic daily
    Cryptochecksum:d6f9f8e2113dc03cede9f2454dba029b
    : end
    Any help would be great! I think the issue is in teh NAT as I am able to access NLB IP from the outside and could not do that before adding the Static ARP stuff. 
    Thanks,
    Chris

    Also If I change to NAT from the public IP to the NLB IP to use either one of the phsyical IPs of the NLB cluster (192.168.0.50 or 51) it works fine when using the public IP.  So it's definatly an issue when NATing the VIP of NLB cluster.
    Chris

  • NAT-PMP and UDP broken

    It seems like the implementation of NAT-PMP with UDP is broken or not well thought out.
    For example if I mapwith NAT-PMP UDP port 1111 to a local machine with the same port, traffic destin to external port 1111 reaches my internal machine fine. The problem however lies with traffic generated from the internal machine with a source port of 1111. It doesn't get mapped to 1111 source while leaving the Airport Extream router, it gets mapped like regular traffic, on some high port.
    Now this incorrect mapping causes a problem while talking with some peers that are also behind a NAT or Firewall. After talking to my device at port 1111, they expect the reply to come back with a source of 1111, which it doesn't so the P2P communications fails.
    FYI every UPNP router I've tried correctly maps the outbound traffic.
    This is with the latest firmware 7.3.2 on an Airport Extreme with 802.11n (gigabit ethernet).
    I hope someone at apple reads this and can put this in a bug database.

    I fixed my problem.
    This old thread: http://discussions.apple.com/thread.jspa?messageID=6925383
    talked about the exact problem I was seeing.
    I had set a manual port map for my SlingBox in the AirPort's settings, not realizing that the SlingBox supports NAT-PMP and can auto configure its own port mapping wit the AirPort. Removing the manually mapped port worked.
    Though it's not exactly the problem you are seeing, maybe you can check to see if there are any apps you are using for which you manually mapped a port, that can auto configure its own port mapping. It could be causing a conflict in the AirPort that screws up NAT-PMP.

  • My .tif images from Ps have broken text on it in Motion 3! Can anyone HELP?

    Hi guys,
    I imported .tif files (Bottle images w/text on it @ 300 Resolution) from photoshop into Motion project but the text is not clear.
    The text looks all broken up.
    My workflow was FCP to Motion and back and even back in fcp the text on the bottles are broken up but everything else looks great.
    The same .tif files I used in fcp in another place on the timeline and they look great.
    Can anyone please help me with this issue?
    Many thanks in advance,
    Zia

    If the image is bigger than 2k than it may be too big for your GPU to handle unless you've got a new nvidia which can handle 4k. I just figured they might be big images if theyr'e 300dpi. O yea and obviously make sure it's RGB and not CMYK. Again i'm guessing what you have may be a large print file.

  • How do I change my NAT from "strict" so I can properly use Xbox LIVE?

    I am able to connect to Xbox LIVE, but the Xbox (360) reports my NAT as "strict", which means I don't have a good connection and can't even participate in some things like tournaments on Project Gotham Racing 3.
    I've spent hours researching this on the net. No luck yet, but here's what I've tried so far:
    One post (http://forums.xbox.com/8109385/PrintPost.aspx) said there are three ways to fix my problem: (1) Use UPnp (universal plug 'n' play, the equivalent of which on the Airport Express seems to be NAT Port Mapping Protocol), (2) Set up a DMZ (demilitarized zone, which is called a Default Host by the Airport Express), and (3) Port Mapping.
    First, turning on NAT Port Mapping Protocol doesn't have an effect on my Xbox-reported NAT rating of "strict".
    Second, I tried setting up a Default Host at 10.0.1.253 then assigning my Xbox an IP of 10.0.1.253. I assigned this IP only through the Xbox's network settings. It seems like I was supposed to assign the IP to the Xbox using the Airport Admin Utility, but if there's a way of doing so, I don't see it. Also within the Xbox's network settings, I set the subnet mask to 255.255.255.0 and the gateway to 10.0.1.1 (my Airport Expres). When I tested the connection to Xbox LIVE, I failed at the DNS stage. So I manually set the DNS info to the primary and secondary DNS specified by my ISP (and shown in the Internet tab of Airport Admin Utility). I retested my connection to Xbox LIVE. Now I passed the DNS test but failed the next test, called MTU. I looked up how to set the MTU and did so according to these instructions from the Apple Support pages: http://docs.info.apple.com/article.html?artnum=303192. I tried MTU values of 1400, 1500, 1362 (recommended minimum specified on Xbox), and 3000 but was unable to pass the MTU test on the Xbox.
    I tried port mapping as explained on the Microsoft Xbox forums (http://support.microsoft.com/kb/908874) and further explained here: http://www.jakeludington.com/xbox/20060103xbox_live_connectionproblems.html. I tried to do this with the Port Mapping tab in Airport Admin Utility, but I wasn't able to specify all of the information given in that last link, so I don't know if I did it right.
    Hours of work and no success, but this ought to be possible, right? Help?
    20" iMac 1.25GHz G4   Mac OS X (10.4.4)  

    I tried to do this with the Port Mapping tab in Airport Admin Utility, but I wasn't able to specify all of the information given in that last link, so I don't know if I did it right.
    As you already know, XBox Live requires three ports to communicate: UDP 88, UDP 3074, & TCP 3074. The AirPort Express Base Station doesn't distinguish between UDP & TCP for port mapping, so you will only need to map one port for the UDP/TCP 3074 values.
    Try the following...
    Port Mapping tab
    - Click "Add"
    - Public Port: 88
    - Private Address: 10.0.1.253
    - Private Port: 88
    - Click "Ok"
    - Click "Add"
    - Public Port: 3074
    - Private Address: 10.0.1.253
    - Private Port: 3074
    - Click "Ok"

  • Help, Need to change NAT from moderate to open for WRT54GS2

    just like to the topic says i used these methods:
    Open an Internet Explorer browser page on your wired computer(desktop).In the address bar type - 192.168.1.1 and press Enter...Leave Username blank & in Password use admin in lower case...
    On the set-up tab change the MTU Size to 1365 and click Save Settings...
    Click on "Administration" tab and disable the option UPnP and click Save Settings...
    Click on "Applications and Gaming" tab and then click on "Port Range Forwarding" subtab...
    1) On the first line in Application box type in ABC, in the start box type in 53 and End box type in 3074, leave the protocol as both and under ip address type in 192.168.1.20 and check the enable box, click Save Settings once done...
    2) Once you return to the set up page click on the Security tab and uncheck Block Anonymous Internet Requests and click on Save Settings...
    3)Click on the Status tab and take note of DNS1 and DNS2 Addresses...
    4) Goto the XBox Network Settings and IP Address Settings and select manual IP Settings and assign the following on your Xbox IP Address :- 192.168.1.20, Subnet Mask :- 255.255.255.0, Default Gateway :- 192.168.1.1...
    5) Also assign the DNS Addresses on the Xbox, Use DNS1 and DNS2 Addresses you took note off of the router status tab as Primary DNS & Secondary DNS for the xbox...
    6) Turn off your modem, router, and Xbox...Wait for a minute...
    7) Plug the modem power first, wait for another minute and plug the router power cable, wait another minute and turn on the Xbox and test it...it will connect...     i have firmare 1.0.01. i am using 2 Pluglink 9650 Powerline Ethernet Adapters to connect to my xbox for xbox live. if u need anything else let me know. PLEASE SOMEONE HELP 

    What device is upstream from the router?  If you have a modem that acts as a router as well, then you might have a double NAT problem.  It's a well documented problem and can usually be solved by bridging the modem or configuring the router to work as a switch only.

  • Warning: Audio from iMovie08 projects broken in iMovie 09

    I had 6 active projects when I upgrade. Three of them seem to be fine, but the other three dropped their audio tracks that I added. Of the three good ones, all three use audio tracks that are simply drop-in songs from iTunes -- where I selected the audio via the iMovie08 media browser.
    Of the three with issues, one of them had a custom audio track that I'm not sure I can replicate, so that may just be lost.
    The other two were simply songs I dropped in from iTunes via the iMovie08 media browser. The songs show up in the projects pane, but with a yellow exclamation point. When I click play, the movie plays fine, but with no audio.
    So, in these two projects with broken audio from an iTunes track, I simply deleted the broken link and re-dropped the same song in. Now the audio is back, but after about 20 seconds of playing, the movie gets choppy, and playback starts freezing though the audio keeps rolling. I haven't tried export, so I don't know if this impacts the final product, but it does make it unworkable to review my projects.
    Has anyone else had this issue -- where the audio link breaks and, if you fix it, it seems to mess up the video somehow.
    I put this up here both as a request for help, and a warning to others -- back up your projects before upgrading, check each project carefully for the broken audio issue, and if the audio is broken, don't think that just dragging the audio back in will fix the issue.

    I spent some time on the phone with apple today troubleshooting this issue. my projects would freeze the visual while running the audio. They had me download a short movie from apple.com (any .mov file will work). close all apps including imovie. go into home folder/movies and drag the imovie events and imovie projects folders to the desktop. this essentially erases all the info in imovie. then open imovie and make sure there is no content inside. once confirmed go to file/import/movies and import a .mov file you know is clean (i would suggest a short one to keep from spending a long time). when the movie shows up in your library select a clip and put it in a new project. does it play both audio and video? if yes the problem is with your clips. if no you have faulty software and will need to replace ilife. go back to home folder/movies and drag the imovie folders on the desktop back. it will ask you if you want to replace existing folders. say yes or continue. if the clip you tested earlier played fine you will have to reinstall ilife and rebuild all events you want to work.
    this is a pain but it works. mine is back to normal.

  • Paste from illustrator now broken after update

    after the latest update of Pages 08, i can no longer paste symbols from Illustrator CS. certain parts of the symbols are broken up after Pages gives me an error message reading: The media can't be used because you don't have access privileges, because it has no content or is corrupt.
    worked fine last week.
    thanks,
    eric

    See this discussion to see if it helps. iPhone 4 Message:SIM Required (in phone that has no SIM card slot)  While it was originally for the iPhone 4, I have seen a couple of Verizon 4s customers also post. You will need to contact Apple back, however their support line, and escalate the call to a Senior Engineer to get assistance.

  • Migrating files from ibook with broken drive

    i have an iBook G4 with a broken hard drive and there's a CD stuck in there that won't come out. i just bought a new MacBook Pro. Is there any way to get my files from the old iBook to the new MacBook Pro without installing new software on the old Mac?

    with the hard drive damaged will the CD still eject if you hold down the track pad select switch at startup?
    If it is free, it should. I don't think it is dependent on the HDD at all. But if it is stuck in there, the trackpad button may not make a difference. Worth a try, anyway.
    Here are suggestions of different options:
    PowerPC-based Macintosh: How to eject a disc when other options don't work
    Ejecting a CD or DVD when all else fails
    Ejecting a disc from the PowerBook G4 disc drive
    Dr. Mac: A dozen ways to eject or unmount a recalcitrant CD or DVD...
    Force Eject 1.0: Free Download
    Hope one of these work for you.
    cornelius

  • NAT from a secondary subnet

    I have been testing a scenario and not having much success, so I would like
    to know if this is even possible.
    I have a real-world subnet with a 255.255.255.240 mask. I am natting
    several addresses internally and it works perfectly.
    I have run out of addresses and so I'm trying to add another subnet. I
    added a secondary binding to an address on another subnet with a
    255.255.255.248 mask. This works fine, but when I try to setup NAT for an
    address on this subnet, it doesn't work.
    I tried NAT'ing from both subnets to the same address and that didn't work.
    I removed the NAT entry from the original subnet and just used the new one
    and that didn't work either.
    Can NAT only work from a Primary IP binding?
    Keith

    That will be because the core switch is relying on an arp table and it
    then has to deal with 2 subnets... this can be a problem. I didn't
    realise that you were using a big switch with VLANs so...
    The solution of the second public NIC could work well though, as then
    only hosted services use one NIC and the outbound stuff could use the
    second :-)
    Good luck
    On Wed, 12 Oct 2005 12:22:15 GMT, "Keith Larson"
    <[email protected]> wrote:
    >i did exactly that and got some very bad results. i can't tell if the
    >routing within the server got screwed up or it caused a serious ARP issue in
    >the switch that the server was plugged into. I lost all of my outside
    >services that were tied to the original subnet until i removed the binding
    >on the new subnet.
    >
    >when i make this binding on the second subnet to a different physical nic,
    >everything works perfectly.
    >
    >if i go back to a second binding on the same physical nic. everything on
    >the inside and on the physical subnet can ping everything perfectly. the
    >core switch that everything is plugged into can ping all addresses on the
    >original subnet and the secondary address on the second subnet, but can't
    >ping the actual binding for the second subnet. we worked backwards from
    >that switch to the internet and found one more farther away could do exactly
    >the same thing. ping the secondary on the second subnet, but not the actual
    >binding address. beyond that router nobody could ping anything on the
    >second subnet. so everything on this new subnet was unreachable from the
    >internet.
    >
    >really bizarre....
    >
    Tim
    Tim Heywood (SYSOP)
    NDS8
    Scotland
    (God's Country)
    www.nds8.co.uk
    http://support.novell.com/forums/
    In theory, practice and theory are the same
    In Practice, they are different

  • Last flash player from Adobe is broken

    Hello
    Last flash player from Adobe seems to be broken when using with Chatroulette:
    on Macbook Air camera stopped working
    on iMac 27" works, but Safari takes 100% cpu (when Flash Player is running with Chatroulette)
    Other users experience the same
    My configuration
    Mac OS 10.6.4
    Flash Player: 10.1.102.64, 10,1,103,19
    Safari, Chrome
    I tried re-installing Flash Player, creating new account, changing language, changing browsers, running Disc Utility = nothing helped
    I tried downloading Chrome because I heard there is different version of Flash Player (10,1,103,19)
    Result is same.
    Hardware is brand new, operating system is brand new. Everything worked until last flash update.
    Please assist! Some of our users experience the same problems
    As a temporary solution I have installed Adobe Flash Player 10.2 but it is unstable and our users cannot do that. However it works
    Thanks much
    Andrey

    This is STILL an issue.   There is something badly broken in the Mac version of Flash 10.   I have a brand new macbook pro, and had the original install of flash 9.  My cameras worked fine.   When I upgraded to 10 -- and yes, I *did* uninstall the previous version -- I lost the ability to config my camera, since it stopped appearing in the control panel dialog.
    I uninstalled Flash 10, saying many not-so-nice things about Adobe and their exceptionally poor QA in the process, and re-installed Flash 9.   Sure enough, my cam worked like a charm. 
    Hey Adobe guys:   If you are reading these forums, PLEASE try to fix this!!!!  Downgrading is only a temporary fix, as more and more sites are specifically requiring for Flash 10.
    GET YOUR QA TEAM TO TEST THIS!!!!!!!!!  PLEASE!!!!!!!!

  • Can i use a iMac from 2008 with broken graphic card as extra monitor

    Can i use My Old iMac as a extra monitor.  My Old iMac from early 2008 has a broken graphic card nvidia 8800 gs. When I start it up I hear the bong and see the symbol spinning then the screen goes black from right to left the computer is running but I can't use it. I assume it's the graphic card. Can I use this iMac as an extra monitor to my other iMac.?

    No sorry.

  • Can i change NAT from moderate to open on WRT160N

    I use to play xbox live with a wrt54g and had an open nat now i have a wrt160n and when i test the connection on the xbox it comes up moderate.

    Change the MTU size from auto to manual .... & 1500 to 1365 ....
    Click save settings ...
    Check the NAT settings again ...

Maybe you are looking for

  • IMAP Sync not working (unread marks)

    We have a number of users that are set up with GMail as a personal email address on their blackberry.  If you read an email on the blackberry or delete an email on the blackberry it will sync that to GMail and the message will be read or deleted.  If

  • Importing from P2 Firestore problems

    Hello there, I have been attempting to import clips from a focus enhancements firestore, which is alternative to the P2 cards for the Panasonic HVX200. When I try to import these clips I get an message that reads "Cannot import possible corrupt or in

  • WLC and preventing access based upon device type

    Hello, I know this may be slightly offbase, and may be more of a Microsoft question, but I'll ask anyway. Here is my problem.  We have a WPA secured wireless network.   Users are now connecting there Iphones & Droids to this network.  We want to prev

  • Unable to install ovi suit in windows 7

    i tried hard but my dvd-rom doesnt even detect the ovi suit disk !!!!!!!!!!!! it hangs 'my computer' 

  • Drop down values not visible

    Hello All, i have a drop down which is filled by the data from R/3. When i run my Web Dynpro appliocation, the drop down is getting populated, but when i run in the portal initially the drop down shrinks such that it dosent have any values but there