IP Address Assign & Port Forwarding

Using the UFO Airport Extreme and Xpress.
I want to use one of my system to host a server. How do I assign an IP Address to that particular host?
A problem I tried port forwarding to an IP address is let say I want to assign to this system (say 10.0.1.5), when I tell it to forward data to that IP on whatever port, Airport reboots and reassign a different IP address. This is annoying.
I have some PC running also and when I tried to use the Access Control List, some PC doesnt want to connect, even when the password is disabled and the ACL is on, and I double checked the MAC address, the PC cannot connect.

Yes you need to assign that computer a static IP address outside the range used by the DHCP server in the AirPort Extreme base station (AEBS). By default the DHCP server uses addresses 10.0.1.2 to 10.0.1.200 so using an address in the range 10.0.1.201 to 10.20.1.254 is safe.

Similar Messages

  • ASA 8.4(2) doesn't respond to ICMP echo on ip address with port forwarding only

    Hello,
    In order to meet our requirements we had to configure PAT for TCP 80 on 2 external IP addresses to one internal IP in DMZ. TCP port 80 is being translated for both external IP addresses and it works as expected. However, since we have migrated to ASA both external IP addresses don't respond to ICMP echo requests generating following error:
    %ASA-3-106014: Deny inbound icmp src outside:<Source IP> dst outside:<Destination IP> (type 8, code 0)
    Previously we have been using Cisco router to achieve the same objective and it worked well.
    I have noticed that when I add "same-security-traffic permit intra-interface" to a configuration the message mentioned above stops appearing in a logs.
    As far as I can tell ASA sends packet back through outside interface, despite the fact that appliance advertises its mac address in response to arp request for the same external IP address.
    Is there any way to make ASA realise that it should respond to ICMP echo requests on external IP addresses that have forwarding setup?
    I do realise that ICMP would work in 1-to-1 NAT scenario, but we can't apply 1-to-1 NAT for 2 external IP addresses to point to one internal IP address.
    Kind Regards,
    Paul Preston

    Hi Julio,
    Interesting. I have tried to map two external IP addresses with using 1 to 1 nat to a single internal IP, but when I tried to configure a second one I remember a message "mapping exists"...
    I think that it might be easier if I paste relevent config:
    access-list From_Internet extended permit icmp any any
    access-list From_Internet extended permit tcp any gt 1023 host 172.17.0.103 eq www
    access-list From_Internet extended deny ip any any log warnings
    object network www-91-17.103
    host 172.17.0.103
    object network www-92-17.103
    host 172.17.0.103
    icmp permit any outside
    object network www-91-17.103
    nat (DMZ,outside) static x.x.x.91 service tcp www www
    object network www-92-17.103
    nat (DMZ,outside) static x.x.x.92 service tcp www www
    With a config above NAT works for both IP addresses, but unfortunately neither IP address respond to icmp echo requests.
    Kind Regards,
    Paul Preston

  • Weird conflicts adding port forwarding rules

    I've just joined BT and I'm trying to add the portforwarding rules I need and had on my previous router (Thompson 585v7).
    I created a ruleset named "eMule (38297)" forwarding TCP 38297 and UDP 16318.
    When I go to assign it, I select the rule then my PC and it changes the name to "BT HomeSafe CameraeMule (38297)" and when I click Add it just shows it as "BT HomeSafe Camera". So I checked this rule by going to Add User Defined and selecting Copy an existing rule and then BT HomeSafe Camera and it shows that this is forwarding TCP/UDP 1024 which doesn't conflict with my eMule rule whatsoever.
    I have the same problem with a rule to forward TCP/UDP 3071-3072, which the Hub mixes up with PalTalk, which forwards 2090-2091 and 2095 and a rule to forward TCP/UDP 52616 which it mixes up with Rainbow Six, which forwards TCP/UDP 2346. In fact, pretty much any ruleset I've created has this problem when I go to assign it.
    So basically it's a big old mess and I wonder if anyone knows how to fix it
    Solved!
    Go to Solution.

    This page may help to sort out your problem.
    Port forwarding problems
    You need to give your devices static IP addresses, and port forward to the IP address, not the device name.
    You should be able to copy an existing assignment, but remember to rename the new application first.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Actiontec Rev. F port forwarding - is filtering by IP possible?

    I would like to know if Actiontect Rev. F router allows filtering by IP address for port forwarding (similar to Windows 7 firewall, Advanced Settings, "Scope" tab). That is I want only requests from specific external IP address to be allowed through.

    Points to your other thread at
    http://www.dslreports.com/forum/r26265890-Windows-7-firewall-and-port-forwarding-from-FIOS-router
    If you are the original poster (OP) and your issue is solved, please remember to click the "Solution?" button so that others can more easily find it. If anyone has been helpful to you, please show your appreciation by clicking the "Kudos" button.

  • Setting up Time Capsule as primary wireless router and enabling port forwarding

    I am attempting to setup my Time Capsule as the primary router on my wireless network. I have an Actiontec Verizon FIOS router that I am connecting the TC to using ethernet, and I was then going to turn off the wireless function on the Verizon router so that the TC will be the only wireless router. I am not exactly sure how to go about this, and I also have to connect a wireless device to the TC that requires a static IP address and port forwarding enabled so that I can access from my iPhone. I am completely lost on how to do this, any help will be greatly appreciated.

    Unless Verizon has made a major change in the last few days, you will not be able to use the TC as the primary router......simply because it is not possible to configure the Verizon router to act as a simple modem......which is what it must do if you want to have the TC act as the primary router on your network.
    As LaPastenague has explained. turning off the wireless on the Verizon modem/router will not make it a modem.  It will still be a wired modem/router in charge of the network, not allowing the Time Capsule to take over the role of main router for the network.
    But, let's assume that I am wrong. Please check with Verizon support and ask them........
    1) If it is somehow now possible to configure their modem/router to act as a simple bridge mode modem. If they say that this is not possible (or they will not support this).....
    2) Ask them if they can provide you with a simple, bridge mode modem......instead of the modem/router that you have now. A simple modem will have only one Ethernet port, and it will not offer any type of routing or wireless service at all.)

  • Port Forward and IP address question

    I am configuring my father's computer so that I can "see" his screen. He's on a different network, using a mac with a wireless router. He enables remote desktop login, I use Chicken of the VNC software on my mac to see and control his computer.
    Here's my question, when I set up his router to forward the ports so this will work, do I use the ports for apple remote desktop or VNC? (The ports overlap (5900) but are different.)
    Also, which IP address do I enter into Chicken of the VNC? His router IP, his static IP that we assigned or his computer's IP.
    Thanks for the help,
    Rob

    ok, but in his prefs for apple remote desktop, it gives the static IP address that we set as the address other people can use, so... any thoughts?
    You use that private address if you are in the same subnet as his Mac. That is the address you enter into the port forwarding settings on the router because the router needs to send requests received on the public IP address to that unreachable private IP address.
    When you are on the internet, you can't reach that private IP address.

  • Port Forwarding and Static IP addresses

    Netcomm NB1300 router and Airport Express.
    I want to use and old G3 mac running 10.3.9 as a server for HTTP and FTP. The Mac is currently connected via Airport but I can connect it via Ethernet if necessary.
    I understand that I will have to activate Port Forwarding on my Router with Ports 21 and 80 to allow external Internet access to the G3. I will also have to configure DHCP Manually for a Static IP address and probably link up with a Free DNS service to maintain reliable access to the G3.
    I have other computers on the network, two Macs (Ethernet / 10.3.9 & Airport 10.4.11) and two PC's (one with Vista, one with XP / both on Airport). Only one of the extra Macs is connected via ethernet, the rest are connected via Airport.
    Will I have to assign Static IP addresses to all the computers or just the one I want to use as a server?
    And also, can anyone tell me about Port Forwarding via Port 22 to give more security from external observation/attacks? I know nothing about this security measure.
    Thanks in advance.
    Christo.

    Hi--
    Christo wrote:
    I am now assuming I will be able to access the 'server' from an external location. Very optimistic! But I can't test that for a couple of days.
    Ah, but you've given up too soon! You can access your web server from outside your network real easy: you just need to find an external client you can point back to your site. I like to use the W4C validator to do that. It has the happy side effect of also telling you if your web page markup is valid. So you'd point your browser to the validator page:
    http://validator.w3.org/
    I like to choose "More Options" and tell it to show the page source. That way I can also verify that it's seeing the page I want it to see.
    If I disconnect the iBook from Ethernet, can it still be accessible from an external location if it is connected to the Router via Airport, or do I have do so something like Port Forwarding with my Airport Express as well? Note the iBook can still connect to the Internet via Airport.
    It would depend on how your Airport is set up. I think there are a couple of ways to set them up. One is to make the Airport a DHCP server, which would make the wireless network essentially a separate network. In that case, you'd have to forward throught the Airport, too.
    My wireless network, though, is set up to bridge, so it's all one network. In that case, all I'd have to do to forward wirelessly to a client would be to set up the forward on the main router.
    Being that persons other than myself will be accessing the iBook via FTP, do I give them the user account password of the Mac, or can I set a password in the Router or something else?
    Also, when accessing the iBook on my local network using Cyberduck, I can see the entire directory of the iBook's user account. Is there a way to limit access to just one folder, such as the Public folder, or a self-designated folder?
    Unfortunately, I don't know anything about setting up FTP. I would suggest that you look into maybe making an account on the iBook specifically for the FTP user and only give out that username and password. You might want to poke around in the Networking and the Web and Unix discussions in the Mac OS X Technologies area. I've seen a number of posts there about setting up FTP, and you might be able to find your answers there.
    charlie

  • Port Forwarding and Printing with Static IP Address

    Hey there -
    I am trying to setup a network printer that can be printed to from anywhere in the world. My organization has 5 static IP addresses given to us by our ISP. Four of those I have on computers, and one of them I have on my Linksys router (WRT54G v.8).
    What I want to do is be able to setup a printer on my router that I can print to from anywhere I have an internet connection. My wireless router's static IP address is 74.172.54.XXX - The address on my network is 192.168.7.1 - I have a printer statically assigned the IP address 192.168.7.2 - and I have a port forwarding for port 70 to forward to 192.168.7.2
    In theory, I would think that now I could print to 74.172.54.XXX:70 and have no problems. But that doesn't seem to be working. Even printing to 192.168.7.1:70 doesn't seem to work either.
    Also, the printer has a web GUI interface that if I type http://192.168.7.1/ into my browser it comes up, so in theory I would think typing http://74.172.54.XXX:70 into my browser it should come up (but it doesn't nor does http://192.168.7.1:70).
    Anybody got any suggestions? I tried to do a search about this, but ever Port Forwarding question seemed to deal with gaming (which I have no desire to do). Thanks!
    I will include two screen snapshots of what I am talking about:
    Thanks for any help.

    Is the router setup to accept static connections?
    I have my router set up to accept both, so from 192.168.1.100 to 192.168.1.192 the addresses are static the other addresses are given by DHCP.
    If you do not define a range and the address your laptop has as static IP conflicts with the address given by DHCP your loose ... as in you get no address.
    Set up of that feature may depend on your type of router but usually any decent router will have that capability ... read your manual for specifics about your unit.
    Best of luck.
    R.
    Last edited by ralvez (2009-12-10 00:08:50)

  • Port forwarding to ip address only allows input of last digits

    I have the Linksys BEFW11S4 router and am trying to port forward to a static ip address but the port forwarding screen is hard coded to 192.168.1.__ and only allows me to enter the last 3 digits of the quartet. Does anyone know how I can get past this? I'm trying to connect a DVR server using this static ip address.

    If your ISP assigns you a static public IP address and you are required by your ISP to configure that on your router, then you have to configure the static IP, subnet mask, gateway IP and DNS servers in the internet connection section of the main setup page in the web interface of the router.
    You then assign a static local IP address like 192.168.1.25 to your DVR, subnet mask 255.255.255.0, gateway 192.168.1.1 and DNS 192.168.1.1 or the DNS servers of your ISP.
    You don't have to disable the DHCP server function in the router.

  • Port Forwarding to specific public IP Address

    Hi, I would like to forward ports to a specific public IP address.
    I could do this with my old cheapo Netgear router, is this possible with the Airport Extreme?
    So far I have assigned a static private IP address, and I can open ports to the world, but I only want a specific public IP to be allowed through and I can't see a way to do this through the Airport Utility (6.1).

    Port forwarding, on the AirPort routers, is designed to work with private IP addresses on your local area network. These private IP addresses can either by dynamic or static. It allows for any communication coming from the Internet (any public IP address) to the local IP address via a specific port or ports.

  • Network Address Translation, Automatic Port Forwarding

    Does the Airport Extreme do
    Network Address Translation? Do I have to do something to make NAT functional?
    Does the Airport Extreme automatically forward ports? Or is this something I have to do manually
    sorry if this is discussed already but a Search of Forum did did not yield the information I need.

    Hi Barbara, welcome to the discussion area!
    +Does the Airport Extreme do Network Address Translation?+
    Yes
    +Do I have to do something to make NAT functional?+
    No, if you have the device configured as a router with the Connection Sharing settings set to Share a public IP address so that the AirPort Extreme is handling the chore of assigning IP addresses to connected devices.
    If you have the AirPort Extreme configured as a "bridge", then NAT is handled by the router that is upstream of the AirPort Extreme.
    +Does the Airport Extreme automatically forward ports? Or is this something I have to do manually+
    Port forwarding must be setup manually on the AirPort Extreme using AirPort Utility, the application used to setup the AirPorts.

  • NATing issue (port forwarding) MPLS Outside address is a local address

    I'm trying to figure out if what I've been asked to do is even possible.
    Current topology for the office in question:
    Internet -> ISP Gateway (no control) -> MPLS Cloud -> (10.1.1.0 outside) My 2800 Router (full control) -> Local network (10.10.10.0) Inside
    We have a public IP address that is translated at the ISP gateway to an IP address on our local 10.10.10.0 network before it enters the MPLS cloud.  As it enters my outside interface the destination address is already set to a 10.10.10.0 address (for example 10.10.10.1).
    I have been asked to make additional network devices available from the public Internet, but I only have one public IP address assigned to our network.
    Is it possible to utilize port forwarding in this situation?  When the traffic comes into my router it's already addressed for the local network, it is passing from an outside to an inside interface.  However the local IP address and the global IP address would both be a part of my local network, since the public IP address is NATed at the ISP gateway to an IP address on my local network.
    So the 10.10.10.1 address is for our web server and needs 80 and 443 traffic pointed to it, we have a new surveillance system accessible via an app and an IP address on port 7001.  Given what I've described above can you setup something like this:
    ip nat source static tcp 10.10.10.80 7001 10.10.10.1 7001
    I have no clue if you can even setup a NAT like this when the local and global are both in the same subnet.  If anyone has experience with a scenario like this I would appreciate a little feedback.
    Thanks in advance!

    Hello.
    I would say, that the best solution would be to do static translations on ISP gateway (into different internal IP-addresses).

  • Port Forwarding on OSX 10.5 Server using Dynamic External IP Address

    I have been able to get Port Forwarding to work properly on OSX Server by following the documentation and following discussion:
    http://discussions.apple.com/thread.jspa?messageID=6700460
    The problem however, is that you specify a static ip address on the natd.plist file.
    I do not have a static ip address, and sometimes it changes. When this happens, of course all the port forwarding configuration will not work, and I need to replace the old external ip with the new external ip address.
    This is an easy task to be accomplished, however having the internal network down just for the change of ip address is a hassle.
    Is there any way the string entry can be updated with the ip address of the external interface (en0), instead of applying an ip address?
    <key>aliasIP</key>
    <string>17.128.128.128</string>
    I would like to have the ip address (ex: 17.128.128.128) to be updated automatically from my interface ip address. So if my external ip address changes to 17.128.30.30, the natd.plist file will be automatically updated with correct values.
    If I could do the following would be great but doesn't work
    <key>aliasIP</key>
    <string>en0</string>
    Any ideas on how to get this accomplished?
    Or better yet, can it be accomplished as of now?
    I know I can use IPNetRouterX (www.sustworks.com) and that will work just fine. Have tested using the trial and it works, however I do not want to spend $100 for the software either, and I bet there should be a way this can be done on OSX 10.5 Server.
    Thanks a lot!!!

    This would be best reposted in the appropriate Leopard server forum
    http://discussions.apple.com/category.jspa?categoryID=96

  • NAT port-forwarding and WAN side IP addresses

    I have my Airport Extreme setup to forward port 21 to an FTP server on the LAN side of my network. The AE is connected via DSL to my ISP.
    When a client from the WAN side connects to my server, the server's LOGS don't list the IP of the client, rather it says the client connected from my assigned WAN IP. For example (fake ip's):
    Client ----> AE ----> FTP-SERVER
    130.129.12.3 76.99.89.3 10.0.1.2
    Log states client connected
    from IP: 76.99.89.3
    My previous Linksys router, with the same DSL modem and ISP, would report the client as connecting from 130.129.12.3.
    Am I missing something in how I am configureing my AE? Or, is this how the AE manages port-forwarding and there's nothing I can do about it?
    I used to use firewall rules to control access to the FTP server, i.e. rules set on the server. This can't be done anymore with the AE operating as it does.

    Seems to me that the NAT translation in the Airport 802.11n is such that it does not use the incoming IP of clients connecting from the WAN side to a computer on the LAN side. The ingoing and outgoing packets reach their respective destinations, it is just that the AE uses some kind of non-standard routing (at least not that I am used to working with).
    This is bad because it prevents the use of some forms of access controls on BSD and Linux servers on the LAN side, TCP Wrappers and iptables for example. This can create obvious security problems when WAN ports are set to forward to such a LAN client. We are already getting hit with robot-like script attacks on our server, this was a problem with our Linksys router, but with the above mentioned tools and scripts we were able to block abusive clients.
    Perhaps an Apple can work on resolving this issue in a future firmware release, at least make it an option... Anyone from Apple out there?
    jmj

  • Wrt160n is not accepting the ip address in the TO IP ADDRESS box in single port forwarding

    help am i doing some thing wrong here i have followed the instructions from pfconfig for opening a port for Bitcomet but when i try to enter my ip address  it allows me to enter the first 2 digits of the address and then says out of range.
    Bit comet says that i have a nat problem and also vuze. 

    I think you are missing some steps, thats the reason you must be getting that error message.
    Click Here and follow the instructions and you might be able to enable Port Forwarding. 

Maybe you are looking for