Mac OS X Server 1-to-1 Routing: Multiple DSL Static IPs

Hi all -
Question here regarding Mac OS X Server 10.4's ability to handle multiple static IP's coming from my DSL ISP. Can this be handled through the Server Admin GUI or does it need to be done in Terminal with iptables or something similar?
My ultimate goal is to send 1 of the static IPs to a Mac Pro, another to a Mini, another to a DVR, etc.
As a piggyback question - what is the general consensus here on using a Mac Pro or Xserve with Gateway Setup Assistant as a VPN router in place of a traditional SonicWALL / Linksys / Netgear, etc?
Thanks in advance.
Eric

>As a piggyback question - what is the general consensus here on using a Mac Pro or Xserve with Gateway Setup Assistant as a VPN router in place of a traditional SonicWALL / Linksys / Netgear, etc?
Go with the traditional box.
For a few bucks you get a box that's designed for that kind of thing, has a far better interface for managing it, and far more fine-grained control over what traffic can come through.
In addition to that, by having a dedicated hardware router/firewall/NAT device you avoid the chance to leak any services to the public - if you're like most people, your gateway machine isn't just running as a gateway - it's also got sshd running, maybe a web server, file server, DNS server, possible even running as a directory server.
Since this gateway machine, by definition, has its proverbial *** hanging out in the wind there's a possibility that these services could be compromised by remote hackers.
By using a dedicated hardware box you can be very specific about what incoming traffic you want to allow, completely insulating your server from the outside world except for the services you know you really want to be public.

Similar Messages

  • Is Mac OS X Server necessary in this situation?

    My company is doing a trade show circuit. In our trade show booth, we will have 40 computers, which will allow people to signup for a service using a simple web form (submitted data stored in a MySQL database). Because of the exorbitant fees the shows charge for each computer connected to the internet, we want to put the signup form on a machine set up as a web server on the local network in the booth (so we don’t have to pay to connect all 40 machines to the internet).
    We want the machine that hosts the signup form to be as portable as possible. An Apple laptop would be ideal. Obviously, the resource demands of a simple web form are very minimal, but I’m worried about the concurrent connections limitations.
    Can I get by with the regular OS X operating system that will come with the laptop, or do I need to upgrade to the unlimited OS X Server license to make sure that 40 computers can hit the web form at the same time (this wouldn’t likely happen, but I’m preparing for the worst case scenario)?

    Not necessarily Mac OS X Server. Pretty much, all you need is a gateway to the internet that uses NAT.
    You could use a wireless router (secured, of course) to route the wireless clients out to 1 internet connection.
    You could use a wired router, with switches enough for all your clients.
    In either case, you would configure them to use Network Address Translation, configure your clients with a private IP block (i.e. 10.0.0.0/27 or 192.168.0.0) and your router with a private IP on the inside and, most likely, dhcp on the outside.
    For example, you could configure your router to serve DHCP to your clients in the net range 192.168.1.10 - 192.168.1.100, set your router's internal address to 192.168.1.1. The outside interface information would need to be provided by the facility whose net connection you are using, but it will most likely be DHCP. This way, you pay for only 1 internet connection.
    Chris

  • Mac OS X Server 10.5.2 and Time Capsule - Auto-portmapping Issues

    Hi,
    So I recently installed Mac OS X Server 10.5.2 onto my Mac mini media center. During the "Standard Server" Setup Assistant, it detected my Time Capsule and asked for the TC's password to setup automatic portmapping. After getting things up and running, OS X Server apparently sends a refresh of the ports every hour to the TC, which also reboots it. Needless to say, this has caused huge issues in getting the first backup from all my Macs completed.
    I disabled the auto-portmapping by changing my TC's setup password. Now, OS X Server is hitting the TC with a auto-portmap request every MINUTE. This is rather annoying as it's essentially spamming my logs on both OS X Server and the TC. Anyone know how to turn this feature of OS X Server off?

    I can relate to this thread.
    Setup:
    I have a Macmini running OS 10.5.2 server and a TimeCapsule router connected to cable modem.
    I have two other machines that backup onto TimeCapsule via TimeMachine.
    Problem:
    My Macmini server backs-up with TimeMachine locally via USB drive, not to TimeCapsule... Yet I have the same problem. Which is: everytime the server runs TimeMachine, TimeCapsule router disconnects from the internet as the macmini "prepares" the directly connected USB drive. (orange light on front implies that it completely resets itself) It reconnects for the duration of the backup, then resets the router again during the "Preparing..." phase of backup.
    I believe the diagnosis implied by the original tread title is incorrect due to the fact that I have seen the same problem with port mapping completely disabled on the TimeCapsule router.
    Something else is going on when TimeCapsule goes through "Preparing..." that is the cause of the problem

  • Regarding mac os x server 10.6 installation, getting an error" Please inspect your network setting and try again"

    Hi,
    we need your urgent help regarding mac os x server 10.6 installation, actually we are stuck in the installation at the point of Network settings. getting an error " Please inspect your network setting and try again" pls give us a solution of it , would be very thankful.
    MTS

    Well, there isn't much anyone can tell you without more information.
    Clearly the installer is complaining about your proposed network configuration, but without seeing it, or knowing what you expect, it's almost impossible to advise.
    I'd guess that it's some combination of the IP address/subnet mask and router address that's invalid, but without seeing them that's little more than a stab in the dark.

  • Not clear about dns service for new Mac 10.4 server

    Due to low budget, I am given the task to convert a powermac g4 into a Mac 10.4 server. I have already installed it as a stand alone master but will promote it to directory master as soon as I configure proper dns setup.
    Now my westell router shows that the dns is 192.168.1.1 and the domain name as myhomwestell.com, does that mean my zone name has to be westell.com? Can having both dns service conflict with each other or is it fine?

    http://discussions.apple.com/message.jspa?messageID=5409254#5409254
    lookup my posts on DNS setup to help you about. Please mention if you want to go full a Fully Qualified Domain Name Setup or just a local setup . Do you dispose of a fixed public IP address as well ?

  • Mac os x server and dhcp

    Hi all,
    Just a quick question. Does the DHCP service in Mac OS X Server override the DHCP in a Time Capsule?
    Thanks,
    Andy

    Certainly try dedicating a DHCP pool of one IP address to a MAC address, as was described in that video.  I might go as far as dedicating that IP address to a MAC address that doesn't exist on the network, as the local servers and static-addressed devices are intentionally not dependent on any DHCP requests; they're entirely static-addressed.   I haven't tried this, as I don't use the particular configuration described in the video, as I prefer to avoid using the Airport or a Time Capsule as a firewall gateway router; I have and use and recommend a dedicated gateway firewall router.  I also prefer to configure the Apple wireless devices as access points (what Apple refers to as bridge mode), and not as WiFi routers.
    It is possible to run multiple DHCP servers for some cases — for reasons not germane to this discussion, I have three DHCP servers running on one network I deal with — so long as the DHCP server address pools don't overlap with each other or with the static addresses.  Ugly, but possible.
    If you can't run as an access point (bridged), then having DHCP relay in the device would be preferable.  But AFAIK Apple's wireless devices don't support that operation.
    My preference is a gateway-firewall device and preferably with VPN server capabilities, running Airport or Time Capsule devices as access points, and having the server or some other device running DHCP. 
    FWIW, that video somewhat conflates port forwarding and NAT.   NAT is the address translation.  Port forwarding is how you configure remote requests through that address translation.  Also adding the IP address of the DNS server into the box itself as is offered in that video will likely also trigger DNS timeouts when the non-local address is selected.   It did, last time I tested that.  His description of setting up multiple local and remote DNS servers in the same list is also something I wouldn't recommend, as you don't want your DNS queries potentially going to the remote DNS servers as you won't get the local translations.
    pfSense and various other open-source gateway-router software packages are available if you have some spare ARM or x86-class hardware with two network interface controllers, and there are also a number of commercial gateway-firewall product offerings with various features.   Since I'm potentially running remote access, having the VPN server in the gateway avoids most of the various "fun" that arises with NAT traversal in a VPN; VPNs and NAT run at cross-purposes.

  • Mac OS X Server, Network Home Directories & Time Machine

    hi,
    I am using mac os x server to manage a small workgroup using open directory and network home directories, the server is backed up using time machine. From what I understand, time machine does work on network home directories.
    However, as I am backing up my server using Time Machine, it is already backing up the user directories. Is there any way of getting a client to access the server time machine backup to access the backups of the user directories?
    Of course, it would be easy to restore files by logging onto the server as the user and restoring from there. I am just wondering if there is a more elegant solution available to do this from a client machine.
    any thoughts?
    thx!

    Hi,
    I am trying to do the same exact thing and find that it is best to do this locally (for now). Not only is the network way slower, but it seems to make things worse. For example, things backed up via the client machine are routed from the FTP server/volume mount and different permission wise. When you try to restore them locally, it should work, but the folder had different permissions because they were initially created in root (for me). So, I hope they would come out with something better than what is available now. Thanks!

  • IP Forwarding on a Mac OS X Server

    Hi!
    I'm really a newbie with Mac OS X Server...
    I got this new X Server with the Mac OS X server O.S.
    I have the DNS, NAT and firewall running.
    My LAN have a private IP like the 192.168.1.x
    Now, i'd like to setup a web server in my LAN, but i want it accessible from outside.
    I tried NATural, but it's seems nothing happens...
    Please, can you tell me (in detail) what I've to do for having it working?
    Thanks to u all!
    Marco

    well... i did some tests...
    Now, from outside is possible to reach my internal webserver.
    If i put my public ip in my browser (inside the LAN) i cannot reach the webserver...
    Do you think it's something to set in my firewall or is it okay?
    Also... for doing that, i used the unique public ip on my xserve.
    There's a way to assign a secondary public IP to redirect to my local webserver?
    I cannot do this on my router, so i hope it could be possible with the xserve.
    Thanks again!

  • Mac OS X Server - Airport or other wireless hub

    I want to set up this network topology,
    Cable Modem->Mac OS X Server->Switch->Airport Extreme (or other wireless hub like a d-link or linksys)
    so that the server is acting as DHCP server, firewall etc. and the wireless hub is just allowing for wireless service (i.e. I don't need any of the routing or firewall services from the wireless hub). Can I do this? How do I set it up? Is the Airport Extreme capable of doing this? Thank you for any help you can provide.

    Ok, so I have the Airport set up, connected via ethernet and pulling it's IP via DHCP. It's pulling that IP address fine from the OS X server. It's also broadcasting it's wireless signal just fine which my laptops can see. NAT is enabled on the server as well. But, the laptops can't seem to pull an IP address through the bridge (the airport) from the server's DHCP server.
    Please help.

  • Mac OS X server together with VPN provider?

    Hi,
    I have question that I'm hoping you can help me answer. I don't have a router that is DD-WRT compatible. But I need something similar - since PPTP VPN on iOS disconnect when it's put into sleep.
    Do you know, or think that it is possible to setup Mac OS X Server with something Privat VPN? Or is it only for setting up and new personal VPN and use an existing server from a VPN provider like you.
    I hope you understand what I'm asking :)

    I would not recommend using the built-in firewall on an OS X Server box that is also running other services. You could put a server at the perimeter of your network and make it a firewall, an probably a pretty good one, but as soon as you start services, you open ports on the server itself. I also can't imagine that the firewall capabilities of a DSL modem would be that dependable or configurable. If you're looking for an inexpensive way, what you're thinking may work, but it would not be as secure as a good standalone firewall.
    I vote for upgrading the firewall.

  • Mac Mini SL Server - how to set it up a basestation

    Hi,
    I have a Mac Mini Server (Snow Leopard Server), boss man just purchased a MacBook air and now needs connection to the server and the rest of the network for file servers (the mac mini server) and printers.
    I know as a desktop you can click "Share Internet" in the Network sharing tab, but that's gone under SL server.
    Any suggestions

    To access the server with the MBA press COMMAND-K or select Connect to Server from the Finder's Go menu.  He will need a user account set up for him on the server that is configured as a Sharing Only account.  He then logs into that account once connected to the server (does not log into the Guest account.)  On the server File Sharing should be enabled.  It can be configured to provide whatever access to the server is desired.  The server's connected drives or folders to which he would have access will need to be shared.  Select a drive or folder, Press COMMAND-I to open the Get Info window and check the box labeled "Shared" in the top section of the window.
    For internet access I assume you have a router between the cable/DSL modem and the server.  If the router has wireless then he can connect wirelessly while in the office.
    Connection when away from the office is another problem, and one with which I have no experience.  Access is usually done via a VPN connection.  Someone else will have to guide you through this particular maze.

  • Mac O X Server v10.39 troubleshooting start up.  'console mode' screen

    I have recently made use of my old *G4 400 mhz* desktop mac, by installing an old version *Mac O X Server v10.39*, to use as home server. The installation has gone well and the server has been working well for over a week, the users and shared points have all been set and there hasn't been any problems. It is now running headless and I am controlling it via Apple Remote Desktop, I have also set the energy setting preferences to put the server to sleep at 10 pm each night. I also have three other family macs which are connected and configured to use the server.
    But today I have tried to wake the server via ARD, but it wouldn't wake up and also when I have tried to getting it to manually awake up it doesn't work either, even though the front light is on.
    I then have then pressed the small reset button on the front of the G4 and now when it boots up, after seeing it go through the start up screens and once the progress bar has reached the end, the screen then goes to a black screen with the words:
    Darwin/BSD (Server name) (console)
    login:
    This is were I'm stuck, I have no knowledge of the Terminal scripts etc.
    But I have tried the put in the servers name, then pressed return, at this point the next line came up as
    password:
    After entering the administrators password, the screen then goes to a plain blue screen.
    Can anyone tell me what I need to do to get passed this stage in booting up, or what I am doing wrong and how I can correct this situation.
    Many Thanks

    Hello !
    Remade an new install with a FQDN* (yourhost.yourdomain.com) hosted by your provider with a A and MX (if you plan to use mail setvices) records pointing on your host
    Too : it's imperative to enter a valid ip on your eth. link (no public adresse : like as 10.x.x. or 192.168.X.X on your en0
    Even it's possible to setup like this, you must configure your router or firewall ... but much complex ! (Port mapping ... virtual server ... etc.. DMZ if you have ... ???)
    Install a second eth card is good think :
    1 for the wan link on the EN0
    the other for the lan EN1
    with a "real" domain name and the ip supplied by your provider : you can setup your server with this public ip on your wan and a 10-net on your lan.
    (Your dns request will be forwarding to the DNS IP servers of your ISP : one line in option of the named.conf file)
    Before you can install the software with your ISP setup (DNS and domain name) : But don't launch any services !!! nothing ! all off !
    upgrade your os x software before setup via pref panel ..
    at tis time, you got an local acces who is accessible via yourhostname.local and once you have the necessary described (domainname.xx hosted and public ip adress you can setup the services by runnig "Gateway Tool" to start DNS, NAT, DHCP and VPN services.
    The Firts step is OK !
    After you can finish the setup with in first : The DNS forwarding
    Once you hosname and reverse resolving : you will be able to jump to the next !
    But before you must get a perfectly lookup of your hostame and ip addr
    (You can setup your DNS as a primary server ! Bind 9.2.2 run well ! but ... not really easy without a goot practice of bind and a good overview of Domain Name basics ... and insecure for your data ; DNS crashed = O.D. dead and access data under LDAP denied and lost !)
    good luck !
    G4(s)  Mac OS X (10.3.9) - X4 

  • How to reinstall mac os x server on mac mini 2011

    Hi
    i need to help
    Can i Reinstall "Mac osx lion server "on my MACMINI 2011

    Then you will need to boot to the Recovery HD partition included on the internal drive when Mt Lion was installed. To do that at startup hold down the Command+r keys and that will boot the computer from the recovery HD. Once that starts use Disk Utility to Erase the Macintosh HD partition. Once that finishes exit DU and select Reinstall Mac OS X and Mt Lion will be downloaded from the internet and whenn that finishes downloading the install will start. Have the Apple ID and password you used to originally install Mt Lion. And it is best to Wire the computer to your internet router, Ethernet cable from computer to router. You can use WiFi but if for some reason the WiFi drops out you will have to start over from the beginning with the Mt Lion download.

  • How to make Mac OS X Server auto-configure Airport Extreme port-mapping

    Mac OS X Server can automatically configure AirPort Extreme to make services such as iChat, Mail, Web, and VPN accessible: http://www.apple.com/server/macosx/features/networking-vpn.html
    I presume this configuration generally takes place during a fresh installation of the server.
    Is there any way to re-run this process post-installation?

    That page talks about Snow Leopard's Networking abilities, not Leopards.
    Off hand, I don't know whether what you describe is a new feature in Snow Leopard or not, but I've never seen Leopard do it (and, to be honest, wouldn't want to).
    In either case, it's basically just Bonjour telling the router to configure port forwarding. Given that, I'd start by enabling mod_bonjour in Apache:
    #LoadModule bonjour_module libexec/apache2/mod_bonjour.so
    but I don't know how other processes are doing it.

  • I am trying to connect a Windows 7 / 64 bit to an Epson printer on my Mac.  The printer is hooked into the Mac via USB; the Mac is networked to a Linksys wireless router with an ethernet cable, as is the Windows box. Any tips on how to do this?

    I am trying to connect a Windows 7 / 64 bit to an Epson printer on my Mac.  The printer is hooked into the Mac via USB; the Mac is networked to a Linksys wireless router with an ethernet cable, as is the Windows box. I installed the current Bonjour printer services software on the Windows machine, and separately installed the driver software for the Epson printer on the WIndows machine.  Running the bonjour wizard, I get an alert saying 'I don't have sufficient access to my computer to connect to the selected printer'.
    The printer has 'sharing' turned on from the Mac end; this works with a Powerbook via the wireless connection.  Sharing is also turned on in the Windows printer control panel for this printer (under properties).  The Mac is a G5 running 10.5.8.  When I try to print a page from the Windows machine it gets hung in the print queue.
    Any advice how to proceed would be appreciated!
    thx,

    I am trying to connect a Windows 7 / 64 bit to an Epson printer on my Mac.  The printer is hooked into the Mac via USB; the Mac is networked to a Linksys wireless router with an ethernet cable, as is the Windows box. I installed the current Bonjour printer services software on the Windows machine, and separately installed the driver software for the Epson printer on the WIndows machine.  Running the bonjour wizard, I get an alert saying 'I don't have sufficient access to my computer to connect to the selected printer'.
    The printer has 'sharing' turned on from the Mac end; this works with a Powerbook via the wireless connection.  Sharing is also turned on in the Windows printer control panel for this printer (under properties).  The Mac is a G5 running 10.5.8.  When I try to print a page from the Windows machine it gets hung in the print queue.
    Any advice how to proceed would be appreciated!
    thx,

Maybe you are looking for

  • ITunes wont let me buy or download since update

    Since I updated my iPhone 4S to ios7, I cannot download anything from the iTunes or app store. When I press the price, it turns green and then gets stuck. But it wont even let me download free stuff, it just gets stuck. The circle is there next to th

  • What's new in J2EE 1.4

    Is there a good paper that dicuss's on what's new in J2EE 1.4 over 1.3

  • Flex RIA (Rich Internet Application)  how to make the deploy  at Netweaver?

    Hello: I'm working with Flex RIA (Rich Internet Application) and I want make them run at NetWeaver WAS. As VC works with this technology I understand that the WAS is a Flex server. I want to know how to deploy them at the server. Thanks a lot for the

  • SQL loader and truncate drop storage clause

    Hi, I check that during load data via sqlloader like that: LOAD DATA TRUNCATE INTO TABLE TEMP_TABLE FIELDS TERMINATED BY "," (id, text it use reuse storage in truncate command. Is there any way to set truncate with drop storage option?

  • Upload xml using xpath when data in scattered in different tags

    Hi, My problem is "I have to upload a big XML File into a relational master child model of hierarcy=5,but the struture of the xml is not as per the Data Model".I am using the xpath approach in PL/SQL because there is no other way I can get this done.