NAT error: UDP OK but TCP = no route to host
I recently did a firmware update on my Airport Express and I think something has changed which is affecting file transfer speed. A NAT test shows UDP listen port 6881 is OK but when testing TCP listen port 6881 I get the following message:
NAT error: No route to host (173.19.148.196:6881)
I have Mediacom Cable and their provided modem is Touchstone Telephony Modem and my Airport Express is plugged into it to provide me a wireless connection (it has an IP address of 10.0.1.1).
I have a MacBook 4,1 Intel Core 2 Duo and run OS X v. 10.5.6. In Security settings my Firewall is OFF.
Can someone explain to me what I need to do to open the TCP port? Also, what is a UDP connection?
Thank you
i had the same problem.
and i did the following steps
on vuze program
1) vuze -> preferences -> incoming tcp listen port (example 50123)
2) set the same port on UDP
after that you have to open tcp protocol (NAT -> virtual server) ... on your router and set start port as the same port as you already set in vuze (ex. 50123)... and an end port (ex. 50124)
be careful as local ip address, you have to set the same ip in the tcp protocol settings with the ip that your macbook uses to connect to the internet. you can find the ip on system preferences --> web--> and get the information.
I hope to help you and others with the same problem!
Similar Messages
-
Help with Time Capsule Double NAT error.
I've been reading different threads on this problem but have been unable to find a solution.
I recently replaced a dead SpeedStream modem with a Motorola 3360, per AT&T's (my ISP) recommendation. Since swapping the modem I've had a "Double NAT" error on my Time Capsule. The new modem is the only change. We connect every device: 1 G5 tower, 1 iMac, 1 iPad, 1 MacBook Pro via our wireless network. The Time Capsule is stand-alone, e.g., not connected to anything but the modem via the either-net cable provided.
Running 10.7.4, the Airport Utility is 6.0, the TC firmware is up to date as well 7.6.1
We've never had great speed but now it's slower than usual, I'm assuming because of the Double NAT error (two firewalls).
I've followed the AT&T website instructions, to the letter, for switching the 3360 to "bridge mode," letting the TC handle the IP address (correct?) = no internet.
I've also followed the support communities directions for switching the Time Capsule to bridge mode as well, letting the modem handle the IP address, the Double NAT error goes away but = no internet. In this mode I can't join my own network and I get a "your computer is using an IP address that's already in use" error, though everything but my laptop is off.
What I'm willing to try anything but I need very specific, step-by-step (noob) instructions. Many thanks.I've followed the AT&T website instructions, to the letter, for switching the 3360 to "bridge mode," letting the TC handle the IP address (correct?) = no internet.
I've also followed the support communities directions for switching the Time Capsule to bridge mode as well, letting the modem handle the IP address, the Double NAT error goes away but = no internet. In this mode I can't join my own network and I get a "your computer is using an IP address that's already in use" error, though everything but my laptop is off.
I have to admit when I see Motorola modem I automatically think cable modem.. but yours is adsl.. so when you bridge the modem you have to use pppoe client in the TC.. not dhcp as you would with cable. Is that how you are trying it.
I looked it up and there is a thread almost identical. https://discussions.apple.com/thread/3808550?start=0&tstart=0
Bob.. gives instructions with pic in the thread on how to setup pppoe in the TC. This should work, although we have noticed some issues of late with the client not always handling IP correctly.
I am not sure why it fails when you bridge the TC.. that IMO should work without too much hassle.
I would download 5.6 utility
http://support.apple.com/kb/DL1482
It just does a lot more things than v6 in Lion.
Go to manual setup in 5.6 utility.
Go to internet tab
Go to connection sharing.
Set to Off bridge mode.
Update the TC.
Then reboot everything..
start in sequence.
1. Modem.. wait a couple of min.
2. TC .. wait again..
3. Clients.
What you have previously done may well be correct but not renewing IP addresses properly has messed up the connection to the modem. -
Hi,
I lost my airport connection when I was using internet and when I wanted to re-reconnect to airport it gave me connection timeout error, I changed my password on router but still doesn't work. How can i fix my problem?Hello there hastibahreini,
It sounds like you were using your Wi-Fi network from your Airport base station and the connection cut out. You have reset the password on the device but the issue persists. I would try the 3 resets outlined in the following article in order to help resolve the issue. If it persists, is the Wi-Fi connection issue happening on more than one device or computer?
Resetting an AirPort base station FAQ
http://support.apple.com/kb/ht3728
Thank you for using Apple Support Communities.
Cheers,
Sterling -
GoldenGate extract issue - TCP/IP error 113 (No route to host)
Hi All,
I have created a new replicat process on a new server. The old server is to be de-commissioned. after I created the replicat process on the new server (I copied the replicat prm file from the existing server - which is to be de-commissioned to new server and changed old encrypted password with new one and DISCARDFILE location), I modified the extract parameter file on source server. I changed RMTHOST and RMTTRAIL from older server name to new server name and old location to new location. once done , I stopped the extract and ran below command:
ADD RMTTRAIL /u01/app/ggs/dirdat/db, EXTRACT Ext1
and then started the extract process after which I am getting this error:
*2012-03-16 02:24:39 GGS ERROR 150 TCP/IP error 113 (No route to host).*
*2012-03-16 02:24:39 GGS ERROR 190 PROCESS ABENDING.*
I can very well ping both servers from both source and target. Any thoughts?
-Onkargot the answer. It was firewall issue. When i turned the firewall down "service iptables stop", everything was smooth. I have raised request with the proper team to add the source ip in the target system firewall.
-Onkar -
VPN Client can't reach router or hosts, but can reach other connected sites.
We have a VPN client configuration on a 2901 router. The client passes authentication and connects fine. When connected, cannot reach the 2901 or any devices directly behind it, BUT can reach routers and hosts that are connected to the same 2901 through site to site connections.
Few notes:
I have added some lines excluding NAT in a few different ways, but does not resolve.
I have switched the RAP rool from 10.96.20.x to 172.21.20.x and can then connect to the local host. Appears to be a routing issue to the 10.x network, but I can't seem to find the solution.
Any help would be greatly appreciated. Here is the config:
boot-start-marker
boot system flash
boot system flash:c2900-universalk9-mz.SPA.153-2.T.bin
no ip domain lookup
ip inspect log drop-pkt
ip inspect name FIREWALL tcp
ip inspect name FIREWALL udp
ip inspect name FIREWALL ftp
ip inspect name FIREWALL fragment maximum 256 timeout 1
ip inspect name FIREWALL ntp
ip inspect name FIREWALL pptp
ip inspect name FIREWALL dns
ip inspect name FIREWALL l2tp
ip inspect name FIREWALL pop3
ip inspect name FIREWALL icmp router-traffic
no ipv6 cef
crypto isakmp policy 1
encr aes
authentication pre-share
group 2
crypto isakmp policy 5
encr 3des
authentication pre-share
group 2
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp policy 95
authentication pre-share
group 2
crypto isakmp policy 99
hash md5
authentication pre-share
group 2
crypto isakmp policy 110
hash md5
authentication pre-share
crypto isakmp client configuration group VPN-RAS
key *********
dns 10.96.17.2 10.1.200.50
wins 10.96.17.2 10.1.200.50
domain mine.com
pool RAPOOL
acl SPLIT
save-password
split-dns mind.com
netmask 255.255.255.0
crypto isakmp profile USERS
match identity group VPN-RAS
client authentication list DOMAIN
isakmp authorization list VPN-RAS
client configuration address respond
keepalive 300 retry 5
crypto ipsec transform-set AES128 esp-aes esp-sha-hmac
mode tunnel
crypto ipsec transform-set 3DES esp-3des esp-sha-hmac
mode tunnel
crypto ipsec transform-set DES esp-des esp-md5-hmac
mode tunnel
crypto ipsec transform-set 3DES-MD5 esp-3des esp-md5-hmac
mode tunnel
crypto ipsec transform-set DES-SHA esp-des esp-sha-hmac
mode tunnel
crypto ipsec transform-set myset esp-3des esp-sha-hmac
mode tunnel
crypto dynamic-map dynmap 1
set transform-set AES128
set isakmp-profile USERS
crypto map COMPANY_VPN 10 ipsec-isakmp
set peer *******
set transform-set 3DES-MD5
match address PA-VPN
qos pre-classify
crypto map COMPANY_VPN 50 ipsec-isakmp
set peer ******
set transform-set AES128
match address VPN
qos pre-classify
crypto map COMPANY_VPN 999 ipsec-isakmp dynamic dynmap
interface Embedded-Service-Engine0/0
no ip address
shutdown
interface GigabitEthernet0/0
ip address 37.222.111.224 255.255.255.248
ip access-group INBOUND in
no ip redirects
no ip unreachables
no ip proxy-arp
ip verify unicast reverse-path
ip flow ingress
ip flow egress
ip nat outside
ip inspect FIREWALL out
ip virtual-reassembly in
duplex auto
speed auto
no cdp enable
no mop enabled
crypto map COMPANY_VPN
interface GigabitEthernet0/1
no ip address
ip flow ingress
duplex auto
speed auto
interface GigabitEthernet0/1.17
description LAN
encapsulation dot1Q 17
ip address 10.96.17.253 255.255.255.0
ip access-group OUTBOUND in
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly in
standby 0 ip 10.96.17.254
standby 0 priority 110
standby 0 preempt
standby 0 track 1 decrement 20
interface GigabitEthernet0/1.27
description VOICE
encapsulation dot1Q 27
ip address 192.168.17.254 255.255.255.0
ip access-group OUTBOUND in
ip helper-address 10.96.17.2
ip flow ingress
ip nat inside
ip virtual-reassembly in
h323-gateway voip bind srcaddr 192.168.17.254
ip local pool RAPOOL 10.96.20.50 10.96.20.150
ip forward-protocol nd
ip nat inside source route-map NAT-POOL interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 37.222.111.223
ip route 10.96.16.0 255.255.255.0 10.96.17.250
ip route 172.22.1.0 255.255.255.0 10.96.17.250
ip route 172.22.2.0 255.255.255.0 10.96.17.250
ip route 172.22.3.0 255.255.255.0 10.96.17.250
ip route 192.168.16.0 255.255.255.0 10.96.17.250
ip access-list extended DMZ
deny ip any 10.0.0.0 0.255.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
ip access-list extended GUEST
deny ip any 10.0.0.0 0.255.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
ip access-list extended INBOUND
deny ip 80.25.124.0 0.0.0.255 any
deny ip 10.0.0.0 0.255.255.255 any
deny ip 172.16.0.0 0.15.255.255 any
permit udp host 173.239.147.114 any eq isakmp
permit esp host 173.239.147.114 any
deny ip 192.168.0.0 0.0.255.255 any
permit udp any host 37.222.111.224 eq isakmp
permit udp any host 37.222.111.224 eq non500-isakmp
permit esp any host 37.222.111.224
ip access-list extended NAT
deny ip 10.96.20.0 0.0.0.255 any
deny ip any 10.96.20.0 0.0.0.255
permit ip 192.168.0.0 0.0.255.255 any
permit ip 10.0.0.0 0.255.255.255 any
ip access-list extended NONAT
permit ip any 192.168.0.0 0.0.255.255
permit ip any 10.0.0.0 0.255.255.255
ip access-list extended OUTBOUND
deny udp any host 22.55.77.106 eq isakmp
deny udp any host 22.55.77.106 eq non500-isakmp
deny esp any host 22.55.77.106
permit ip any any
ip access-list extended PA-VPN
permit ip 10.0.0.0 0.255.255.255 10.96.18.0 0.0.0.255
permit ip 10.0.0.0 0.255.255.255 192.168.18.0 0.0.0.255
permit ip 192.168.0.0 0.0.255.255 10.96.18.0 0.0.0.255
permit ip 192.168.0.0 0.0.255.255 192.168.18.0 0.0.0.255
ip access-list extended SPLIT
permit ip 10.0.0.0 0.255.255.255 any
permit ip 192.168.0.0 0.0.255.255 any
ip access-list extended VPN
permit ip 10.96.16.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 10.96.17.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 10.96.18.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 10.96.0.0 0.0.255.255 192.168.0.0 0.0.255.255
permit ip 10.96.0.0 0.0.255.255 10.0.0.0 0.255.255.255
permit ip 192.168.16.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 192.168.17.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 192.168.18.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 192.168.17.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 192.168.18.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 172.22.0.0 0.0.255.255 10.0.0.0 0.255.255.255
permit ip 172.22.0.0 0.0.255.255 192.168.0.0 0.0.255.255
route-map NAT-POOL deny 5
match ip address NONAT
route-map NAT-POOL permit 10
match ip address NATWe have a VPN client configuration on a 2901 router. The client passes authentication and connects fine. When connected, cannot reach the 2901 or any devices directly behind it, BUT can reach routers and hosts that are connected to the same 2901 through site to site connections.
Few notes:
I have added some lines excluding NAT in a few different ways, but does not resolve.
I have switched the RAP rool from 10.96.20.x to 172.21.20.x and can then connect to the local host. Appears to be a routing issue to the 10.x network, but I can't seem to find the solution.
Any help would be greatly appreciated. Here is the config:
boot-start-marker
boot system flash
boot system flash:c2900-universalk9-mz.SPA.153-2.T.bin
no ip domain lookup
ip inspect log drop-pkt
ip inspect name FIREWALL tcp
ip inspect name FIREWALL udp
ip inspect name FIREWALL ftp
ip inspect name FIREWALL fragment maximum 256 timeout 1
ip inspect name FIREWALL ntp
ip inspect name FIREWALL pptp
ip inspect name FIREWALL dns
ip inspect name FIREWALL l2tp
ip inspect name FIREWALL pop3
ip inspect name FIREWALL icmp router-traffic
no ipv6 cef
crypto isakmp policy 1
encr aes
authentication pre-share
group 2
crypto isakmp policy 5
encr 3des
authentication pre-share
group 2
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp policy 95
authentication pre-share
group 2
crypto isakmp policy 99
hash md5
authentication pre-share
group 2
crypto isakmp policy 110
hash md5
authentication pre-share
crypto isakmp client configuration group VPN-RAS
key *********
dns 10.96.17.2 10.1.200.50
wins 10.96.17.2 10.1.200.50
domain mine.com
pool RAPOOL
acl SPLIT
save-password
split-dns mind.com
netmask 255.255.255.0
crypto isakmp profile USERS
match identity group VPN-RAS
client authentication list DOMAIN
isakmp authorization list VPN-RAS
client configuration address respond
keepalive 300 retry 5
crypto ipsec transform-set AES128 esp-aes esp-sha-hmac
mode tunnel
crypto ipsec transform-set 3DES esp-3des esp-sha-hmac
mode tunnel
crypto ipsec transform-set DES esp-des esp-md5-hmac
mode tunnel
crypto ipsec transform-set 3DES-MD5 esp-3des esp-md5-hmac
mode tunnel
crypto ipsec transform-set DES-SHA esp-des esp-sha-hmac
mode tunnel
crypto ipsec transform-set myset esp-3des esp-sha-hmac
mode tunnel
crypto dynamic-map dynmap 1
set transform-set AES128
set isakmp-profile USERS
crypto map COMPANY_VPN 10 ipsec-isakmp
set peer *******
set transform-set 3DES-MD5
match address PA-VPN
qos pre-classify
crypto map COMPANY_VPN 50 ipsec-isakmp
set peer ******
set transform-set AES128
match address VPN
qos pre-classify
crypto map COMPANY_VPN 999 ipsec-isakmp dynamic dynmap
interface Embedded-Service-Engine0/0
no ip address
shutdown
interface GigabitEthernet0/0
ip address 37.222.111.224 255.255.255.248
ip access-group INBOUND in
no ip redirects
no ip unreachables
no ip proxy-arp
ip verify unicast reverse-path
ip flow ingress
ip flow egress
ip nat outside
ip inspect FIREWALL out
ip virtual-reassembly in
duplex auto
speed auto
no cdp enable
no mop enabled
crypto map COMPANY_VPN
interface GigabitEthernet0/1
no ip address
ip flow ingress
duplex auto
speed auto
interface GigabitEthernet0/1.17
description LAN
encapsulation dot1Q 17
ip address 10.96.17.253 255.255.255.0
ip access-group OUTBOUND in
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly in
standby 0 ip 10.96.17.254
standby 0 priority 110
standby 0 preempt
standby 0 track 1 decrement 20
interface GigabitEthernet0/1.27
description VOICE
encapsulation dot1Q 27
ip address 192.168.17.254 255.255.255.0
ip access-group OUTBOUND in
ip helper-address 10.96.17.2
ip flow ingress
ip nat inside
ip virtual-reassembly in
h323-gateway voip bind srcaddr 192.168.17.254
ip local pool RAPOOL 10.96.20.50 10.96.20.150
ip forward-protocol nd
ip nat inside source route-map NAT-POOL interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 37.222.111.223
ip route 10.96.16.0 255.255.255.0 10.96.17.250
ip route 172.22.1.0 255.255.255.0 10.96.17.250
ip route 172.22.2.0 255.255.255.0 10.96.17.250
ip route 172.22.3.0 255.255.255.0 10.96.17.250
ip route 192.168.16.0 255.255.255.0 10.96.17.250
ip access-list extended DMZ
deny ip any 10.0.0.0 0.255.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
ip access-list extended GUEST
deny ip any 10.0.0.0 0.255.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
ip access-list extended INBOUND
deny ip 80.25.124.0 0.0.0.255 any
deny ip 10.0.0.0 0.255.255.255 any
deny ip 172.16.0.0 0.15.255.255 any
permit udp host 173.239.147.114 any eq isakmp
permit esp host 173.239.147.114 any
deny ip 192.168.0.0 0.0.255.255 any
permit udp any host 37.222.111.224 eq isakmp
permit udp any host 37.222.111.224 eq non500-isakmp
permit esp any host 37.222.111.224
ip access-list extended NAT
deny ip 10.96.20.0 0.0.0.255 any
deny ip any 10.96.20.0 0.0.0.255
permit ip 192.168.0.0 0.0.255.255 any
permit ip 10.0.0.0 0.255.255.255 any
ip access-list extended NONAT
permit ip any 192.168.0.0 0.0.255.255
permit ip any 10.0.0.0 0.255.255.255
ip access-list extended OUTBOUND
deny udp any host 22.55.77.106 eq isakmp
deny udp any host 22.55.77.106 eq non500-isakmp
deny esp any host 22.55.77.106
permit ip any any
ip access-list extended PA-VPN
permit ip 10.0.0.0 0.255.255.255 10.96.18.0 0.0.0.255
permit ip 10.0.0.0 0.255.255.255 192.168.18.0 0.0.0.255
permit ip 192.168.0.0 0.0.255.255 10.96.18.0 0.0.0.255
permit ip 192.168.0.0 0.0.255.255 192.168.18.0 0.0.0.255
ip access-list extended SPLIT
permit ip 10.0.0.0 0.255.255.255 any
permit ip 192.168.0.0 0.0.255.255 any
ip access-list extended VPN
permit ip 10.96.16.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 10.96.17.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 10.96.18.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 10.96.0.0 0.0.255.255 192.168.0.0 0.0.255.255
permit ip 10.96.0.0 0.0.255.255 10.0.0.0 0.255.255.255
permit ip 192.168.16.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 192.168.17.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 192.168.18.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 192.168.17.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 192.168.18.0 0.0.0.255 10.0.0.0 0.255.255.255
permit ip 172.22.0.0 0.0.255.255 10.0.0.0 0.255.255.255
permit ip 172.22.0.0 0.0.255.255 192.168.0.0 0.0.255.255
route-map NAT-POOL deny 5
match ip address NONAT
route-map NAT-POOL permit 10
match ip address NAT -
Back to my Mac: Double NAT error
I can't seem to get Back to my Mac to work. My Airport Extreme says that I have a double NAT error. I have tried to put it in Bridge mode, but doing so disables the wireless capabilities of the Airport Extreme.
The geography of my network is as follows:
Cable port on wall> Cable modem
Cable modem> Ethernet> Airport Extreme
Airport Extreme> WiFi> Macbook Pro
I have a Motorola surfboard modem, which I have called Motorola about and they say that it does not provide a layer of NAT. I have called my ISP and they confirmed that they do not provide a layer of NAT as well.
Does anyone have any ideas on how to resolve this issue?FiggyOO wrote:
I have confirmed that my modem is simply a modem, no gateway. In case you were wondering its a Motorola SB5101U. According to the Airport utility, my IP is 10.1.4.104.
If that's really the "WAN" IP address of your AirPort unit, then it's a "private" IP address, as it's in one of the private address ranges of 10.0.0.0 - 10.255.255.255, 172.16.0.0 - 172.31.255.255, and 192.168.0.0 - 192.168.255.255. You can verify that address in the AirPort Utility Internet panel, TCP/IP tab. Unless your ISP tells you otherwise, you should have the "Configure IPv4" set to "Using DHCP" and the WAN IP address should be just below that.
If that address checks out, something "upstream" of your AirPort unit is doing a NAT operation.
The manuals I found for your modem seem to confirm that it has no router functionality, so it would be unable to be the source of the NAT.
I'd call your ISP and ask them why your modem is passing you a "private" IP address. There no need (at least initially) to mention what you have connected to the modem, as that would only tend to confuse the support people. -
I just upgraded my AEBS to the 7.1.1 firmware and I am now receiving a dual NAT error on the AEBS. The error message states that I have a private address on the WAN port. I'm assuming that my Time Warner Cable Modem has its own NAT and issues a private address to my home network.
Everything seems to be working fine. The error message recommends that I configure my AEBS as a bridge instead of a router. Should I do this? Is there a way to prevent the error? Should I be concerned about the error message?
ThanksHi I'm having a similiar problem ... doubleNAT
Here's my 1st setup.
Existing netork: Netcomm DSLmodem acting as NAT router (static ip of 192.168.1.1) connects via ethernet to PowerMacG4 with DHCP (dynam ip of 192.168.1.100). Another iMac connects via ethernet with DHCP (dynam ip of 192.68.102) and an ipp printer.
If i connect my MBP via ethernet everything is fine - automatic locations DHCP gets me a dynamic ip of 192.168.1.103. All good. Safari good, Mail.app good. Quit. Disconnect.
Problem Network: I go downstairs to connect to network via Airport Card in PowerMacG4.
So I set the PMG4 to share its Ethernet connection to computers connected via Airport. Network/Airport/TCPIPv4 tab set to DCHP. (ip, subnet mask, router remain blank)
Airport Menu Bar indicates Airport has created a network.
So - On MBP my Airport card allows me to join the closed WEP netowor called G4_13. MBP Network Airport/TCP is set to DCHP results in ip4 = 10.0.2.5/24 and router 10.0.2.1.
Open Safari. No Go.
Diagnostic eventually reports all green lights. But Safari fails. Mail in/out fails.
(Strangely i can still run sshfsfusefsMacFusion to mount the PowerMacG4/Users/Admin/Desktop as a remote Desktop volume.)
Now I see netstat reported "blackhole.ntp" msgs.
Can the PowerMacG4's Airport card handle the NAT task effectively ? Because it seems that the job of transferring my http or mail or ftp requests from 10.0.2.1 range over to the 192.168.1.1 range whence the DSL NATs my requests again.
Another member suggested firewall issues were now involved and that WaterRoof.app run on the PowerMacG4 may help but ... er ... i'm still working on it ...
All help logged. Thanx.
:g -
Double NAT Error with Airport Extreme and Airport Express
I have an Airport Extreme 802.11n base station which is connected to my DSL Modem/ Router via Ethernet. I have a MacPro which does not have an airport card installed so I bought an Airport Express 802.11n - which is connected to my MacPro via ethernet - and thus provides my MacPro with internet access.
Originally I had the APExtreme and the APExpress set up in a WDS - all worked well - my other wifi equipped macs and devices in the house connected to the network with no problem, but I did notice that the maximum throughput I was getting was 802.11g speeds - this is of course due to the overhead of the WDS.
I originally purchased these 802.11n devices because I wanted the higher throughput - so I decided to terminate the WDS and just have the APExpress (attached to my MacPro) "join" the wireless network instead of extending it - which works and I am enjoying the 802.11n speed.
So, I just upgraded a couple of my Macs to 10.6.2 and was going to start using "Back to My Mac" and I got the error that there is a double NAT address problem and that "Back to My Mac" won't work until this is resolved.
I know that going back to a WDS will resolve the double NAT problem - but I don't want to take the performance hit that goes with the WDS.
So, short of buying an Airport card for my MacPro (which would eliminate the need of the APExpress)
Is there any other way to resolve this double NAT problem besides WDS?
Thanks for any advice.First of all thanks for your quick reply!
Connecting my MacPro to the Airport Extreme would be a serious pain as the DSL Modem and APExtreme are upstairs near the only connection point in the building to a phone line - and my MacPro is downstairs.
I suppose I could dig out a very long ethernet cable to perform the test. But before I jump through that hoop - please explain to me what you are trying to get at - in other words - what does it mean if this resolves the double nat error - and what does it mean if it does not? -
Port Forwarding ? NAT Error ? Azureus.
Ok My I book G4 is hardwired to the internet (not wireless). I am using my Ibook with airport as a "software router" to provide my MACMini with wireless internet.
So my Ibook isnt Receiving wireless it is Sending a wireless signal to my mac mini.
The internet on my mini works fine, as well as messenger ect.
The problem i am having is that i keep getting NAT errors in a P2P sharing program called Azureus. I have had wireless working fine on this mini before, with no NAT errors, but that was when i was using a wireless hub.
I have since gotten rid of the wireless hub because i thought it was redundant because i could just use this ibook as a wireless "software router" so that my mini could "leech" of the signal that is directly plugged into the modem (cable).
Before i got rid of the Router all was good.
Now i cant upload anything to my peers cause i keep getting nat errors.
My firewalls arent on on either computer so im not really sure if im just out of luck or if its some other issue.
I believe all my ports are open and such, i dont know, all was good with the router but since i have used the Ibook as a software router all has gone to poop.
Anyone please....Who is your internet service provider is that cable or DSL connection
Please let me know so that Acoordingly we can decide whether we should go for port range triggering or port range forwarding -
Hi,
I have following error message in my system log.
Anyone knows where the problem is coming from??
Apr 18 22:03:43 athena natd[23886]: failed to write packet back (No route to host)
Cheers
BenHi there,
Here is one thing that is prime with the NAT service.
The Firewall service MUST be running for NAT to work. Most of the NAT problems I have seen are based around this one issue, but obviously are not the only possibility.
From the Apple documentation:
Enabling NAT also automatically creates a divert rule to the Firewall configuration. The Server Admin application in Mac OS X Server allows the NAT service and the Firewall service to be enabled and disabled independently. But for the NAT service to operate, both the NAT and the Firewall service need to be enabled. This is because an essential part of NAT is the packet divert rule. That rule is added to the Firewall when NAT service is enabled, but the Firewall service must be turned on for the packet divert rule, or any Firewall rule, to have any effect.
Warning: IP Firewall must be enabled for NAT to function.
I hope this helped! -
Linux Error: 113: No route to host
After completeing 3.1 in the installation guide I jump down to chapter 4, but I can't get the web interface to work.
It doesn't matter how I access the URL, I've tried both http://localhost:8080/htmldb and http://realhostname:8080/htmldb/ with same result, no data at all, the connection is closed directly.
I've checked listener.log and found this:
02-NOV-2005 01:01:02 * http * (ADDRESS=(PROTOCOL=tcp)(HOST=10.8.0.22)(PORT=2556)) * handoff * http * 12518
TNS-12518: TNS:listener could not hand off client connection
TNS-12571: TNS:packet writer failure
TNS-12560: TNS:protocol adapter error
TNS-00530: Protocol adapter error
Linux Error: 113: No route to host
02-NOV-2005 01:01:23 * http * (ADDRESS=(PROTOCOL=tcp)(HOST=127.0.0.1)(PORT=33183)) * handoff * http * 12518
TNS-12518: TNS:listener could not hand off client connection
TNS-12571: TNS:packet writer failure
TNS-12560: TNS:protocol adapter error
TNS-00530: Protocol adapter error
Linux Error: 113: No route to host
02-NOV-2005 01:02:54 * service_update * XE * 0
02-NOV-2005 01:03:01 * http * (ADDRESS=(PROTOCOL=tcp)(HOST=X.Y.Z.W)(PORT=33509)) * handoff * http * 12518
TNS-12518: TNS:listener could not hand off client connection
TNS-12571: TNS:packet writer failure
TNS-12560: TNS:protocol adapter error
TNS-00530: Protocol adapter error
Linux Error: 113: No route to hostProblem located (as usual after the 3 hours it took me to find the forum and post about it).
Using netstat and lsof I found that XE not only binds to 1521 and 8080, but also to port 33172 and since iptables blocks everything it got "No route to host".
The question is if 33172 is static or just a randomly chosen port number. -
External services moved, but SOA suite still gives "no route to host"
We have a SOA Suite integrating towards external services. The external service provider moved the services to a different server, and updated dns entries to reflect this move. But our SOA Suite gave "no route to host" errors when this move was performed, clearly not reloading the changes done in DNS, but still using the old address.
How and where can the SOA Suite be configured to actually time out domain name resolutions, when external services are moved this way. Can we ask it to use hostname instead of ip address.
Bouncing the servers is of course working, but there must be a configuraiton way around this.
bouncing production servers is the final resort.
Details of error message
<MSG_TEXT>BusinessEvent diapatch failed for {ESBDomain.Service.publish} with error An unhandled exception has been thrown in the ESB system. The exception reported is: "oracle.tip.esb.server.common.exceptions.BusinessEventRetriableException: An unhandled exception has been thrown in the ESB system. The exception reported is: "org.collaxa.thirdparty.apache.wsif.WSIFException: exception on JaxRpc invoke: HTTP transport error: javax.xml.soap.SOAPException: java.security.PrivilegedActionException: javax.xml.soap.SOAPException: Message send failed: No route to host: connectalso check for firewalls on the server - a good test would be to an attempt to telnet into webservice hostname and portnumber from the SOA Server.
Regards,
Shanmu. -
No route to host:connect -- error in the struts-config.xml file
hi all,
acutally am doing a struts application in that i have written everything properly
but getting this kinda no route to host:connect error
my struts-config.xml file is like this...
<struts-config>
<form-beans>
<form-bean name="myForm" type="MyForm">
</form-beans>
<action-mappings>
<action path="/action"
name="myForm"
type="MyAction"
scope="request"
validate="true" >
<forward name="success" path="/success.jsp" />
<forward name="failure" path="/failure.jsp" />
</action>
</action-mappings>
</struts-config>
sikandarHi Lee,
I am working on Oracle ADF 10.1.2 and getting the same problem. The lines in my struts-config.xml are as below:
<action path="/unitsView" className="oracle.adf.controller.struts.actions.DataActionMapping" type="view.UnitsViewAction" name="DataForm" parameter="/unitsView.uix" unknown="false">
<set-property property="modelReference" value="unitsViewUIModel"/>
<forward name="unitsEditLink" path="/unitsEdit.do"/>
</action>
<action path="/unitsView" className="oracle.adf.controller.struts.actions.DataActionMapping" type="view.UnitsViewAction" name="DataForm" parameter="/unitsView.uix" unknown="false">
<set-property property="modelReference" value="unitsViewUIModel"/>
<forward name="unitsCreateLink" path="/unitsCreate.do"/>
</action>
I have two lines with [action path="/unitsView"]. The reason why is that I want the user to go to the form create screen for the create button and form edit screen for the edit button. If this does not work, it seems to mean that only a single screen can be used for create/edit functions. However, the ADF editor diagram looks perfectly to point to create.uix and edit.uix respectively.
Please shed some light.
Thanks,
Regards,
Michael -
FTP receiver channel error: No route to host
Hello,
I am using a ftp receiver channel and got the following error:
java.lang.Exception: ftp access error: java.net.NoRouteToHostException: No route to host.
The following steps are processed right:
- Connection to FTP-Server "XXXX", Folder "/public_html/external/eh/"
- Write to FTP-Server "XXXX", Folder "/public_html/external/eh/", file "xyz.xml"
- Sending: Modus "TXT", Size XXX, Codepage UTF-8
And then the error occurs.
It seems that the channel could connect to the server and start sending the data, but then the error occurs.
Did anybody know this problem?
Thank you very much
ThomasHi Thomas -
Is your FTP server configured for active or passive data connections? If active, you need SP15. Before SP15, only passive data connections are supported.
Regards,
Jin -
Double NAT error status after updating to firmware 7.1
This may be a bug. My Airport Extreme was working perfectly, but after updating to firmware 7.1, with no other changes to configuration, it is now reporting a Double NAT error. Both wired and wireless clients still have access to the WAN and each other, so everything still works. I know I can ignore the error, but I wonder if anyone else has seen this issue?
I have a possibly unusual setup -
My DSL modem creates an address of 192.168.1.47 and hands that to the APE as its WAN address. I've configured the APE to hand out addresses to its client machines on the LAN in the 192.168.2.x range and it does that correctly. So there is no actual conflict - the WAN address is 192.168.1.47 and the client addresses are all in the 192.168.2.x range. Could the new software be assuming that the 192.168.1.x range is the NAT range without verifying the actual range is really 192.168.2.x? Seems unlikely, but it appears to be the case.
Any insights on this appreciated....
mac mini Mac OS X (10.4.9) my Airport Extreme is less than a month oldWhen iTunes attempts to sync photos from iPhoto, it shows the amount of the iPod drive taken up with photos, BUT NO usage on the drive graph itself.
When Sync Photos from iPhoto is deselected and another sync attempted, iTunes asks if photos should be removed from iPod, despite the previous sync being unsuccessful. When I choose to remove the photos, the amount shown taken up by photos disappears.
Does anyone know what the error message quoted in my question above means?
iBook G4 1Ghz/iMac G5 iSight Mac OS X (10.4.3) iPod Photo 40GB
Maybe you are looking for
-
Std report for BOM : Reg.
Hi experts, I need to display the materials along with the BOM of those materials with its quantity and its total price while user give the vendor name and date range as input. Is there any std report for the same? Try to give apt solution on it
-
Problem in project system report ZPS_PROJSUMMARY
i am working with a report ZPS_PROJSUMMARY which extracts all project summary report.now problem is it is extracting las financila years (2006 ) closed WBS element also with this years WBS elements. this problem happening in production only. this is
-
Homepage via iWeb problems with google etc.
I created a homepage with iWeb uploaded it to my university's server and created a new link with nic.de.vu. Then I registered it at google, yahoo etc. I got a message that the registration was successful. But this happened more than four weeks ago. T
-
Morning Coffee for version 10.0.2 does not load. Why?
Does this extension work with 10.0.2? If not, how do I go back to one that it does?
-
Converting sample rate when exporting
CS5.5 I'm using Audition to do some final mastering to 16-bit stereo 44100 wav files, in 32 float multi-track sessions. All I'm doing is increasing the clip gain, then exporting to 16-bit stereo 44100 wave and 320 mp3. I'm not changing the sample rat