Port Monitoring for AirPort Network

I recently did a port scan of my AirPort Extreme network and there are more ports active on my network than Im comfortable with. I searched each port and got 'kind of' useful information ... enough where I know people aren't hacking the bajesus out of my network. I would like to know if there is a utility somewhere that logs this kind of thing? It would be useful to know who's trying to get in (or out).
Thanks

FunkeyJunc wrote:
Actually, no ... they were the extreme's ports. Indicative of something listening on that port (which is why I can see it when doing a scan). For the really detail thirsty ... I did a port scan in NetWork utility of my Public IP address. I was hoping to identify which programs are listening on which ports through the base station. A log would be helpful.
I guess it would make sense that an AirPort unit would be listening to ports so as to be able to support port forwarding. That doesn't necessarily mean that there's anything paying attention to those ports on a Mac on your LAN.
If you search for "firewall" on VersionTracker (http://www.versiontracker.com/macosx) you'll see several products, some offering logging.
The Mac OS X firewall capability is based on the software "ipfw". You can learn more about it here:
http://developer.apple.com/mac/library/documentation/Darwin/Reference/ManPages/m an8/ipfw.8.html

Similar Messages

  • Tool for Airport network statistics per connected device ?

    I'm in search of a tool that would help me identify network traffic load per connected device to my Airport network.
    My network is made of
    * WiFi infra: one main Airport Extreme base station connected thru Ethernet to my SP's cable-modem + 2 Airport Express as relays, all interconnected with WDS.
    * WiFi clients : 2 Macs + 2 PCs + 1 printer + 1 WiFi PDA-Phone, all connected thru WiFi only
    * I suspect misuse by one of the Macs or PCs (or alien ?) of WiFi network as sometimes network performance is really low, impacting all end-points' network performance
    * ideal tool could be based on SNMP stats of Ethernet/TCP/UDP/ports & packets per connected device. Should cover each Airport Express relay, the main Airport Extreme, possibly the cable-modem, and bring help for root cause analysis to go up the chain to faulty client and application (at least port/protocol)
    any idea of such kind of tool (preferably run on Mac OS X)
    thx in advance

    I apologize for taking up your time. I had bought this to use with my PS3 (60GB Launch model with 802.11b) but hadn't used the PS3 in the equation yet. I kind of gave up on the project for awhile and unplugged the Express. Just for giggles I plugged it in later and cabled it up to the PS3 for the first time. Worked perfectly. Now my PS3 downloads are flying.
    I'm not sure what solved the problem but it is working great now! Thanks again for the help.

  • Unknown system keychain for airport network

    Hi, i wonder if anyone can explain me this:
    I have found in my keychain access a totally unknown "system keychain", under somebody's name.
    the Kind says "Airport Network Password", the Account says "Person Name " , Where is in "Airport Network" and it has the icon of an application.
    i dont have such account in my computer, and never set anything under this name, and when i try to retrieve this password with my administrator login keychain, it doesn't let me access it.
    but i can see that it always allow access by these applications:
    configd /usr/sbin
    airport /system/library/privateframeworks/
    airportcfgtool /system/library/privateframeworks/
    system preferences /applications
    what is exactly going on?
    thank you for your help

    yes i do have a wireless internet connection and it is insecure, i got a second hand wi-fi router and couldn't figure out how to set a password. of course it isn't my wireless login account, it says "lisandro" and that's not my name...
    besides, what happens now (unlike before) is that often while im on the internet, i get a lot of pop-up windows that tells me that safari cannot verify the identity of this or that website because the certificate of the website is invalid and there i have to click on "continue" or "cancel" to keep going.
    for instance, it happened when i opened "discussions.apple.com", whose certificate was
    a certain 'a248.e.akamai.net' from an organization named 'Akamai Technologies, Inc' ....?
    also, when i open safari, now the keychain asks me to input my login password, whereas this never happened before...
    how can get rid of these anomalies?
    thanks for your help

  • Port forwarding for airport utility 5.6.1

    Hi,
    The previous version of airport utility had a simple tab "port mapping" that allowed me to forward ports so that various servers running on my machine could be accessible via outside of my WAN/LAN.  However, when using the latest version, I don't see anything related to port mapping, the closest I found was an IPv6 Firewall-- which I am not certain is what I am looking for......
    Ultimately, I have a development web server that I run on port 3000, and I want this to be accessible from the outside world--- and also I would like VNC guests to be able to do screen sharing / remote access which I believe is through port 5900...  How can I make these two things accessible through my standard IPv4 address?
    Thank you.

    Tesserax, you seem to be the Airport Extreme guru.  Been trying to find answers on forums all day so as not to duplicate a post.  Also tried to find a way to contact you directly so as not to get off topic here...but couldn't see an option.
    Running Airport Extreme Version 7.6.1.  Hosting a FileMaker Pro 10 file on a PowerPC on my home network (ISP is TimeWarner ...ugh).  Need to publish this file to the URL the gent that hosts my site has pointed at my public IP addy here on my home network.
    Created DHCP Reservation by MAC Address for the machine hosting to achieve static IP.  Have opened ports 80 and 5003 (filemaker) in Port Mapping.  Both pointing at the IP addy of that same machine hosting the file.  Some discussions have said to make the end of IP .201 or higher for port forwarding so I've done so.
    Port checkers all say these ports are still closed.  Time Warner has told me they are not blocking either of these ports and that my modem does not have a firewall holding things up—they say the prob is with my router settings.
    I should probably also mention that I used to successfully forward these ports and host/access this file via the URL (same ISP and domain host etc. then as currently).
    Obviously posting here because none of this is working.  Have looked over the links and docs you regularly reply with—hoping you may have other wisdom to give us.  Thanks in advance.

  • Port forwarding for Filemaker network

    I want to set up my computer as a host for Filemaker Pro networking. I have 2 other remote computer locations I want to share my FM database file. I am about to purchase a new AEBS for my router.
    Instructions from FM forum was to forward port 5003 on my router & use no-ip.com (to track my dynamic IP address) to get a specific domain name for the remote computers to find when they select Open Remote.
    Reading some of these posts sounds like the AEBS makes this easier. Is the port mapping same as port forwarding? Does the reserve IP address capability negate the need for the no-ip.com service?
    Would appreciate the step-by-step process I need to do this.

    Is the port mapping same as port forwarding?
    Yes, both terms are used interchangeably and mean the same thing.
    Does the reserve IP address capability negate the need for the no-ip.com service?
    No. Reserving an IP address is a means to instruct the DHCP service on the router to "save" a specific Private IP address for a device on the local network. No-IP.com is a service that basically tracks the dynamic Public IP address of your modem or router and provides you with a "static" URL address to access it from the Internet. A similar service to No-IP.com would be DynDNS.
    Accessing a server on the local network from a remote client would require that the client knows the Public IP address and port(s) required to access that server. Servers, like yours that are behind a firewall, must either use port mapping (port forwarding) or be configured to be in a DMZ which would completely expose them to the Internet. Port mapping reduces that risk to only allow predefined ports to be open to the Internet.
    Since most consumers have Internet service with comes with a dynamic (changing) Public IP address, just knowing what it is at any given time won't help in the long run. This is where services, like No-IP come in. Typically they will give you a client utility that you would run on your computer. This utility will provide them with an update every time your ISP changes your Public IP address ... or you may be required to do this manually. They will also provide you with a URL to use instead of using the Public IP address.
    To setup port mapping on an 802.11n AirPort Extreme Base Station (AEBSn), either connect to the AEBSn's wireless network or temporarily connect directly, using an Ethernet cable, to one of the LAN port of the AEBSn, and then use the AirPort Utility, in Manual Setup, to make these settings:
    1. Reserve a DHCP-provided Private IP address for the Filemaker Pro server.
    Internet > DHCP tab
    o On the DHCP tab, click the "+" (Add) button to enter DHCP Reservations.
    o Description: <enter the desired description of the host device>
    o Reserve address by: MAC Address
    o Click Continue.
    o MAC Address: <enter the MAC hardware address of the host computer's Ethernet or wireless depending on how it accesses the network>
    o IPv4 Address: <enter the desired Private IP address you want to assign to the host>
    o Click Done.
    2. Setup Port Mapping on the AEBSn.
    Advanced > Port Mapping tab
    o Click the "+" (Add) button
    o Service: <choose the appropriate service from the Service pop-up menu or leave blank>
    o Public UDP Port(s): <enter the appropriate UDP port values>
    o Public TCP Port(s): <enter the appropriate TCP port values>
    o Private IP Address: <enter the IP address of the host server>
    o Private UDP Port(s): <enter the same as Public UDP Ports or your choice>
    o Private TCP Port(s): <enter the same as Public TCP Ports or your choice>
    o Click "Continue"

  • DA server within a DMZ - ports needed for internal network

    Hi,
     I'm planning on adding a domain joined DA server in my DMZ. The DA server will have 2 NICs, one for the internal network and the other for the external. I'll be using two consecutive public IPv4 addresses.
    On my external firewall I'll be opening the following ports for my DA server:
    - Port 443 inbound and outbound
    - UDP 3544 inbound and outbound.
    On my Juniper firewall between the internal network and DMZ I'll be opening the following bi directional ports between my DC and DA server:
    - IP Protocol 41 inbound and outbound.
     TCP/UDP 53, 88, 3389, 389, 443, 445, 636, 3268, 3269
    Am I right in thinking that in order for my DA clients to reach file shares (for example) I need to ensure that the required protocol and ports are open between my DA server and my file share (i.e. 443)? Doesn't this open a whole load of security holes?
    Thanks
    IT Support/Everything

    Hi there - in a similar scenario on many customer sites i have done the following configurations on the Internal Firewalls
    Internal IP of the DA Server ---> allow all traffic to selected VLAN's
    The above rule is restricting traffic from the DA Server to the required VLAN's / Networks you specify, The reasoning being is that Direct Access requires full connectivity to your apps / infrastructure. 
    john davies

  • Higher End Usage for Airport Network

    Greetings...
    I am creating a wireless network for my company of which there are roughly 40 users who will be using it intermittently. In order to cover the area I have, I installed 3 Airport Extreme (new ones), gave them all the same wireless network name, and the exact same authentication method & password. This does allow any given person to roam around the office without losing their wireless connection, however some iBook G4's are having problems switching to a base station with a stronger signal and are instead insisting upon using one further away with a far less stable connection... I can force it to use a closer one by signing off the network completely and signing back on, but if you restart, it picks the further away base station once again. Anyone have any ideas on this? My logic for not using WDS is for more bandwidth as each base station has access to an ethernet drop. It is still better to use WDS instead of each base station having a dedicated LAN connection?

    I had the same problem. So, I named each airport with a unique name and now have 5 different signons possible (5 airports). It did not fix the problem, but as I use it more and more, I am able to figure out which airport should be used for what area. Also, I use iStumbler to see the signal/noise levels in different locations. That has helped some. Still, this is a problem that Apple needs to look into. OSX just doesn't switch to the highest level airport connection when it should.
    iStumbler will give you a lot of data about your wifi network and I highly recommend it. You can get it here for free, http://www.istumbler.net/ If you like it, I suggest giving the author a donation.

  • Unable to activate ethernet port to bridge airport network to wired clients

    Hi,
    I have two AE setup in a WDS arrangement. The WDS is working fine. My problem is that I want to connect wired clients to the remote station; but everytime I select "Enable ethernet port" and restart the AE, the option is unchecked and the ethernet port is disabled.
    Can you help?
    Many thanks,
    David.

    ... everytime I
    select "Enable ethernet port" and restart the AE, the
    option is unchecked and the ethernet port is
    disabled.
    I saw similar behavior in my setup. I seem to have gotten it working now.
    Finally, I actually attached an ethernet cable and wired client to the AE Ethernet port (instead of just trying to configure it without an actual client connected, which I tried several times). After that, when I checked the box for Enable and restarted the AE, it worked.
    Did you get yours working?

  • Port forwarding for LaCie NAS on AirPort Express

    Hello,
    I have just purchased both an AirPort Express and Airport Extreme to which I would like to connect a LaCie 5big NAS Pro. The NAS is physically connected to the AirPort Express, which is acting as a bridge to the AirPort Extreme. The issue is that all the ports which the NAS uses for various sharing services (SFTP, HTTPS, MyNAS, etc) are unavailable. How would I go upon opening these ports on the AirPort network, or go upon forwarding new ports to the local ones?
    Thank you in advance!

    Just to make sure I understand the situation..
    You have a new AC model extreme?? Running 7.7.1?
    Are these the correct things to be doing? I've included screenshots of both the NAS port errors as well as an example of a port entry in the AirPort utility.
    Your port forwarding looks fine..
    This is pedantic but can you change the variable name.. eg.
    Harrison HTTPS
    I know will fail in most routers.. the space being illegal.. I know apple have this strange naming convention.. but it just gives me the heabie jeabies when I see it. You can call it HHTTPS for example .. anything but no spaces and pure alphanumeric.
    BTW you never need block out a private IP address.. it is not routable.. I can tell you my computer is here.
    MacProie-5
    Information
    Status:
    Active
    Type:
    Generic Device
    Connected To:
    ethport1 (Ethernet)
    Addressing
    Physical Address:
    00:1f:f3:bd:58:52
    IP Address Assignment:
    DHCP
    IP Address:
    192.168.2.103
    Always use the same IP address:
    Yes
    DHCP Lease Time:
    Infinite
    Connection Sharing
    There is no game or service assigned to this device.
    There is absolutely no way you can connect to 192.168.2.103 or 10.0.1.101 or whatever private IP is.
    When hovering over the red buttons, it reads "Port # is already in use on your router, or your router is not compatible with the UPnP-IGD/NAT-PMP protocol"
    Your last few lines are the most distressing..
    Lacie being a more Mac orientated product has included NAT-PMP protocol in the NAS to open the required ports.. automatically in an apple router..  that means it should be able to work without intervention.
    Ports cannot be opened if they are already allocated. which is what the error message means.. already in use.. they are in use because you allocated them..
    I suggest you reset to factory the AE.. start up a single computer.. leave everything else off.. Do a basic setup of the AE just to get you network and internet access.. Then power up the NAS .. and see if it can open those ports automagically.. If not then the AE is simply not going to work at this firmware level.
    BTW.. there is no doubt the 6.3.1 utility on Mac is problematic.. Apparently the iOS one is much better.. or even 5.6.1 utility on a windows PC. If you have an iphone/ipad use the airport utility app and do the setup from there.. rather than a mac.. it has more chances of working.. maybe.
    You have an express.. this sounds odd but please change the firmware in the express back to 7.6.1 (I don't use express so I know less about them). Set it up as router in place of the extreme.. and try the NAS again.. you might need to buy a switch to do all this. But it should work if you do it via the iOS device.. well worth a try too and see if the earlier firmware can auto allocate ports via the NAT-PMP or even if that fails by manually allocating them. 
    Or the other choice is a non apple router for now.. and put the Extreme in bridge .. ie take away all NAT responsibility from it .. use your non-apple router firstly try by upnp and then manually forward the ports if you have to..
    Hope something in there helps.

  • How to recover from network port configuration deletion (airport)

    a couple of years ago, i accidently deleted the network port configuration for AirPort in the Show pop-up menu. No big deal, i thought at the time. I don't have an AirPort card and I won't be using AirPort in this computer. Ok, I now have an old-style AirPort card (powerbook G3 firewire, 10.2.8) and the AirPort utility doesn't see that it's installed. I realized right away, the network doesn't have a port... so the system doesn't see it, right? So, how do I get this port back? Do I have to reload a new System entirely and not save previous network settings... or is there an easier way to recover from my blunder?

    Thanks Rob,
    Glad to be here. Yeah, 10.2 works the same as 10.4. The problem with what you suggest is that I can no longer get airport as an option in Network port configs... so when I go to the new button all the other options are there EXCEPT AirPort. This is what I need to restore. I haven't checked, but I'm assuming I've nuked the pref panel out of the master library. So, I've messed up big time. I was looking for a way to recover that didn't involve reloading the whole system. This isn't like OS 9 and older where you can go and pick a little piece and stick it back into your system folder... I think. Thanks for the reply.

  • SCOM 2012 SP1 Cisco Interface/Port Monitoring

    Hey.
    We are trying to finish our parallel rollout of SCOM 2012 (previously used 2007 R2 with xSNMP) and have ran into a snag with a port that goes to a T3 connecting two of our offices.
    The device is a Cisco 7206 router (listed as Certified in the
    latest lists). SCOM sees the port and labels it IF-47 (stupidly) during discovery and rediscovery, but won't apply any type of performance monitoring on it. I could create the override to enable one but the only monitors it shows are three rollups (High
    Discard, High Error, and High Queue Drop percentages). We need to be able to monitor utilization like any other port on the router. Ironically, SCOM has added these monitors for disabled (admin-down) ports.
    We have the other endpoint router in SCOM and have added the interface/port to the "Critical Network Adapters Group" but that only seems to monitor availability (up or down). So besides creating my own SNMP monitors from the Cisco OIDs needed, anyone
    know of a way to get this interface/port monitored for performance (i.e. utilization)?
    One peculiarity, if I look at the monitors between this interface/port and another that has the perf monitors this one has "Network Adapter (Common)" whereas the one with the perf monitors shows "netcor cisco" of multiple fashions.
    thanks!

    Hi,
    Some monitors are disabled by default. For details about the monitors, please see the section “Tuning Alerts for Network Monitoring” in the following document:
    Tuning Network Monitoring
    http://technet.microsoft.com/en-us/library/hh282073.aspx
    For utilization information, we can check the views:
    Viewing Network Devices and Data in Operations Manager
    http://technet.microsoft.com/en-us/library/hh212706.aspx
    In addition, I would like to share the following post about network monitoring:
    What Gets Monitored with System Center Operations Manager 2012 Network Monitoring
    http://blogs.technet.com/b/momteam/archive/2011/09/20/what-gets-monitored-with-system-center-operations-manager-2012-network-monitoring.aspx
    Network Monitoring with System Center Operations Manager 2012
    http://blogs.technet.com/b/ptsblog/archive/2011/11/28/network-monitoring-with-system-center-operations-manager-2012.aspx
    Thanks.
    Nicholas Li
    TechNet Community Support

  • I am using SURPLUSMETER :) I am also using Apple Airport Time Capsule as my Router that is connected to my Satellite dish Internet Modem ... Now on the Surplusmeter I have the option for PPP Modem . Ethernet Port , Airport , Network Card ,

    I am using SURPLUSMETER I am also using Apple Airport Time Capsule as my Router that is connected to my Satellite dish Internet Modem ... Now on the Surplusmeter I have the option for PPP Modem . Ethernet Port , Airport , Network Card , & Adaptor .
    Which one can I use properly to monitor all the wireless Devices in my hous

    Actually, none of the options will do what you are looking for it to do. That is because, this application only monitors the traffic from the device it is hosted on. That would also mean that you would have to run a copy on each computer that will access the Internet on your network; note their individual usages, and then, combine them to get an idea of the total usage.
    However, if you are only interested in the amount of Wi-Fi traffic that only your computer is seeing, then the "AirPort Network Card" option would be the correct choice.

  • Can I use the Airport Express to connect to a Linksys Wireless Network and then use the Ethernet port on the Airport for a wired connection to a device for internet access?  Would I be able to then also use that Ethernet pt to a Ntwk Hub for more wired c

    Thanks for the help.  Looked but not clear on what I am trying to do as being possible.  Can I use an Airport Express to connect wireless to a Linksys Wireless Router, such that I can then use the Ethernet ports on the Airport to either connected to a PC wired, or even use a hub off the Airport Express to allow multiple wired connections to it? 
    I am not looking to have the Airport Express extend my wireless network, just connect to it and provide me wired connections in a different location from where my Linksys Route is located.  Would prefer to replace Linksys with all Apple, but just not possible financially yet.  Thanks for the help.

    If the AirPort Express Base Station (AX) is an 802.11n model, then yes, you can reconfigure it as a wireless Ethernet bridge. In this configuration, the AX would join the wireless network provided by the Linksys router and its Ethernet port would be enabled for either a single wired device or for an Ethernet hub or switch for multiple devices.

  • How do I open ports on my airport extreme and assign a fixed IP Address for a device connected to my network?

    I recently had a security system installed in my house.  One of the features is an EPAD which enables me to have a virtual keypad on my iphone, and computer to operate the alarm system.  The technician was not familiar with Mac's and Airports.  How do I open port 80 to 80 in my airport and assign a fixed IP address for the EPAD?  Apparently this is what is needed to make this work.

    There are three ranges of "strictly local" IP addresses reserved for local Network use:
    192.168.xxx.yyy
    172.16.xxx.yyy
    10.xxx.yyy.zzz
    What your Router does for you is to act as your agent on the Internet.Your requests are packaged up and forwarded on your behalf, and only when a response is expected is the response returned to your local IP address.
    Directing Network Traffic to a Specific Computer on Your
    Network (Port Mapping)
    AirPort Extreme uses Network Address Translation (NAT) to share a single IP address with the computers that join the AirPort Extreme network. To provide Internet access to several computers with one IP address, NAT assigns private IP addresses to each computer on the AirPort Extreme network, and then matches these addresses with port numbers. The wireless device creates a port-to-private IP address table entry when a computer on your AirPort (private) network sends a request for information to the Internet.
    If you’re using a web, AppleShare, or FTP server on your AirPort Extreme network, other computers initiate communication with your server. Because the Apple wireless device has no table entries for these requests, it has no way of directing the information to the appropriate computer on your AirPort network.
    To ensure that requests are properly routed to your web, AppleShare, or FTP server, you need to establish a permanent IP address for your server and provide inbound port mapping information to your Apple wireless device.
    To set up inbound port mapping:
    1) Open AirPort Utility, select your wireless device, and then choose Base Station > Manual Setup, or double-click the device icon to open its configuration in a separate window. Enter the password if necessary.
    2) Click the Advanced button, and then click Port Mapping.
    3) Click the Add button and choose a service, such as Personal File Sharing, from the Service pop-up menu.

  • HT4260 Is Airport Express Gen 1 (no WAN port) suitable for an extended network (roaming)

    Is the Airport Express Gen 1 (no WAN port) suitable for an extended network (roaming)? It (Express) ha no WAN port.
    I have a new Airport Extreme.  I wish to extend the network (wired, not wireless) to an older (Gen 1) Airport Express.
    I have followed the instructions explicitly.
    EXCEPT: the Airport Express has only a LAN port and no WAN port.  The instructions state to insert the cable from the Extreme into the Express WAN port.
    Solutons? Thanks!

    Thanks, CRMDVM, for that explanation.
    I am successfully using the Express as extended (wireless) now with the Extreme as the primary base station.  I will try it (wired) with an ethernet cable attached to the Express (Gen 1) LAN port (which you say also functions as a WAN port in this case). BTW, my confusion arose because Gen2 of the Express includes a WAN and a LAN port

Maybe you are looking for

  • How to turn on webcam on hp pavilion g6

    my model no is B6U26PA my product name is hp pavilion g6-210tu notebook pc mt serial no is[edited by Moderator] how do i turn on my integrated web camera?

  • REG:- SQL QUERY

    HI FRENDS MY PROBLEM IS IN BELOW QUERY select SUBSTR('Sales - Alternate Channels (Sub Department).Area Manager.1',1,7) from dual HERE I WANT TO TAKE ONLY 'SALES' FROM THE STRING. BUT SOME TIME INSTEAD OF SALES IT WILL COME 'Branch Operations' LIKE TH

  • Convert files with WMV extension to QuickTime

    Is there a ways to convert video files with wmv extension to quicktime on the ipohne it self, so the video can be played on the iphone?

  • Javax.xml.soap.SOAPElement where does this  class exist

    Hi When i run the client application of a JAX-RPC it cannot find the javax.xml.soap.SOAPElement class and hence give runtime error I am using jwsdp final release Thanks and Regards Maria

  • How i can give page reminder to firefox?

    how i can give reminder to firefox for a page.