Set up vpn on mac osx server

What is the most common reason that I can connect to the newly created vpn locally but not remotely (over the wan)?

I have had the same problem with setting up L2TP on Mavericks after upgrade.  After several failed attempts I have the following recepie.
To test this you need to have two separate networks to connect you VPN client to.  One should be the same as where the server is running and the other needs to be different so that the incoming traffic to your router is coming from the outside.
I'm assuming a setup with a router and behind it a local network with an OS X server running the VPN service (vpnd daemon)
On the server
Note the local ip-adress of your server.  This should preferably be static.
Install the VPN fix from apple: http://support.apple.com/kb/DL1716
In the OS X Server VPN Service create a VPN profile where VPN Host Name is local ip-adress of the VPN server.
Restart the VPN service and save the configuration file.
On the router
Open ports 500, 1701 and 4500 to pass UDP traffic to the server.  Make sure to activate them in the router interface.
Make a note of your routers public IP address. This should be static.
If this keeps changing you can set up a dynamic domain name (http://dyndns.org)
Optional: verify that the ports are actually open using nmap:
sudo nmap -Pn -sU XX.XX.XX.XX -p500,1701,4500
Password:
Starting Nmap 6.40 ( http://nmap.org ) at 2014-02-14 14:21 CET
Nmap scan report for ... (XX.XX.XX.XX)
Host is up (0.012s latency).
PORT     STATE         SERVICE
500/udp  open          isakmp
1701/udp open|filtered L2TP
4500/udp open|filtered nat-t-ike
Nmap done: 1 IP address (1 host up) scanned in 1.29 seconds
XX.XX.XX.XX is the public IP-adress of the router.  You can also try the same on the local IP-address of the server.
On the client
Copy the configuration file and install it by double klicking on the file.
Connect the client to the same local network as the vpn-server and activate the VPN connection. 
Verify that the VPN connection comes up.
Up to this point, smooth sailing. 
Now change the Server address to the IP-address of the router and turn on extra logging found under Advanced. Save the new configuration.
Bring up the VPN connection again.  Should work.  Right?
I did not for me.  The error complains about the L2TP-VPN-server not responding.
Digging deeper using the system logger I found the error
2014-02-14 14:43:31,039 racoon[60284]: IKE Packet: receive failed. (Malformed or unexpected cookie).
2014-02-14 14:43:31,039 racoon[60284]: Malformed cookie received or the initiator's cookies collide.
2014-02-14 14:43:31,172 pppd[60283]: IPSec connection failed
2014-02-14 14:43:31,172 racoon[60284]: vpn_control socket closed by peer.
2014-02-14 14:43:31,173 racoon[60284]: received disconnect all command
So it sort of works, but complains about some bad cookie.
The simple change of the IP-address apparentely generates this error.
Now change the network of the client so that it is not on the same networks as the server.
Bring up the VPN again.  Now it just works.
So apparently, when the traffic is coming in from the outside the VPN connection just works.
If you change back to the local network of the server and the keep the router IP-address the error is back.
Conclusion
The conclusion is that the client used for connecting to the VPN network must be on an outside network.
In retrospect, this makes sense since we should test using an environment that reproduces the actual use case. The crux is to ensure that the client traffic is coming in from the outside.
Hope this helps.

Similar Messages

  • How to set up VPN using MAC OSX 10.4.11, Please help I need someone to help me set up VPN using regular DSL connection on my home so someone can help me troubleshoot my XSAN system remotely. THANKS

    Hello,
    I'm having trouble setting up a VPN using MAC OSX 10.4.11 Server. I have and XSAN system and one of my volumes has been down for quite a while now. There is a very kind MAC IT professional that is willing to help be troubleshoot my system but he needs to be able to access my system remotely. I am able to connect the MDC to DSL but I haven't been able to set up the VPN. Please help, this is an emergency. Thanks!
    Marco

    have you forwared the ports on your router? Why not let him in via teamviewer? its free and mac compatable

  • Mac OSX Server VPN Not Working

    Heres how my setup is: I have an ATT DHCP Server/Router That assigns my public ip.
    I have an Apple AirPort Extreme in Bridge Mode Which hosts the main wifi connection.
    I have my Mac OSX Server connected to the AirPort Extreme
    On my ATT Router DHCP Server's Firewall I have my computer set to DMZ Plus mode which forwards all ports on the network to my mac.
    I am trying to connect to the vpn network via my MacBook Pro and iPhone5 and I cannot. However I can connect to the online wiki page on my server by going to server.djswirkmke.com if you would like to see it. My host name is server.local on the network but on the internet it is server.djswirkmke.com I also have a mail domain setup as mail.djswirkmke.com. My problem is I am not able to connect to the vpn on the client computers can you please help?

    In a moment of random frustration, I tried listing the DNS server in VPN settings three times, and it somehow fixed the problem. Even though it is the same IP all three times, it works when it is listed three times but not when it is listed just once.
    In other words, in VPN > Settings > Client Information > DNS Servers, I have:
    192.168.100.64
    192.168.100.64
    192.168.100.64
    Hope this helps someone having the same problem.

  • Need help setting up Mac OSX Server for remote/off-site access

    Hello, I want to be able to access our g5 tower running Mac OSX Server 10.5.8 remotely when not in the office. We have a static IP.
    Are there easy step-by-step directions someone could provide or point me to? Thanks a bunch.

    Hi
    its really easy
    You need to have Apple remote desktop
    there are bunch of software s like chichen vnc and etc.
    01. open your router from your web browser
    02. go to nat settings
    03. screch the option calld port forwading
    04. enter the server ip address to that
    05. save and restart the router
    ** What you did so far
    if some one want to connect from your static ip address now it will forwerd to your server. *******
    Go to system preferences (on server)
    go to sharing
    enable remote management
    select opetions which you want
    your done
    2nd part Adding Computer to ARD
    Select All Computer ----> click plus button and select add by address
    put the Address : ip address
    user name : server User name
    password : server password
    eureka
    now you done

  • Is following message due to 'Java' setting left unchecked? Mac OSX supportsUser Authentication Mechanism (UAM) plug - ins from other manufacturers to control access to servers.To use a UAM, copy the plug - in to: Library/ Filesystems/ AppleShare/ Authenti

    Is following message due to 'Java' setting left unchecked?
    Mac OSX supportsUser Authentication Mechanism (UAM) plug - ins from other manufacturers to control access to servers.To use a UAM, copy the plug - in to: Library/ Filesystems/ AppleShare/ Authenti

    Man that is an ancient message.
    The last time I saw that was using Mac clients connected to a Microsoft (Windows) Server running 'Services for Macintosh' which included the ability to act as an AppleShare compatible file server. Because Microsoft have a different security system for defining accounts which includes the 'domain' as well as username, the standard Mac AFP client did not know how to send that information.
    Therefore Apple made it possible to installed a plugin in the form of a UAM or User Authentication Mechanism which added the ability to send this information to login to the fileserver.
    See http://support.microsoft.com/kb/101747
    However Microsoft have long discontinued 'Services for Macintosh' and now the only way for a Mac to connect to a standard Windows Server is via SMB not AFP. I don't believe this plugin is available to download anymore.

  • Script won't run on machine w/MAC OSX Server 10.4.9

    Why won't the following script work on a machine that is running MAC OSX Server 10.4.9. On Machines running Mac OS X 10.4.9 it works fine, but on my server machine it won't name the file as per the script--the menu dialog box pops ("save as") up asking for a file name.??
    The only difference between the machines as far as I can tell is the OS.
    Thanks.
    Pedro
    global fileSpec
    tell application "TextEdit"
    activate
    tell application "Finder" to set visible of process "TextEdit" to false
    tell application "Finder"
    set theFileName to "Date.rtf"
    set fileSpec to "Photo [Data]:Archive error LOG:" & theFileName
    end tell
    save document 1 in fileSpec
    tell text of document 1
    set the size to 20
    set the font to "Lucida Grande"
    end tell
    close document 1 saving yes
    end tell
    G5   Mac OS X (10.4.9)  

    Edit: sorry, you should be choosing a folder, not a file. Try this script instead.
    tell application "Finder"
        activate
        set tempy to choose folder
        display dialog ("" & tempy)
    end tell

  • Not installing Mac OSX Server 10.5.4

    Hello Friends...
    I purchased Mac OSX Server 10.5.4 Leopard DVD.
    I would like to install and configure it.
    According to the manual , its not working.
    It is getting upgrade to my Mac mini 10.5.7.
    After installing , it wants to restart. But, its not booting and getting always restarted.
    So, any advices and suggestions from your side.
    Regards,
    Bhanu

    I'm going to point you to these two places to see if you can resolve your issues:
    http://discussions.apple.com/thread.jspa?threadID=2019706&tstart=300
    http://support.apple.com/kb/HT3479
    Basically what happens is if you insert the Server install DVD and start the installer package, if the DVD will boot your Mini it will show the 'Restart' button. If it can't, the installer will run and then you should follow the instructions in the second link.
    Given the fact that many have tried and failed with the second method, I would attach the Mini, in target disk mode, to another Intel-based machine and run the install from there with the Mini as the target. Then boot the other machine from the Mini's disk and let the Setup Assistant finish -don't configure any services on the server in this mode other than setting it up as standard or advanced, apply any updates and then restart. Then shutdown both machines, detach the Mini, then let it boot on its own and continue configuration from there. I've done this several times with both PPC and Intel-based machines with positive results.

  • Is a mac osx server fits to a office with 10 PCs

    I want to set up a server for my company
    The purpose of the server is to store files, share files & printer, a calendar, an internal website( for hosting a blog and filemaker files), regular backup
    My office will have 10 PCs (window 7) connects to the server, and my company dont have an IT expertise ..
    I have considered between Window SBS, Mac osx server and ubuntus server
    I think a mac mini server is the best solution for me as:
    1: easy installation
    2: less expensive than SBS
    however, is the mac mini server work well in my case?
    Thank you very much!

    An Apple Mac Mini server would be a good fit. It includes two 500GB drives and an unlimited-user copy of Mac OS X Server. Not bad for $999.
    Mac OS X Server itself is very easy to configure and Apple has a lot of resources on their website to help guide you.
    You will want to make sure to configure all of your file sharing share points with SMB for the Windows clients to access. You won't be able to take full advantage of Mac OS X Server's offerings, but for file sharing it will be fine.

  • How do I re-install my Mac OSX Server from scratch

    Hi,
    I have purchased two MacMini Servers with 10.6 OSX Server software pre-installed.
    I have changed the organization as our company name changed and run into license issues.
    I want to re-install the Mac OSX Server software and start from scratch. How do I go about this. I tried yesterday for many hours to do so and the new installs are still running into duplicate license issues and other issues. What is the best approach to do re-install? I am willing to erase the internal Hard Disk and boot (with an external DVD optical drive) if that is the best way to go. What are the steps?
    I have the original CDs or DVDs and have extra, external hard disks to do a Time Machine backup, etc.
    Thanks,
    Don

    If you are looking to do a nuke and pave of the system, and you have an external optical drive, then yes, that is likely the most direct method. Connect the optical drive, insert the installation DVD, and reboot the system targeting the optical disk as the boot volume (you can do this by holding down the C key or the Option key during startup).
    Now, if you do not have an optical drive, you can put the installation disk into another Mac running 10.6 and use the Remote Install Mac OS X application in your Utilities folder.
    Hope this helps

  • Bridge CS6 Mac cannot browse Mac OSX server 10.8

    Hello:
    We had a drobo file server which was mounted on the desktop and had no issues browseing the volume in bridge.  After we moved to a new Mac OSX server running 10.8 we can no longer browse the mounted server.  We get a primission violation. Using the finder we're able to browse files and folders and create new files without this same type of issue.
    Is there a preference that allows connection to a network volume via Bridge?
    I hope I was clear on the discritpion of the problem.
    Thanks,
    Rick

    Try a reset of preferences for Bridge using option key while restarting Bridge and choose reset prefs.
    There is also a plist file for Bridge in the user library preferences folder that can be manual deleted and will be refreshed after restarting Bridge.
    And maybe run a check and repair permission with either Apple Disk utility or cocktail.
    Unfortunately Bridge is not designed for use over a network nor official supported by Adobe when it comes networks.

  • Mac OSX Server error message in console

    Hi,
    I have the following error message having recently bought and configured (for the first time) a MacMini Server with Mac OSX Server 10.6.n.
    1/26/11 1:38:11 PM org.dovecot.dovecotd[8582] Fatal: Invalid configuration in /private/etc/dovecot/dovecot.conf
    Can someone help me understand how to fix this problem?
    I can see the file in terminal, but don't know how to edit the file or change the file configuration to be correct.
    Thanks,
    Don

    Don,
    Welcome to the Discussions.
    You may find a better audience for you question over in the server-specfic discussions.
    http://discussions.apple.com/category.jspa?categoryID=96
    Matt

  • What is xgrid admin in mac osx server?

    Hello friends...
    What is xgrid admin in mac osx server?

    Xgrid is a grid or a compute cluster or distributed batch-processing engine. A grid allows an application programmer or system administrator to manage and coordinate a collection of computers and to distribute portions of a task across multiple computers.
    Apple have [an Xgrid introduction|http://www.apple.com/server/macosx/technology/xgrid.html] available, and for details, have a look at the [Xgrid Administration and High Performance Computing|http://images.apple.com/server/macosx/docs/XgridAdmin_and_HPCv10.5.pdf] document that is available among the Mac OS X Server manuals.
    Here is the [high-level overview of Mac OS X 10.5 Leopard Server technologies|http://www.apple.com/server/macosx/technology>, which can connect you with answers to many questions.

  • Where can I find the download for Mac OSX Server Mountain Lion ?

    Where can I find the download for Mac OSX Server Mountain Lion ?

    On the App Store. Search for it:

  • Installing Mac OSX Server hangs at Network Configuration

    Hi there!
    I am installing my new Mac OSX Server (SNow Leopard) straight forward the assistant.
    Asking for Language: OK
    Asking for Country: OK
    Keyboard Layout: OK
    Entering License: OK
    Configuring Network:
    Ethernet: Static
    Airport: OFF
    FireWire: OFF
    Clicking on Forward to continue: The assistant keeps telling me "configuring network". Nothing happens. It is doing that for hours now.
    I tried to connect with Server Admin tool: OK works.
    The network is up and running, but the assistant is not continuing.
    Any ideas?
    Thanks for any help or suggestion

    Smells vaguely of a DNS error or IP routing or a network connectivity problem.
    What did you specify for your network settings, and particularly what was entered for the DNS server address? If you're not running DNS on your local network here, then enter no DNS servers as part of the prompting, and let Mac OS X Server establish its own default single-host DNS.
    (You're not going to be able to use your ISP DNS here; those ISP DNS servers are not valid when you are establishing a server on a network behind a NAT gateway.)
    I'd probably wipe the disk and boot from DVD and reload.

  • Mac OSX server not supported behind Airport Extreme NAT router?!!

    For a customer, I recently installed a new XServe, within a local network with an Airport Extreme (n) with FW 7.4.2. Mac OSX Server manages the router (which has a fixed IP from the ISP). Because the Mac OSX Server runs a DNS server (supporting a local domain), OSX Server reconfigured the Airport Extreme, so that it would forward DNS queries to the server. The server's dns server will forward queries for non-local domains to the ISP's dns servers.
    All clients get their IP configuration using DHCP from the router. You can't use the DHCP service of the server, as you can't disable DHCP on the router (in NAT mode).
    All clients get the router's IP as the dns server.
    HOWEVER:
    The Airport Extreme can't connect to the internal DNS server! *It doesn't seem to be able to route dns requests to the internal network* (verified using nslookup). Any dns queries sent to the router will time out.
    Come on, Airport Extreme team.. you can't claim the Airport Extreme to be the ideal router in combination with an OSX server, if this simple and very common setup is not supported! How hard can it be to either:
    ...*Allow us to disable DHCP on the router* (even when in NAT mode), so we can use the OSX server for this (which will dispatch the correct DNS settings)
    ...*Allow the router to route DNS queries to the local DNS* (OSX) server (which should be working anyway)
    Message was edited by: blackbit

    blackbit, Welcome to the discussion area!
    It doesn't seem to be able to route dns requests to the internal network (verified using nslookup).
    That is true.
    This is a user to user discussion area so Apple will not see your suggestions here. Instead go to www.apple.com/feedback/airportextreme.html and send them to Apple.

Maybe you are looking for

  • Need a step by step guide - S-VIDEO Connection

    I have concluded that the mini-DVI to S-VIDEO connection (from Apple) does not work with Mac Mini's of the 2009 vintage. So I am looking for help on the steps that I need to go through to connect a Mac Mini to 35" Sony Standard Definition TV, because

  • Very Urgent : Multithreaded - ResultSet ??

    How can a ResultSet handle more than one request at the same time. Can I make ResultSet Multithreaded??How to mak??Giv the code.. Thanks in advance>>

  • Norton Anti Virus for Mac?  Does it do anything?

    I didnt know where to post t his so sorry if it's in the wrong place.  Im just wondering if there's any reason to use Norton  for Mac.  My internet service provides it for free so I had downloaded it. (Antivirus/Firewall/LiveUpdate)   But I don't kno

  • Problem with RSC card on sun fire v490

    Hi all, I have a little problem. I got few v490 that were already used. When I connect to the management port of the RSC card I get the prompt of the RSC password, somthing i don't have. The OS doesn't get loaded and I can't do anything. ( if I had a

  • Why does iCal's appearance have to look like this?

    Why can't the columns be evenly lined up? This is the biggest flaw in iCal...