Time Capsule port mapping is broken for L2TP Servers behind NAT config.

I'm hoping that someone here can refute the below bug assertion... am I missing something?
There is a bug with Apple’s Time Capsule/Airport Express Base Station (TC/AEBS) rendering L2TP servers on the LAN unusable:
When TC/AEBS is used as a router providing NAT services to the LAN, it will NOT under any circumstance provide port mapping services for 500/UDP, 1701/UDP, & 4500/UDP making L2TP VPN servers on the LAN side of TC/AEBS are unreachable from the WAN/Internet side.
*The conditions for my tests*:
3 different external networks used for all tests: MacBook Air at home on TWC network, the Air on AT&T mobile dongle, & CentOS server at ThePlanet.
MobileMe configuration was removed from both the TC/AEBS & Snow Leopard Server on the LAN.
I used port 501 for my control-test; spot checks of other ports worked as well, though they were all < 10000.
Simultaneous local and server monitoring of port traffic using
tcpdump -vvv -i en0 -s 0 -X port 500 or port 1701 or port 4500 or port 501
The TC/AEBS was configured to forward UDP ports 501, 500, 1701, & 4500 received from the WAN interface to the Snow Leopard Server on the LAN.
The port forwarding was accomplished both 1) manually via AirPort Utility, and 2) automatically via Snow Leopard Server’s Server Preferences utility. Each was tested separately.
*The tests*:
Netcat with the following commands, in turn, on the server:
nc -l -u 501
nc -l -u 500
nc -l -u 1700
nc -l -u 4500
which causes traffic to the udp port specified to be dumped to std out. Provides a confirmation of the tcpdump output.
On the various external networks, nc -u WAN-address-of-AEBS.example.com 501 to send UDP packets on port 501. The output of the nc -l 501 command and the server-run tcpdump confirmed that packets left the client and made it to the server as expected. Remember, 501 is the control-test.
For each test permutation on ports 500, 1700, & 4500, no packets made it to the server.
Based on some web research, I’m not the only one to have found trouble with this configuration, but I haven’t been able to find any conclusive tests.
I’ve filed a bug with Apple (#7720101) and encourage you to do the same.
Message was edited by: WebMarc

Confirmed here. This only seems to be a problem with Airport 7.5.x firmware though - I find the older TCs running 7.4.2 work as expected even with BTMM / MobileMe services active.
I'm so glad you posted this - I haven't found it mentioned anywhere else and was beginning to feel very alone with this problem. I also found that having two TC 7.5s in the mix - one at both ends - also results in no response to SSH or Remote Desktop ports.

Similar Messages

  • Leopard + iChat + Time Capsule Port Forward

    Hi,
    Here are my settings
    OS: Leopard
    Modem: Motorola 2210-02
    Router: Time Capsule
    Macbook
    I am trying to use video ichat with my girlfriend in Canada but I can't get it to work. (audio works)
    Currently I am using the modem as a Bridge and I forwarded the ports on Time Capsule according to the guide for AEBS (http://portforward.com/networking/static-Mac10.4.htm). However, it's still not working.
    Is the problem coming from the port mapping? => in the private ip field should i put the router or the macbook's ip.
    Does it make a difference which setting i use as my DHCP beginning address? 10.1.0 vs 192.168.1
    Should my dhcp reservations for my macbook (and other laptop) be within or outside the dhcp beginning and end address?
    Sincerely,
    Adama

    It should work just setting it to Share An IP in the drop down.
    I am not sure if the set up is exactly the same as a Base Station but you should have a pane like this
    http://flickr.com/photos/90943061@N00/2043616510/
    10:32 PM Wednesday; March 19, 2008

  • Using external hard drive on a Time Capsule as a network drive for PCs.

    I own a Macbook Air and am using a 2TB Time Capsule router. I am currently using for automatic backups for my Macbook Air.
    I also own 2 PC laptops for the rest of the family. Would it be possible to use an external hard drive connected to the USB port of the Time Capsule as a network drive for the PCs? I want to share files between the two PCs.
    Thanks

    Yes, you can do that.. although it is not necessarily as straight forward as you might think it should be.
    1. The TC has to be running SMB compatible names. short, no spaces, pure alphanumeric.
    2. The disk must be formatted to file system the TC can read. HFS+ or Fat32.. but the HFS+ is vastly superior.. the actual format is irrelevant from sharing point of view as it is still shared via SMB to the network.
    3. It is slow.. half the speed of the same drive plugged into your computer.. although if the connection is over wireless that is probably irrelevant.
    4. You might need a powered hub to get the drive to work.. Apple underpower the USB.. and even a powered disk still won't work.
    5. There are some issues with the TC getting the USB drive to work.. too many factors to say you will have issues or not.. but be aware this is not as straight forward as it could be. or should be.
    6. If you want to share files.. you can always share them directly.. pc to pc or pc to mac.. there is no necessity to do it via a network store.. You can also use the 2TB internal drive.. create a disk image and you can then store you data in that. Internal drive is much more reliable and faster.
    See http://pondini.org/TM/TCQ3.html

  • Connect time capsule via ethernet to Mac for back-up only. Is it possible without internet connection ?

    Connect time capsule via ethernet to Mac for back-up only. Is it possible without internet connection ?

    Hi Bob,
    I'm not certain the post I sent was posted correctly, as I added it as a reply to a 3-year old thread. Since this is a recently-active thread, though not specific to the issue at hand, I thought I'd post again:
    Three years ago you helped me set up a roaming wireless network in my home. It's been rock-steady and I'm forever grateful to you for the time and guidance you gave me. I'd now like to swap out my AirPort Extreme base station for a time capsule. As I understand it, I should be able to unplug the base station and replace it with the TC without problem, so long as I use all the same settings on my TC... network name, security protocol, password, etc. Given the complexity of my network, I thought I should check with you first for any advice you might have. I don't want to set up a new network or make any changes to the existing one-- with the exception of using the TC in place of the AE. I'm already using Time Machine for backups. As a refresher, my current setup has the AE as base station and 3 expresses hard-wired with Ethernet connections elsewhere in my home. I have a 4th express set up wirelessly to use with my stereo system at the front of the house. All AXs are 'n's and are set up, as per your instructions, in Bridge mode to extend the existing network. I'm running the most updated version of Mavericks on my MBPro. Any suggestions you might have will be, as always, very much appreciated! Sincerely, Phyllis Sommers

  • How to put time capsule AP in 40 MHz (for 2.4G)

    Hello,
    Can anybody help me in putting time capsule AP in 40 MHz (for 2.4G). I am able to put 40MHz in 5G using airport utility in XP by checking use width channel.
    Thanks in advance,
    Vishal

    Can anybody help me in putting time capsule AP in 40 MHz (for 2.4G).
    Sorry, but this is not possible as the Time Capsule does not support wide channels on the 2.4 GHz radio.

  • Time Capsule + Airport Express (no password for extended guest network)

    Hi guys,
    I´m using at home an Time Capsule combined with an Airport Express for extended range.
    I´ve activated the Guest Network on the Time Capsule, using an WPA2 Password for it.
    Problem is, the Airport Express is extending both the regular network and the guest network, but there´s no password set for the extended guest network.
    So basically there are 4 networks, 3 are properly secured (TC regular and guest and AE regular) but I can´t set a password for the Guest Network that´s being extended by the Airport Express.
    I have looked everywhere on the AirPort Utility with no luck whatsoever.
    I appreciate any help on this.
    Kainan-Maki.

    Time Capsule and Airport Express, Windows 7
    So you don't have a Mac or even iOS device to setup the TC and express?
    This addition of extending guest is new in later firmware.. but you need the 6.2 utility to control it.. AFAIK.

  • How can a company sell a Times Capsule appliance as a solution for backup and die for this manufacturing fault? And with that Apple? nothing, or technical assistance. Of a sledgehammer, open the device and attempt to recover your files by force!???

    How can a company sell a Times Capsule appliance as a solution for backup and die for this manufacturing fault? And with that Apple? nothing, or technical assistance in Brasil. Of a sledgehammer, open the device and attempt to recover your files by force!???

    Heat up the bottom rubber mat with a hairdryer for 5-10 minutes to loosen the adhesive, then pull the rubber mat away from the bottom metal plate carefully.
    Then use a screwdriver to remove the 10-12 screws to open up the case.

  • Can you use Time Capsule as a print server for printers connected via Ethernet or wirelessly?

    Can you use Time Capsule as a print server for printers connected via Ethernet or wirelessly?
    I know that it works marvelous for printers connected via USB, but I'd like to know if you can use it as a more general print server.

    No, you can't, but what do you expect to gain by doing so?
    The main advantage of the print server is to provide multi-user network access to a printer that typically only supports a single connection. Since, by definition, your printer already has a network connection and can be used by multiple users.

  • I presently have a linksys wifi router, can i connect a time capsule through cat 5 cable for my apple products and to boost my signal ?

    I presently have a linksys wifi router, can i connect a time capsule through cat 5 cable for my apple products and to boost my signal .i live in a three story home and my linksys is in the basement. I have one cable on the top floor where most of my computers/ipads are.

    can i connect a time capsule through cat 5 cable for my apple products and to boost my signal
    Yes, configure the Time Capsule to create a wireless network using the exact same wireless network name and password as the Linksys wireless network.

  • We use a time capsule as the wireless router for our house.  We cannot get service to the whole house.  Is there anyway to boost the signal?

    We use a 2TB Time Capsule as our wireless airport for the whole house but we can't get the signal to all rooms.  Is there anyway to boost the signal?

    You to purchase an extreme or express and use it as wrieless extender.. that is the only way Apple provided for boosting the signal.

  • Time Capsule + Ports

    When I try to open any ports my entire network crashes and I have to Factory Reset the Time Capsule to get back online...

    I suggest you use NAT-Port Mapping Protocol on your TIme Capsule. NAT-PMP will dynamically open ports required for any application trying to get to the Internet. It is similar to the PC world use of UPnP - Universal Plug and Play.

  • Time capsule port forwarding problem.

    I'm trying to portforward minecraft the game to my LX195 hp mediasmart home server but everytime i do 25565 FOR all of the public and private UDP and TCP's and update it with my home servers static ip it doesn't work i always use canyouseeme.org to check if it's open and 25565 (the port) is always closed or connection refused
    Please help!
    Thanks

    1. Find your computer's IP address. In system preferences, click on "Network.: Then click on either Ethernet or Airport (depending on how you're connected to your network). Your IP address will be listed on the right and will likely be something like 10.0.1.3.
    2. Open Airport Utility, select your time capsule and select "Manual Setup." Click on the "Advanced" button, then on the "Port Mapping" tab. Click the + to make a new port map.
    3. Enter the port mapping information as followed:
    Service: Choose a Service (This doesn't matter)
    Public UDP Ports: 6890-6900
    Public TCP Ports: 6890-6900
    Private IP Address: 10.0.1.3 (This must be your IP address that you found in step 1)
    Private UDP Ports: 6890-6900
    Private TCP Ports: 6890-6900
    4. Click "Continue." Type in a description such as "MSN" and then click "Done." The other fields do not mater. Click "Update" at the bottom of airport utility to update these new settings.
    Once your airport device has restarted, the ports should then be forwarded.
    If this doesn't work properly, it is possible that your time capsule is connected to the internet through another router or router/modem. You must turn off the routing functions on either of the routers.
    You can also try enabling the default host in airport utility. This should forward all ports to a computer's IP address. Find it in Airport Utility / Manual Setup / Internet / NAT. Enter your computer's IP address in the "Enable Default Host At:" box and update.

  • Can I use 2 time capsules at once? 1 for back up and other as a hard drive?

    I have a 1tb time capsule that I use for back up of my macbook pro. Everything works great. However, like most people, I have problems with my hard disc space and have to store my itunes and photos externally on a portable usb hard drive. This works fine for now. I keep it plugged in most of the time so that time machine can back it up when it is physically attached buy the usb cable. Obviously, when it isn't, it misses out being backed up.
    My question is this. Would it be a bad idea to run two time capsules at the same time? I would like to keep my current time capsule as the back up and the new one purely as an external hard drive for storage. Would the old time capsule back up both the new time capsule and my macbook? The reason for my question is that my current portable is too small now and I currently move my laptop around so I am forever unplugging this usb drive which becomes a real pain and also, interupts it being backed up, etc.
    I am looking for a wireless solution so that the external drive gets backed up along with my laptop no matter what. I used to have the usb portable drive plugged into the back of my time capsule but it wouldn't appear in the list in time machine preferences to be included. I am aware that I can buy wireless hard drives but would like to find out about an extra time capsule first.
    Hopefully this is a simple question for someone. Any help gratefully appreciated, thanks.

    Samanthaluck wrote:
    My question is this. Would it be a bad idea to run two time capsules at the same time? I would like to keep my current time capsule as the back up and the new one purely as an external hard drive for storage.
    You don't need another Time Capsule. Just buy a USB HDD and plug it into the TC USB port for additional storage.
    Would the old time capsule back up both the new time capsule and my macbook?
    No. Time Machine can back up TO a NAS (e.g TC), but cannot backup FROM a NAS (e.g. TC). An app such as CarbonCopyCloner (donateware) or SuperDuper! (purchase) may be able to, however.

  • Time Capsule- Can i use it for Time Machine and store media files?

    Hi,
    I'm very new to Time Capsule (have a 1TB TC), but have been using Time Machine to back up my MacBook Pro onto an external HD for a while now.
    Here's my question. is it possible to use the Time Machine capabilities of Time Capsule while also using it to store music and picture files. Ideally I'd like to be able to have my iTunes and iPhoto library available on the Time Capsule. that way it could be centralized and readable from a few Macs in the house.
    Thanks!

    brianfallen wrote:
    When you say the info on it won't be backed up. What do you mean "the info on it"? Do you just mean the mp3, AAC ...etc files aren't backed up because they live on the TC only?
    I just want to make sure cause I did the same thing but I want to make sure I wont lose all my music and photos.
    If the only place you have these music and photo files is on the TC HDD, then if the TC HDD fails, you lose all those files. Here's another option. TC has an archive feature. That means you can, via AirPort Utility -> Disks, use the Archive feature to clone the TC HDD onto a USB HDD attached to the USB port of TC. It's not like TM, making incremental backups. You have to manually archive it, but it is an alternative.
    My photos remain on my iMac internal HDD. That means they are backed up by TM onto the TC HDD. If my iMac internal HDD fails, I still have the TM backups. I also backup yearly photos to DVDs. Photos are irreplaceble, you know.

  • HELP ME PLEASE: MY TIME CAPSULE IS NO LONGER WORKING FOR ME

    Due to a recent move,  my Time Capsule doesn't seem to have the range & strength that it once did.
    - A Local Internet Provider (MEDIACOM) installed their Router for our Internet/Internet Phone Service. 
    - Due to the required use of the Provider's Router, I had to set my Time Capsule in "Bridge Mode" to function. 
    - Although my computer can recognize BOTH (MEDIACOM & my Time Capsule) networks, I select & use my Time Capsule for my Home Wireless Network. 
    - It seems to me, that in "Bridge Mode" my Time Capsule doesn't have the range & strength that it once did. For whatever the reason, I need to increase my Wireless range. 
    - I ONLY use the Wireless WiFi (My Home Network) to access my e-mail/Internet from my iMac or IPAD.  All "other" Internet access (streaming) is done through my TV system, which is hard wired to the Internet.  Again, the Internet is hard-wired and directly connected to the TV's receiver. Thus, there isn't a huge demand for my Wireless Home Network. It's also password protected so nobody else is using it.
    - I will admit that I'm now in a much bigger house (about twice as big as the previous home).  Also, I usually have to access it on the opposite end of the house.
    How do I extend my Wireless range? Any suggestions, How To's, or useful websites would be most appreciated. In other words, what hardware do I need to purchase & how do I set it up?  My Tech knowledge is very limited. I think the solution will need to also be wireless because the distance is to great for ETHERNET.  That is, unless I can use what is already wired into my home.  For example, I'm told there is a CAT 5 Access point (whatever that is) very near the vicinity of where I need wireless access.  Would the purchase of another Time Capsule potentially solve my problem?

    Due to a recent move,  my Time Capsule doesn't seem to have the range & strength that it once did.
    It must have the same strength it always had. .but the new environment blocks or absorbs wifi.. some houses are like a black hole.. nothing gets out.
    - It seems to me, that in "Bridge Mode" my Time Capsule doesn't have the range & strength that it once did. For whatever the reason, I need to increase my Wireless range.
    Being in bridge or being in router mode makes no difference whatsoever to wireless output.. however range is affected dramatically by environment and perhaps by operating next to a much higher wireless power device in the Mediacom router.
    How do I extend my Wireless range?
    If I give you useful sites.. apple mods will delete my posts.. so you should google yourself for "extend lan"
      That is, unless I can use what is already wired into my home.  For example, I'm told there is a CAT 5 Access point (whatever that is) very near the vicinity of where I need wireless access. 
    This is the best method.. you do not need another TC.. plug the existing one into the Cat5 access point on the wall.. plug the other end into any LAN Port on the Mediacom router.. and as long as the cable is in good condition it will work great.
    Make sure you are doing the setup correctly.
    You bridge the TC.
    You also create a wireless network.. it can be the same name as the mediacom router or different .. that is up to you. You do not attempt to extend the wireless.. this is most important.
    Try it now.. all you need is a patch cord or two.

Maybe you are looking for

  • I am a student and Firefox 4 is not compatible with TestGen, now I have a real problem. I can't get Firefox 3 to come back

    I am enrolled in Intermediate Algebra with Pearson My Math Lab and they use TestGen to take quizzes and test. Firefox 3 was compatible with this program. Over the weekend I download Firefox 4 and lost access to my tests and quizzes. Their Tech Suppor

  • Help me please. Kernel Panics on a new laptop

    Interval Since Last Panic Report:  433561 sec Panics Since Last Report:          1 Anonymous UUID:                    D4D8F8FB-91C8-3561-AD6E-05AC3AD5481C Wed Nov  6 21:41:15 2013 panic(cpu 4 caller 0xffffff8026cb8945): Kernel trap at 0xffffff7fa85aa

  • Calculate Average value based on Day ??

    Hello, I am trying to calculate the Average value based on a day. The data is presented as follows... Day          SOCount Mon                34 Mon                 56 Mon                 67 Tues               24 Tues               25 Tues           

  • Confusion b/w term.Roll area and Work area

    Hi, Can someone explain me these Two Term in simple english. 1)Roll Area 2)Work Area How aou distinguish b/w them. Thanks. Samir.

  • Java.lang.OutOfMemoryError(Native Method)

    Hello Everybody, We hava a java.lang.OutOfMemoryError,the problem weblogic server installed in windows 2003 x64,weblogic version 9.2 MP1,sun jdk 1.5.0_22 32bit,the memory configuration below: set MEM_ARGS=-server -Xms1024m -Xmx1024m -verbose:gc -Xlog