Unable to access gateway and DNS via VPN (L2TP) with Snow Leopard Server

Summary:
After rebooting my VPN server, i am able to establish a VPN (L2TP) connection from outside my private network. I am able to connect (ping, SSH, …) the gateway only until the first client disconnects. Then i can perfectly access all the other computers of the private network, but i cannot access the private IP address of the gateway.
Additionally, during my first VPN connection, my DNS server, which is on the same server, is not working properly with VPN. I can access it with the public IP address of my gateway. I can access it from inside my private network. A port scan indicates me that the port 53 is open, but a dig returns me a timeout.
Configuration:
Cluster of 19 Xserve3.1 - Snow Leopard Server 10.6.2
Private network 192.168.1.0/255.255.255.0 -> domain name: cluster
-> 1 controller, which act as a gateway for the cluster private network, with the following services activated:
DHCP, DNS, firewall (allowing all incoming traffic for each groups for test purposes), NAT, VPN, OpenDirectory, web, software update, AFP, NFS and Xgrid controller.
en0: fixed public IP address -> controller.example.com
en1: 192.168.1.254 -> controller.cluster
-> 18 agents with AFP and Xgrid agent activated:
en1: 192.168.1.x -> nodex.cluster with x between 1 and 18
VPN (L2TP) server distributes IP addresses between 192.168.1.201 and 192.168.1.210 (-> vpn1.cluster to vpn10.cluster). Client informations contain the private network DNS server informations (192.168.1.254, search domain: cluster).
_*Detailed problem description:*_
After rebooting the Xserve, my VPN server works fine except for the DNS. My client receives the correct informations:
Configure IPv4: Using PPP
IPv4 address: 192.168.1.201
Subnet Mask:
Router: 192.168.1.254
DNS: 192.168.1.254
Search domain: cluster
From my VPN client, i can ping all the Xserve of my cluster (192.168.1.1 to 18 and 192.168.1.254). If i have a look in Server Admin > Settings > Network, i have three interfaces listed: en0, en1 and ppp0 of family IPv4 with address 192.168.1.254 and DNS name controller.cluster.
The DNS server returns me timeouts when i try to do a dig from my VPN client even if i am able to access it directly from a computer inside or outside my private network.
After i disconnect, i can see in Server Admin that the IP address of my ppp0 interface has switch to my public IP address.
Then i can always establish a VPN (L2TP) connection, but the client receives the following informations:
Configure IPv4: Using PPP
IPv4 address: 192.168.1.202
Subnet Mask:
Router: (Public IP address of my VPN server)
DNS: 192.168.1.254
Search domain: cluster
From my VPN client, i can access all the other computers of my network (192.168.1.1 to 192.168.1.18) but when i ping my gateway (192.168.1.254), it returns me timeouts.
I have two "lazy" solutions to this problem: 1) Configure VPN and DNS servers on two differents Xserve, 2) Put the public IP address of my gateway as DNS server address, but none of these solutions are acceptable for me…
Any help is welcome!!!

I would suggest taking a look at:
server admin:vpn:settings:client information:network route definitions.
as I understand your setup it should be something like
192.168.1.0 255.255.255.0 private.
at least as a start. I just got done troubleshooting a similar issue but via two subnets:
http://discussions.apple.com/thread.jspa?threadID=2292827&tstart=0

Similar Messages

  • Are there any problems with Snow Leopard Server (Xserve) and PPC Clients

    Hi,
    are there any problems identified yet with Snow Leopard Server, installed on a Xserve and PPC Clients running Mac OS X Tiger and Leopard?
    Currently I have a Xserve Intel running Leopard Server and about 12 Mac Minis PPC running Mac OS X Tiger and Mac OS X Leopard. The Xserve serves services like DNS, OpenDirectory, Software Update Server, NetBoot, etc. All users have Home Directories stored on the Xserve.
    Now I want to install Snow Leoaprd Server on the Xserve, but I wonder if there are any problems using the PPC Clients? I have read something like this on a german website.
    Thanks!

    We've actually found that the Server 10.6.3 DVD does an amazingly smooth job of upgrading 10.5.8. We've been upgrading our production servers and nothing has gone wrong yet. Snow Leopard employs an archive and install method of upgrading which results in an install which is very close to a clean install. So it's been very convenient for us because our servers are used as Windows PDCs and it's a pain in the *** to have to re-join all PCs to the domain if we start from scratch.

  • I'm running OS 10.4 and purchased Mac Box Set with Snow Leopard.  When I run the Snow Leo install it errors saying I need OS 10.5 to run the install.  How do I get around this?  I've read that it's possible to go direcectly from 10.4 to 10.6.

    I'm running OS 10.4 and purchased Mac Box Set with Snow Leopard.  When I run the Snow Leo install it errors saying I need OS 10.5 to run the install.  How do I get around this?  I've read that it's possible to go direcectly from 10.4 to 10.6.

    To buy a hard drive try Newegg.com http://www.newegg.com/Store/SubCategory.aspx?SubCategory=380&name=Laptop-Hard-Dr ives or OWC http://eshop.macsales.com/shop/hard-drives/2.5-Notebook/
    Here's a cheap SATA external hard drive case on eBay http://cgi.ebay.com/USB-2-5-SATA-HDD-HARD-DRIVE-EXTERNAL-ENCLOSURE-CASE-BOX-/120 636286623?pt=PCC_Drives_Storage_Internal&hash=item1c167ba69f
    Here's instructions on replacing the hard drive http://creativemac.digitalmedianet.com/articles/viewarticle.jsp?id=45088

  • DNS Configured-Best Practice on Snow Leopard Server?

    How many of you configure and run DNS on your Snow Leopard server as a best practice, even if that server is not the primary DNS server on the network, and you are not using Open Directory? Is configuring DNS a best practice if your server has a FQDN name? Does it run better?
    I had an Apple engineer once tell me (this is back in the Tiger Server days) that the servers just run better when DNS is configured correctly, even if all you are doing is file sharing. Is there some truth to that?
    I'd like to hear from you either way, whether you're an advocate for configuring DNS in such an environment, or if you're not.
    Thanks.

    Ok, local DNS services (unicast DNS) are typically straightforward to set up, very useful to have, and can be necessary for various modern network services, so I'm unsure why this is even particularly an open question.  Which leads me to wonder what other factors might be under consideration here; of what I'm missing.
    The Bonjour mDNS stuff is certainly very nice, too.  But not everything around supports Bonjour, unfortunately.
    As for being authoritative, the self-hosted out-of-the-box DNS server is authoritative for its own zone.  That's how DNS works for this stuff.
    And as for querying other DNS servers from that local DNS server (or, if you decide to reconfigure it and deploy and start using DNS services on your LAN), then that's how DNS servers work.
    And yes, the caching of DNS responses both within the DNS clients and within the local DNS server is typical.  This also means that there is need no references to ISP or other DNS servers on your LAN for frequent translations; no other caching servers and no other forwarding servers are required.

  • Running CF9 and CF10 together on Mac with Snow Leopard

    This may be a very basic question, but I am trying to set up CF10 to run alongside CF9 on a developer installation on my Macbook with Snow Leopard. I can see both administrators, CF9 on localhost and CF10 on 127.0.0.1:8500. It seems that both are runing on JRUN because I can't run CF10 without having CF9 running.
    How do I set up a site to run on CF10 only? I can't figure out how to set up the virtual host files to have the site determine which version to run. If I set up the virtual host in Apache2 httpd-vhosts.conf file, it seems to run the site using CF9 and it breaks because it has to run on CF10. If I set up the server.xml file as if it was using Tomcat, then it seems to break the ability to get to the administrator app in either CF9 or CF10 to run.
    Any ideas out there to help me?

    Do you mean like this? First, copy the URL. Next, open up TextEdit. Here, you can paste the URL. Next, highlight the URL, right click it and select "Make Link". After that, press the arrow key or click in a blank spot on TextEdit. Select the link, and type in the new name of the link. You have now successfully created a hyperlink.

  • DNS Settings have Changed with Snow Leopard Update

    Before I upgraded to SL, I was able to append a DNS server to the list of servers that my MacBook Pro acquired from the DHCP server. This way, I didn't have to manually edit my DNS settings all the time when I was in the office and wanted to access our lab network by name. Now after the upgrade, I have to remove all manually entered DNS servers before it will use the DNS servers given to it by the DHCP server. Is there a way that I can always append my lab DNS server to the list given to me by DHCP?
    Thanks,
    John

    I am on or office wireless network which handles the DHCP lease and DNS addressing, but I am an engineer in the office and access the lab often and we have another DNS server in the lab to handle all of the lab network. The Sales folk don't need access to the lab so the DHCP server doesn't give out the lab dns server... I would like to access the lab via name, not IP, so I need the lab DNS server on my list of servers. If I can't append this to the DHCP list, I have to manually add all three every time I am in the office. I am frequently out at customer/vendor sites and use thier wireless, so I get thier DNS list.
    Short answer is I need our lab DNS server on the list and frequently move from network to network... I want it to work the way it was before the "upgrade", which wasn't much of an "upgrade" if it breaks this. I want my Leopard back.
    John

  • IWork is all white and doesn't work properly with Snow Leopard

    Whenever I open Pages or Numbers 09, everything is displayed as white. The text colour is black but I can't see the blinking text mouse icon (which looks like I). I can open templates and can only see the text when I highlight it otherwise the screen is white and I cant even type in a blank document. It all worked fine until I installed Snow Leopard.
    I had similar problems with iMovie and iDVD 09 with transparencies not working. Could this be a problem with the graphics driver for my Nvidia 8800 GT? Or is there another way to fix it?

    Apple's instructions are:
    *Transferring files from one account to another on the same Mac*
    *You can use your Shared folder:*
    1) Log in to the account you wish to copy files from.
    2) In the Finder, navigate to the Shared folder. It is located in the Users folder.
    Copy any files or folders you wish to the Shared folder, such as items on your desktop, in your Documents folder, in your Music folder, and so forth. You may be asked to enter an administrator password when copying certain items. Note: To ensure that you copy items (as opposed to moving items), hold the Option key as you drag files to the Shared folder. Depending on item permissions, some files or folders will copy by default, some may move by default.
    3) Log out of the current account.
    4) Log in to the new account (that you are transferring files to).
    5) In the Finder, navigate to the Shared folder. It is located in the Users folder.
    Copy any files or folders you wish from the Shared folder to the desired locations, such as desktop, Documents folder, Music folder, and so forth. You may be asked to enter an administrator password when copying certain items.
    And I'll add an additional step and a warning:
    6) Having copied the files to the new account, Get Info, and change the ownership of them to your new account name. The easiest way to do this is to select each folder inside the user folder (ie Documents, Pictures etc). These should have the permission set properly to the new account owner. Click on the gear icon and select Apply to Enclosed Items
    The Warning
    It is safe to copy the contents of your Documents, Pictures, Music, Movies and Sites folders but since the problem is likely to be inside the user Library folder it isn't a good idea to copy it. You can probably safely copy your Safari bookmarks (not the entire Safari folder), Calendars, and Mail (but open the folder and delete the Bundles folder inside because it contains Mail plug-ins which might be the problem). I'd be very leery of copying any more than this since doing so might copy the problem into the new user folder. I often copy a one or two items from the Library folder at a time, restart, and then if all seems okay, copy a couple more. But I never copy the Preferences which means re-serializing a lot of programs and one or two programs might need to be reinstalled. The Applications Support folder is another one that may not be safe to copy over, but then again may be. It is one that I move into my new Library folder a couple folders at a time.
    In short, moving items into the new account via the Public folder is, itself quite easy though you do need to be sure to that the ownership gets changed to the new account. As I said, the data is easy and safe. The Library is where the problems tend to be.
    Incidentally it might seem easier to keep the old account and just moving the user Library elsewhere since that's where the problem is living. I've found that it isn't such a good idea for a number of reasons. Copying to the new account may be more time consuming but safer and in the long run better.

  • Erratic mouse and blue screens: very disappointed with Snow Leopard

    Since SL installation half of the times I get an eternal blue screen at startup and I have to do a hard power off and restart. But the worst thing is that the mouse pointer gets mad very often and makes the computer totally unusable. I have to restart to keep working, and it's not a problem of the Mighty Mouse (I have 2). Any solution for, at least, the mouse problem? I will have to waint until 10.7 release to get more reliability?

    I dont' want to sound like I'm passing you off, but have you posted in the hardware discussion area?
    http://discussions.apple.com/category.jspa?categoryID=190
    Might be better help there.

  • Help with CF9 Standard Install and Mac OS Server (Snow Leopard Server)

    Hello,
    I recently purchased a mac mini server (with snow leopard server) and will be using it to host my CF9 applications.  This install is WAY different than the install needed on a windows machine.  I tried to install it once and somehow hosed up Apache and now I can't even get it to start up (apache).  So I am having the colo company to do a full restore of the server and I took notes on the Mac Server install and below is the questions I have.
    1.) Since Snow Leopard Server comes with Apache webserver, it is what CF wants to use.  This is fine, I just need to know where these things are...
    It is asking for the Configuration Directory:  I'm guessing it is /private/etc/apache2 ? Right or Wrong???
    2.) It is asking for Directory and file name of server binary:  It currently defaults to /usr/sbin/httpd  is this right or should I point it to another directory?
    3.) It is asking for Directory and file name of server script: It currently defaults to /usr/sbin/apachectl  is this right or should I point it to another directory?
    It also wants the location where I can place the CFIDE.  Can I place this anywhere I wish or is there a preferred location to point this to?
    and finally, I have CF9 Standard, so on the mac server should I install it as a server configuration (self contained instance) or Enterprise Multiserver config.  I was reading online that its better to install as an Enterprise Multiserver setup, but I don't know if this will work for me since I'm useing the standard edition.
    Please Help ANYONE, if you have mac os experience and installing CF9 onto a mac server
    Thanks

    I have been getting this exact same problem.  CF installer is somehow writing some invalid information into the httpd.conf file.  I was able to replace the httpd.conf file with the default one, and was able to go through the webconnector process again and (sometimes randomly) it works.  I also spent about 4 hours on the line with adobe CF support and made no progress beyond what I'll post here .
    To answer your questions about file locations:
    /private/etc/apache2/ for the httpd.conf files
    /usr/sbin/ for both the apachectl and the httpd binaries
    Although I'm able to get past where you are, and it seems to work correctly, Immediately upon adding a new site via server admin it all breaks.  Coldfusion then will only work if I manually go to a cfm document.  For example:  http://example.com/ will give me the raw text from the (default index) index.cfm file.  But typing http://example.com/index.cfm works.
    I am lost here as well.  After 4 hours on the phone with adobe support I would have hoped it would be an easy fix.  I've completely nuked and reinstalled the server from scratch with the exact same results both times.
    Does anyone have the slightest clue about what may be going on here?

  • Snow Leopard Server and ISP POP email

    Hi there
    Just wondering if the Mac Mini Server with Snow Leopard Server could manage the following:
    Rather than set up my own domain for email, I am wondering if SLS can be set up to retrieve my POP email from my ISP mail server and then serve that mail using an IMAP mail box so that I can then access what were originally POp emails from anywhere.
    Is this possible?

    I'm facing this same problem... is there by any chance some sort of "guide" to using fetchmail and it's features? Or a GUI-interface for fetchmail?
    I'll be the first to admit that I need training and such about working with OsX (server), and I'm working on that part

  • Remote Desktop and Snow Leopard Server

    What is the best way to use Remote Desktop with Snow Leopard Server?
    I purchased a mac mini with snow leopard server and Remote desktop so I can easily manage my 11 computers, install and upgrade software etc. etc.
    The mac mini server will basically be nothing but a server.
    I will use as my main computer a mac pro. Do I need to install Remote Desktop on the server and on my mac pro? What is the best way to deploy the services of Remote desktop and mac os x server?

    You install Apple Remote Desktop on the machine you want to control from. In this case, install on your Mac Pro. All you have to do on the clients (controlled Macs) is enable remote management in the System Preferences under Sharing. Just make sure that all your controlled Macs are up to date on their ARD version (v3.3.2) which can be taken care of from Software Update.

  • Wiped my entire macbook drive and now snow leopard won't install over snow leopard server, HELP!

    I ordered, what I thought, was Snow Leopard a while ago because I was running Leopard and I wanted to get the app store so I could move onto Lion and then Mountain Lion. I ordered the disc over the phone and the woman sent me the Snow Leopard Server instead of just Snow Leopard, I didn't think much about it so I clean installed it and ran it on my unibody macbook for a while. I didn't see much use for the disc anymore seeing that everything was downloadable at this point, so I sold the disc on Ebay and carried on. The server edition started to slow my computer down due to all of its excess applications and what not, and I read online that Lion and Mountain Lion are also very slow on the old unibody Macbooks so I ordered a regular Snow Leopard disc, now available online, and tried to install it. My computer said Snow Leopard cannot be installed over Snow Leopard server so I went to disc utitlity and wiped my entire drive while the OS X Snow Leopard disc was running and trying to install. I went back to the install window and it still said OS X Snow leopard cannot be installed over Snow Leopard Server so I shut down my computer and tried to turn it back on and I all I got was a blinking folder with a question mark in it, what do I do????????
    P.S. All of my content is backed up on an external harddrive so I am all good with that.

    Drive Preparation
    1. Boot from your OS X Installer Disc. After the installer loads select your language and click on the Continue button.  When the menu bar appears select Disk Utility from the Utilities menu.
    2. After DU loads select your hard drive (this is the entry with the mfgr.'s ID and size) from the left side list. Note the SMART status of the drive in DU's status area.  If it does not say "Verified" then the drive is failing or has failed and will need replacing.  SMART info will not be reported  on external drives. Otherwise, click on the Partition tab in the DU main window.
    3. Under the Volume Scheme heading set the number of partitions from the drop down menu to one. Click on the Options button, set the partition scheme to GUID then click on the OK button. Set the format type to Mac OS Extended (Journaled.) Click on the Partition button and wait until the process has completed.
    4. Select the volume you just created (this is the sub-entry under the drive entry) from the left side list. Click on the Erase tab in the DU main window.
    5. Set the format type to Mac OS Extended (Journaled.) Click on the Security button, check the button for Zero Data and click on OK to return to the Erase window.
    6. Click on the Erase button. The format process can take up to several hours depending upon the drive size.
    7. After formatting has finished quit DU and return to the installer. Complete the Snow Leopard installation.

  • TLS and Snow Leopard server issues

    I have a customer with Snow Leopard server running mail services. A few clients cannot email them due to what we think is a TLS related issue. Their host has TLS enabled for the mail server and they receive the below error message when sending to my customer:
    15:27:41.044 3 SMTP-406902(domain.com) failed to establish a secure connection with [xx.xx.xx.xx]:25. Error Code=X509: signature algorithms do not match.
    The host that cannot send seems to think it's a Postfix configuration issue but I don't know where to begin. It's not a firewall issue as we've tried that with no success.
    Any ideas would be appreciated. Thanks.

    You are in the Leopard Server section, better to direct your question to the +Snow Leopard+ Section.

  • Access to DFS root via VPN not working - error 0x80070035 keeps popping up

    Dear all,
    when trying to access the DFS root via VPN from a Windows 7 non-domain member computer I always receive an error stating "Windows cannot access \\eggs.local\dfs", Error Code: 0x80070035, The Network Path was not found.
    I searched the internet as well as these forums in order to get to grips with this error message but didn't find anything to solve my problem.
    I made sure, that NetBIOS over TCP/IP is enabled, that I have access to the VPN adapter's DNS as well as WINS servers, that DNS name resolution is working properly, DNS split tunneling is enabled, Windows Firewall is disabled, and so forth. Still no luck.
    Any ideas?
    Thanks Alex
    Alexander Ollischer Diplom-Wirtschaftsinformatiker (FH) Citrix & Microsoft Certified Engineer (CCEA, CCEE, MCSA, MCSE, MCDBA, MCTS) Afontis IT+Services GmbH Baierbrunner Straße 15 81379 München Deutschland Telefon (089) 74 34 55-0 Fax (089) 74 34 55-55
    mailto:[email protected] http://www.afontis.de http://www.itganzeinfach.de Amtsgericht München, HRB 109 005 Geschäftsführer: Thomas Klimmer

    Hi,
    Though you mentioned DNS is working properly, please check if DNS forwarder is set as set correctly. 
    And incase it is caused by authentication, please try to force Kerberos to use TCP - by default it using UDP and on a slow VPN connection, UDP packets may be dropped. 
    How to force Kerberos to use TCP instead of UDP in Windows
    http://support.microsoft.com/kb/244474
    Also check NTFS and Sharing permission on top of the DFS Namespace. At least give users a Read permission. 
    If you have any feedback on our support, please send to [email protected]

  • I have an ipad and it has iCloud is unable to access account and it won't let me go to settings or use any buttons

    I have an ipad and it has iCloud is unable to access account and it won't let me go to settings or use any buttons.  How do I fix this?

    Go to Settings>General>Restrictions>Accounts (near the bottom) and set this to Allow Changes.

Maybe you are looking for

  • The Photo Stream option dissapeared from the left side-bar in iPhoto.

    Hello everyone, just to let you all know, I'm new to the world of Mac. As I was setting up Photo Stream in iPhoto, I accidently clicked on the "No Thanks" option instead of clicking on the "Turn on Photo Stream" option. Now the link has disappeared f

  • Deleting Songs That Aren't In My Library

    I recently got an ipod classic and a friend took it to put some music on it. I want to delete some of the songs but they aren't in my itues library and to sync the library would mean that I would lose all the music he downloades for me. How do I get

  • Lightroom Tech Support SUCKS!!!!!!!

    To Adobe Corporate---- I have a case that has been going on now for 5 days---I was on a chat when a Sharmji basically shut the chat down in the middle of a conversation. I have spoken to numerous 1st level Tech support people who then try to "FIX" th

  • Regarding data flow in SAP XI

    Hello Friends, In Landscape where XI connected to system(s), is there any way to find how the data flows through or how it is designed to connect other systems in SAP XI other than SLD thanks

  • Study material for consolidation

    hi experts, please help me out with the study material for doing consolidation , its prerequists , basis knowledge .. thanks in advanced.