Why does the new Dual-Band AirPort Extreme Base Station act as a proxy?

The previous thread
http://discussions.apple.com/thread.jspa?threadID=1531675
has been archived and nothing came of it, but after testing, I'm certain that their findings are true.
The Dual-Band AirPort Extreme Base Station (AEBS) with firmware 7.4.1 acts as a proxy for TCP ports 21, 554, and 7070 when NAT is turned on. This can be verified by using Nmap on any external server known to NOT have the ports open and having Nmap return that the ports are open. You can telnet to these ports to verify that they're "open," even though they are not on the server.
This functionality appears to be undocumented and as far as I can tell, the only way to turn it off is to put the AEBS into bridge mode and having some other device do NAT further upstream.
As a computer professional, this functionality extremely undesirable, particularly since it is not documented and doesn't have an "off switch." I wasted a bunch of time with one of my network engineers because of this, thinking that some network router was spoofing our server. I also wasted a bunch of my time trying to detect whatever "stealthy rootkit" had opened a FTP server and some other botnet related ports on our server, when in reality, it was simply my AEBS tricking me.
Disabling NAT-PMP ("Enable NAT port mapping protocol") does not affect this.
Is it too much to ask to have a checkbox in the "Advanced" section of the AirPort Utility to turn this feature off?

Welcome to the discussions forum Michael Bennett2.
Thanks for investigating this odd behavior.
If you want your work to be noticed by those who can effect change, you'll have to tell Apple via their feedback link. It won't do any good to post it here.
http://www.apple.com/feedback/

Similar Messages

  • No more WDS networking in the new dual band airport extreme?

    we had a network of 3 airport extremes in our small 2 story design studio, we bought a new dual band to see if it would help with our DSL problem [it did], but there is no more WDS networking option available. this unit replaced our MAIN WDS unit. so now we are left with 'extending the network' option. it seems to be working, but what is the reason behind no more WDS?

    WDS gives you more control over your network. You can set-up certain base stations as relays and others as remotes. Using the "Extend a network" option just tells the base stations to try and find other base stations. It is much easier for a novice to set-up, and I think this is probably why Apple has highlighted this feature as opposed to WDS (where you have to specify MAC addresses for all base stations and remotes).
    WDS is nice if you have a mixed network with older b/g base stations since they don't have the option to "Extend a network" or "Allow this network to be extended".

  • Wireless HP Printer on Dual Band Airport Extreme Base Station

    I'm looking to upgrade my router to the dual band AEBS. I'll end up with some n machines and some g machines, including a wireless HP printer. Will my n-enabled machines be able to print to the g wireless printer on the g network?
    Thanks,
    JD

    +Will my n-enabled machines be able to print to the g wireless printer on the g network?+
    Yes. All devices will receive an IP address from the AirPort Extreme, so they will all be on the same network and will be able to communicate with each other. This is true even if you have a wired only computer connected to the AirPort Extreme. It will be able to print to the printer.
    But, if you enable the Guest network features, computers on this network will not be able to "see" other computers or connect to any devices on the main network.

  • V. Slow transfer speeds with new dual band Airport Extreme

    I have a new Airport Extreme (late 2009, dual band, full 'N' spec) which I am using to replace an older Airport Extreme (early 2008, 5Ghz, 'draft' N).
    I have a USB disk attached and was interested in benchmarking the transfer speed of the new Extreme, compared to the previous version. The results are puzzling / alarming.
    Shown below are transfer speeds (file copied to the attached USB drive) under different connection standards (2.4Ghz / 5Ghz & a/b/g/n)
    'Old' Airport Extreme
    5Ghz - 'draft' N : ~5-7 Mb/sec
    'New' Airport Extreme
    2.4Ghz - b/g : ~3-5 Mb/sec
    5.0Ghz - a : ~3-7 Mb/sec
    5.0Ghz - N : ~200 Kb/sec
    Hence transfer speeds appear to collapse when I try to make use of the 'N' spec with the latest Extreme. I have tried altering items such as - wide channels (on / off), interference robustness (on / off), 5Ghz channel (manual, instead of auto), with no upside.
    I seem to be at the point of concluding that either
    1. I have a 'broken' Airport Extreme
    2. The WiFi card on my early 2008 iMac (which implements I guess the 'draft' N standard) is 'incompatible' with new the Airport Extreme under a 'N' connection.
    Any thoughts ?

    Since all devices in my wireless network are capable of latest 802.11n protocol, I really do not need older and slower 802.11a/b/g protocols. To achieve above 200 Mbit/sec, 5GHz band with wide channel option turned on is really necessary. Thus I really wish I can turn off the 2.4GHz radio band (seems Apple has set this band as default) of my new dual band Airport Extreme to avoid unwanted bandwidth degradation. Unfortunately this is not possible with radio mode setting in Airport Utility.
    The best I can do to force connection with 5GHz radio band (with quite consistent result) is as follows:
    On Airport Extreme through [Airport Utility>Wireless] :
    Radio Mode: 802.11n only (5Ghz) - 802.11b/g/n
    More Options>Wireless Network Option>Transmit Power: 100%
    More Options>Wireless Network Option>Use Wide Channels: checked
    More Options>Wireless Network Option>5 GHz Network Name:
    checked and same network name with extra suffix "(5 GHz)"
    On 27" iMac through [System Preferences>Network>AirPort>Advanced>AirPort]:
    Preferred Networks:
    Create only one profile in Preferred Networks for the above network name with suffix "(5GHz)"
    Uncheck the option [Remember networks this computer has joined] to ensure there is only one profile under Preferred Networks .
    Once all above settings are done, restart Airport Extreme in Airport Utility. Your computer should connect wirelessly to the base station through 5GHz band after booting most of the time. Even when it is not occasionally, simply go to the Airport icon in main menu bar and click on the network name with suffix "(5GHz)" in dropped-down list to connect manually. With all these settings, I have achieved 300 Mbit/sec bandwidth on my iMac most of the time for fast Time Machine backup.
    How I wish feature for better radio mode control by end user will be implemented in next update of Airport Utility. Apple should trust end user's brain better than artificial intelligence (or ignorance ?) in wireless network implementation. Wireless traffic between the two radio bands and among various wireless devices should be segregated specifically in Airport Utility by end users whenever dual band Airport base stations are in use.

  • How to disable the wireless section of Airport Extreme Base Station?

    Is it possible to disable the wireless section of Airport Extreme Base Station?
    It is because I do not want to have any high frequency radio signal which may be dangerous for small baby (no such proof for the moment, however).
    Anyone using the new Airport Extreme Base Station please check and help.
    Thanks!!

    I think you are a little too concerned. Just for the sake of how to, here it is.
    go to manual set up, airport, wireless, wireless mode, and then choose off.
    good luck.

  • Which Mac's have airport that can work on the new dual band Airport?

    I have a MB470 Macbook Pro (Late 2008) and want to know if it can transmit on the 5GHz band if I were to buy the new AirPort Extreme Base Station dual band?
    I checked the manual and spec but no mention.
    Also from reading on this subject I have seen most articles saying only the original 802.11a band wifi products used 5GHZ bands and b/g/n use 2.4GHZ so what has happened there? Have manufacturers started using the 5GHZ again only recently and can products have their firmware upgraded to make them work on 5GHZ?

    Also from reading on this subject I have seen most articles saying only the original 802.11a band wifi products used 5GHZ bands and b/g/n use 2.4GHZ so what has happened there?
    The 802.11a standard works on the 5 GHz radio band; for 802.11b/g, it's the 2.4 GHz band, but for 802.11n it can be both bands.
    Have manufacturers started using the 5GHZ again only recently and can products have their firmware upgraded to make them work on 5GHZ?
    Use of the 5 GHz band for Wi-Fi is restricted in some countries due to conflicts with either military or governmental regulations. Manufacturers typically comply with these regulations in order to sell their products in such countries "legally."
    Firmware alone, in most cases, will not solve the problem. The device would have to have the proper antennae & transceiver to meet the appropriate standard in order to provide the wireless network.

  • Problem consistently printing via new (summer 2011) AIRPORT EXTREME BASE STATION and Brother wireless printer (model HL5370DW). What am I doing wrong?

    Thanks in advance for any help you folks can offer. I'm a newb here and will try to offer as much detail as I can about the dilemma at hand.
    Scenario: Home network has been recently set up for wireless internet access via NEW Airport Extreme Base Station (purchased September 2011). Units accessing the network include: 2011 Macbook Pro, 2011 Macbook Air, 2007 Macbook, 2009 Macbook Pro, 2 iPhone 3GSs, and a 1st-gen iPad (and a partridge in a pear tree AEBS is configured to run WPA2 encrypted network, as well as a WPA2 guest network. I am attempting to yoke a BROTHER HL5370DW wireless B or G/ ethernet / usb-capable printer to the main network such that any and all units can print wirelessly or its equivalent (i.e., via printer hooked to AEBS through USB hub)
    Problem: Despite configuring the Brother printer to recognize the main WPA2 network I created, I am unable to get wireless printing to work. My workaround was to physically connect Brother printer to AEBS via USB, specifically using a Belkin USB hub (after all, I wanted access to usb drives, as well as the printer). This workaround works ONLY SOME OF THE TIME. Generally, after a fresh boot of any computer or after a restart of the AEBS, any given computer will be able to print (i.e., any computer wirelessly connected to the main WPA2 network recognizes the printer). HOWEVER, at random times, printer access is gone (as is access to USB drives connected to AEBS's usb hub). Wireless networks are still up and running when that happens. IS THERE A WAY TO GET THE USB HUB's devices (i.e., printer and usb drives) to ALWAYS REMAIN AVAILABLE AS LONG AS THEY STAY CONNECTED TO THE AEBS? In other words, what accounts for the intermittent loss of the usb peripherals?
    Sometimes, I just shut the airport off on whatever computer is having this problem, and the problem goes away. Sometimes, the problem is present across all computers in the house, sometimes only a few are affected. I can ALWAYS see the AEBS in the Airport Utility if the AEBS is connected to the particular computer via ETHERNET CABLE.
    My theories:
    - true wireless printing (i.e., without usb hub workaround) doesn't work because the N network somehow isn't backwards compatible with the Brother printer, which, i believe, is B/G. Although...isn't Wireless N networking supposed to work with BG devices? I did find a thread (https://discussions.apple.com/thread/2570774?start=0&tstart=0 ) that explains some of the particulars of WPA2 encryption and Wireless B/G issues, but it was beyond my level of comprehension (I'm a psychologist, but not an Apple Genius
    - The usb workaround is only intermittently viable because of some flaw in the Airport or Airport Utility that causes dropouts to happen when a Macbook Pro or Air's lid gets closed or one gets opened after having been at a different network (e.g., at my office).
    QUESTIONS:
    - Should I try to use my old router (7 year old Linksys WRT54G) as an access point and connect the Brother printer to that G-router? How do I do that?
    - I wouldn't mind just relying on the usb hub method if I could just insure more consistency (i.e., no random dropouts of peripherals). How could I do this?
    Rule out:
    - wireless printing works on my printer - it was being recognized back before the AEBS. I had the Linksys router running a WEP network and had the wireless printer talking with no cables to the router and the computers. (I just don't want to revert to using WEP encryption given its lack of security and my trying to protect HiPAA related health information on behalf of patients)
    Any help will be greatly appreciated.
    Thanks in advance!

    13 ASCII characters = 104 (aka 128)-bit WEP
    encryption
    If turning off WEP works, then you just need to
    provide the cameras with the "Equivalent Network Password".
    One of the problems with WEP is that the actual
    standard relies on a 10 character HEX key for 40bit
    WEP and a 26 character HEX key for 128bit WEP.
    In order to make things easier, vendors use certain
    algorithms to convert simple alphanumeric passwords
    (or passphrases) into HEX keys, thus enabling the use
    of simple easy to remember WEP password rather than
    lengthy HEX keys. The problem is that different
    vendors use different algorithms to generate the HEX
    key and therefore a ASCII password on an AEBS will be
    hashed differently on a non-Apple client and vice
    versa.
    You may find the following article helpful:
    - Apple article, especially the part about
    "Third-party client to Airport".
    Brilliant idea about trying the system with No encryption on... that DID solve the problem... almost.. once I turned off the encryption option, and restarted the Airport, I got a dialog box showing that the "Base station needs attention" but it didn't indicate WHAT kind of "assistance" it needed. Nonetheless, I closed out of the Airport program only to find that the indicator light, which had been Green, was now, flashing Yellow and I could not connect anything, including my computer. I opened the Airport program again and found the ONLY way I could get the Green light on was to select some sort of encryption option... then the light would go Green again but my cameras would not hook up again, and when I went back in and ONLY changed the option to NO encryption, I got the yellow flashing light and the "this base unit needs attention" warning...
    I think your suggestions are almost on the mark... is there any way of reconciling the WEP coding between the cameras and the Airport??? Or turning off the encryption option and STILL have Airport work?
    Thanks again for your help and suggestions... I really appreciate it.
    geoff

  • Howto disable the firewall in AEBS Airport Extreme Base Station

    Is there any way to do that?
    Motivation: I don't want to reroute ports to a DHCP address which changes constantly. Plus: Editing the port reroute list is a pain!
    I have no problems with my Asus WL500gP but this thing just doesn't get printing right while all the other funktions work flawlessly.
    AEBS plus: Canon ip3000 works perfect over WLAN
    AEBS minus: All services relying on ports being redirected are blocked
    I have a firewall in my mac which I can switch on and allow services to whatever I want, for the Airport Extreme Base Station, this simply does not work. If I donwload a new Ubuntu torrent with the Asus it's yipiiee, with the AEBS it's 0KB/s. Great.

    The only way to disable the "firewall" is to configure the AEBS to act as a bridge. In that mode it is not providing local IP addresses for local machines.
    Motivation: I don't want to reroute ports to a DHCP address which changes constantly. Plus: Editing the port reroute list is a pain!
    You can configure the AEBS to use DHCP. You can give one of your computers a static IP address outside the range used by the AEBS's DHCP server. Then you can configure the AEBS to recognize that computer as default host (thing DMZ) or you can forward selected ports only to that computer. Once configured you won't need to change anything since that computer is at a static IP address.

  • Recovering Old Datas on New Drive + Setting Airport Extreme Base Station old and new ones

    Hello All,
    Situation:
    -iMac 24" Alu/2008/2.8 Ghz Intel Core 2 Duo/ 2Go DDR2 SDRAM
    -2 Airport Extreme Base Stations mushroom type,
    -1 Airport Extreme Capsule Model: A1143
    The original 320 Go Hard Drive of my iMac crashed few months ago. A "technician" installed a new Hard Drive 235 Go while trying to recover all datas from old one. Failed.
    No back up. The old disc needs to be unlocked in a dustless atmosphere. Quite expensive at the moment.
    I decided to install OS X from sratch with the original Install Disc delivered with my iMac.
    OS X is 10.5
    Once on line I updated all pre-installed softwares. Among which Aiport Utility 5.6.1 today.
    Problem:
    I would like to get bigger hard drive disc, 1To for example. Does this still exist for this iMac 2008 Alu ?
    How can I do to get my iMac again to OS X 10.9 ?. Does this mean I need to buy all intermediate levels again ?
    How do I get my softwares (the ones on the original Disc: Pack office, Pages, Numbers, etc ...) back on track again, since my iMac is now more like down to factory level ?
    Extending my internet provider from the WiFi router via my 3 Airport Extreme Base Stations: 2 mushroom type that need OS X + Airport Utility softwares at a certain level, while the Capsule might need another level. Right now I tried to set up the 3 of them with this Aiport Utility and though they all recognize the provider network, I can never conclude to extend it with the Base Stations: it drops the case. (WDS trouble which I don't even know what it is, or the Base Station simply desapears from Airport Utility scan, ...)
    Thank you all for you attention.
    Your comments are welcome especially if you have any knowledge on these various subject.
    Can't wait to read your piece of advice.
    Lionnel From Paris (France).

    me too... i connected my hard drive with all my music but i cannot see any of the music that used to be in my itunes... i checked and its there (when I connect the HD directly to my computer) but not when is plugged into the Airport Extreme... Please help!

  • New Mac and Airport Extreme Base Station User - Setup question

    Good Morning,
    I just received my new MacBook Pro yesterday along with the Airport Extreme Base Station. I was tying to setup the airport extreme but have had no luck. I want to make sure I'm connecting things correctly - make sure I'm not doing something stupid.
    I have a cable modem and I previously had a Netgear router. The connection from the cable modem that had previously been connected to my Netgear router - I disconnected it and connected it to the Airport extreme base station instead. And then I plugged it in. Is that all the connecting that I need to do? I get the flashing amber light.
    Now I did read a few other threads and it sounds like I may need to install the Airport Utility that came with the base station. So I'll try that when I get home tonight. But I would appreciate any other suggestions - especially whether or not I've connected the airport extreme correctly to my cable modem.
    Thanks, Susan
    MacBook Pro   Mac OS X (10.4)  

    I want to make sure I'm connecting things correctly
    The network configuration should look something like the following:
    Cable modem > (Ethernet cable) > [WAN port] AEBSn > (wireless) > MacBook Pro
    I have a cable modem and I previously had a Netgear router. The connection from the cable modem that had previously been connected to my Netgear router - I disconnected it and connected it to the Airport extreme base station instead. And then I plugged it in. Is that all the connecting that I need to do? I get the flashing amber light.
    Since you changed your network configuration, you should perform a complete power recycle of your network components to allow enough time for them to "synchronize."
    Modem/Router Power ReCycling
    - Power-off the Cable modem, AirPort Extreme Base Station (AEBSn), & computer(s). (Wait at least 30 minutes. If possible, leave the modem off overnight.)
    - Power-on the Cable modem; Wait at least 30 minutes.
    - Power-on the AEBSn; Wait at least 5 minutes.
    - Power-on the computer(s)
    Now I did read a few other threads and it sounds like I may need to install the Airport Utility that came with the base station.
    Yes, you will need this utility to perform the setup and follow-on administration of the AEBSn.

  • Ip8500 does not print with XP & Airport Extreme Base station (OK with Macs)

    My canon ip8500 is connected to an Airport Extreme Base station. I can print from either Mac (a G4 and a new iMac 24") but no luck with either XP laptops (accessing the internet is no problem). I've installed both PC's with Bonjour but after a minute or so I get a failed to print message. Any suggestions?

    They are simply obsolete. You cannot update their firmware to be compatible with new products. Buy something to replace them such as a couple of new Airport Expresses.

  • Will Airport Express 802.11g network with a new Dual Band Airport Extreme?

    Bob Timmons I need your help. I have a older Airport Express, can I use it to extend my wireless network to the far reaches of my house by linking it to my new Airport Extreme 802.11n?
    There must be an article on this somewhere.
    Thanks!

    Welcome back!
    If by "older" AirPort Express, you mean it is a "b/g" version, you'll have to use the WDS setup options on both the new AirPort Extreme"n" and the AirPort Express.
    Unfortunately, two negative things will occur when you setup WDS:
    1) Because WDS is a "g" technology thing, the entire wireless network will drop down to "g" wireless levels. So, you lose any advantages of "n" speeds with your new router.
    2) The bandwidth on the entire wireless network will be cut 50%.
    Bottom line, you will have a "g" wireless network operating at half of it's capability. That's a tremendous loss of performance for a bit more wireless coverage, but you may disagree.
    WDS is difficult for most users to set up because it is very easy to make a mistake. Look over this post to get an idea of what is involved with this. There is also a link to Apple's instructions in this post, but the step by step by expert user Tesserax is easier to follow.
    http://discussions.apple.com/thread.jspa?threadID=2287950&tstart=0
    I do not recommend WDS, but it's your call.

  • I have an old airport that still works, can you use it the same way that one uses an airport express to extend the range of an airport extreme base station?

    It would save me a few bucks if I could use an old airport that I have to extend the range of a new airport extreme.  My concept would simply be to use the old Airport the same way I would use a newer Airport Express as a slave repeater.  Is this doable?

    Both the new AirPort Extreme and older AirPort Express will have to be configured using Apple's WDS settings to provide more wireless coverage. 
    Here are the downsides:
    WDS operates only at "g" wireless speeds, so you will lose all of the faster "n" wireless capability of the new AirPort Extreme
    WDS cuts the bandwidth on the entire network in half, so you will have a "g" wireless network running at half speed.
    WDS is difficult for most users to configure because it is easy to make a mistake and hard to recover without starting all over again
    Bottom line......Saving a few bucks will be very costly in terms of performance on your network.

  • How do I find the password to my airport extreme base station?

    I have a flashing yellow leght on the base station and when I try to find out which one I have it asks for a password. I don't remember assigning one but it won't let me in.

    Launch Keychain Access located in  HD > Applications > Utilities
    Select passwords on the left.
    Type   base station    in the search field top right corner of the window.
    Now double click that keychain then select the Attributes tab.
    Select the box next to:  Show Password
    You may be prompted for your admin password before proceeding.
    Now open AirPort Utility located in the same Utilities folder. Select the base stattion on the left then click Manual Setup.
    Select AirPort from the menu at the top of that window then select the Base Station tab.
    Type in the correct password then select:  Remember this password in my keychain then click Update.

  • Streaming DVD movies over Dual Band Airport Extreme Airdisk

    Hello,
    This is my first post in the discussion forums. I have been a long time reading of the discussion forums. I recently bought a late 2009 dual band Airport Extreme base station. I have been trying to stream DVD movies (TS_VIDEO) using the Airdisk feature. What I did, as an experiment, was to hook up the dual band Airport Extreme to my 2009 Mac-Mini using an ethernet cable from the base station to the Mac-Mini. I enabled file sharing on the Airport extreme base station. I hooked an external hard drive to the base station via a USB port on the base station. I mounted the Airdisk on the Mac-MIni. When I play the ripped DVD movies (TS_VIDEO) from the Airdisk I get a lot of stuttering using Front-Row. According to the Apple customer service reps, this is normal behavior. Can anybody comment on if this is normal behavior.

    An uncompressed DVD should have a maximum data rate of around 6 or 7 Mbps and so be well within the nominal 300 Mbps of an 802.11n network - even allowing for the slower actual speeds attained due to networking overheads and weak signals. However, given that you have the latest Airport Extreme it sounds like you may be suffering from the common fault many are reporting in these forums, in which disk transfer rates are very, very slow over the 5GHz 802.11n connection. Look at some of the other threads here. It is clearly a fault in the current design (not a fault with your particular unit) and something that Apple are apparently aware of. Most are hoping it will be resolved in an updated firmware at some point in the future.
    Edit: I just re-read your post and notice that you said you used a physical connection between the Airport and the Mac Mini. Thus no wireless involved. Nevertheless, others have reported poor data rates with disks connected to the unit, and so this may still be the issue. Check out some of the other threads here.
    Message was edited by: Paul Howland2

Maybe you are looking for

  • My Review for MSI Big Bang Xpower & Overclocked

    This will be the very 1st X58 big bang series of MSI and the 1st X58 MSI motherboard to have USB 3.0 and SATA 3 connections. Targets the enthusiast, hardcore gamers as well as overclockers. This board is already equipped with OC Genie buttons which w

  • Want to restrict buttons in PV8i screen in Training & Event Management

    Dear All, My requirement is to restrict available buttons in PV8I screen except the 'Appraisal' function. The standard buttons given in PV8I screen are like Rebbok event, cancel etc. My client requires that an user can only use this screen to maintai

  • Difference in actual figure and figure calculated by report

    I am using Report 6i. I have created tabular report of provident fund through salary annualy as follows empno, op_bal, apr, may, jun, jul, aug, sep, oct, nov, dec, jan, feb, mar, cl_bal column total apr_tot,may_tot,jun_tot,xxx,xxx,xxx,xxx,xxx,xxx,xxx

  • Using HTML tags in Flash

    Hello I have some XML that's loaded into Flash by ActionScript and in the XML, I have some text under a node as a parameter called "content" but the problem is that I need to have some HTML code in there (Anchor Tag for links) But it isn't rendered b

  • Changes to an order through Call Transaction not showing up in change log

    I m having a problem such that if I update an order programmatically with Call Transaction u2018VA02u2019, the order does get updated updated but I donu2019t see the changes in the change log. I m only updating the order quantities. However if I upda