AFP548

Isolate VPN listener to a single interface?

Hi, folks... wondering if anyone has seen this and knows what to edit.

Until last night, I had been successfully running Tiger's VPN service on an Xserve with clients connecting from all points around the country and accessing all of our internal network services.

Last night, I activated the second Ethernet card. Since that moment, VPN connections fail to connect. The server and the client negotiate, but the server quickly uses up its pool of allocated IP addresses on that one connection and eventually it times out. The connection never gets to an authentication stage.

I tried a large number of techniques to fix this, but found only one that makes a difference: If I disable en0, VPN comes back to life on en1. (We want VPN connections on the IP assigned to en1, but I've reversed this and it doesn't matter.) Once I reenable en0, we're dead in the water.

We had the same issue with DHCP, but I modified the bootps.plist so that bootpd only listens on en0. I think this is the right solution for this issue but cannot find where to specify a port (or IP address) to listen on.

Anyone know where Apple is hiding this thing? TIA.
Exit mobile version