Jump to content

I need a router that will support built-in VPN protocols under macOS Monterey

atxcyclist

I need an inexpensive gigabit router with wireless that will support IKEv2, Cisco IPSec, or L2TP over IPSec. My crappy router at work only supports OpenVPN and PPTP VPN, and I cannot natively use either one of those under macOS. I went through all the trouble to get an internet connection with a static IP, now this is keeping me from completing the next phase in my office network. 

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

I'd check with your IT department. If you need it for work, they should be able to help you out. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, atxcyclist said:

I need an inexpensive gigabit router with wireless that will support IKEv2, Cisco IPSec, or L2TP over IPSec. My crappy router at work only supports OpenVPN and PPTP VPN, and I cannot natively use either one of those under macOS. I went through all the trouble to get an internet connection with a static IP, now this is keeping me from completing the next phase in my office network. 

Um… I’m confused. Your router doesn’t need any VPN capabilities if your hosting the VPN on a client machine. You just need to open ports on the router. 
 

If the router is what’s handling the VPN, your client machines will be oblivious to the VPN even existing. 
 

Also, why did you need a static IP? Could you not just either use Cloudflare or another dynamic DNS provider (they are free, and forward your public IP to a domain name, so as it dynamically changed, your domain name is auto updated to match). 

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, DrMacintosh said:

I'd check with your IT department. If you need it for work, they should be able to help you out. 

I am the IT department, haha. This is a little two-person design firm, so it falls on me as the more tech-savvy one.

 

I've been working toward remote access for a while, I didn't realize the protocols my router used were all deprecated from modern OS's.

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, LIGISTX said:

Um… I’m confused. Your router doesn’t need any VPN capabilities if your hosting the VPN on a client machine. You just need to open ports on the router. 
 

If the router is what’s handling the VPN, your client machines will be oblivious to the VPN even existing. 
 

Also, why did you need a static IP? Could you not just either use Cloudflare or another dynamic DNS provider (they are free, and forward your public IP to a domain name, so as it dynamically changed, your domain name is auto updated to match). 

I need to host it on the router, we don't have specialized hardware for this task. This is a very small setup with a basic file server on our local office network, I just need remote access. The static IP was more or less a benefit of upgrading to a symmetrical fiber connection, but I would like to use it for simplicity's sake.

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, atxcyclist said:

I need to host it on the router, we don't have specialized hardware for this task. This is a very small setup with a basic file server on our local office network, I just need remote access. The static IP was more or less a benefit of upgrading to a symmetrical fiber connection, but I would like to use it for simplicity's sake.

I don’t understand then. If the router is what’s negotiating the VPN… oh, your not trying to set up site to site VPN between multiple routers, your talking about providing credentials for remote access to VPN back into the office from laptops.

 

Can you just set up a r-pi running WireGuard? Or spin up a VM/container for WireGuard within the network somewhere. Or… few hundreds bucks and set up a pfsense router/firewall and use WireGuard on that would be my recommendation. 

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, LIGISTX said:

I don’t understand then. If the router is what’s negotiating the VPN… oh, your not trying to set up site to site VPN between multiple routers, your talking about providing credentials for remote access to VPN back into the office from laptops.

 

Can you just set up a r-pi running WireGuard? Or spin up a VM/container for WireGuard within the network somewhere. Or… few hundreds bucks and set up a pfsense router/firewall and use WireGuard on that would be my recommendation. 

Yeah, this is just remote file access to our server.

 

Most of that stuff is way beyond my level of expertise. I could fumble through it, but I'd need a much better server to run a virtual machine for PFsense, and host our files, and I have to imagine that's much more expensive endeavor than a router that will do this task. 

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

Why can't you just install the OpenVPN client on MacOS?  What features do you need to run natively that you can't do thru the client?

CPU: Ryzen 5 5600X  | Motherboard: ASROCK B450 pro4 | RAM: 2x16GB  | GPU: MSI NVIDIA RTX 2060 | Cooler: Noctua NH-U9S | SSD: Samsung 980 Evo 1T 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, LapsedMemory said:

Why can't you just install the OpenVPN client on MacOS?  What features do you need to run natively that you can't do thru the client?

I don't want to manage access accounts on a 3rd party system. I also ran OpenVPN previously on another setup, and I had random authentication/connection problems with it. I also had problems with the 3rd party software funneling internet traffic through the VPN as well, and I'm not messing with that again I just want file access.

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, atxcyclist said:

I don't want to manage access accounts on a 3rd party system. I also ran OpenVPN previously on another setup, and I had random authentication/connection problems with it. I also had problems with the 3rd party software funneling internet traffic through the VPN as well, and I'm not messing with that again I just want file access.

In that case, UniFi's hardware should do it.  Personally I'd go with a Dream Machine Pro and a Unifi access point,

 

but you could also do it with the Dream Router....

https://www.wundertech.net/how-to-set-up-a-vpn-server-on-unifi/

CPU: Ryzen 5 5600X  | Motherboard: ASROCK B450 pro4 | RAM: 2x16GB  | GPU: MSI NVIDIA RTX 2060 | Cooler: Noctua NH-U9S | SSD: Samsung 980 Evo 1T 

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, atxcyclist said:

Yeah, this is just remote file access to our server.

 

Most of that stuff is way beyond my level of expertise. I could fumble through it, but I'd need a much better server to run a virtual machine for PFsense, and host our files, and I have to imagine that's much more expensive endeavor than a router that will do this task. 

A pfsense box is actually pretty affordable. But…..

 

Can you run VM’s on whatever server you have? Just spin up a very light weight client and instal WireGuard. 

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, LIGISTX said:

A pfsense box is actually pretty affordable. But…..

 

Can you run VM’s on whatever server you have? Just spin up a very light weight client and instal WireGuard. 

It's an old AMD Phenom X6 machine, I think it supports virtual machines but I couldn't take our file server offline long enough to test that.

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, atxcyclist said:

It's an old AMD Phenom X6 machine, I think it supports virtual machines but I couldn't take our file server offline long enough to test that.

What OS is running your file server on that Phenom? But, yea. That is pretty old.

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, LIGISTX said:

What OS is running your file server on that Phenom? But, yea. That is pretty old.

Windows 7, it’s what I’m familiar with and had a key.

 

 

My Current Setup:

AMD Ryzen 5900X

Kingston HyperX Fury 3200mhz 2x16GB

MSI B450 Gaming Plus

Cooler Master Hyper 212 Evo

EVGA RTX 3060 Ti XC

Samsung 970 EVO Plus 2TB

WD 5400RPM 2TB

EVGA G3 750W

Corsair Carbide 300R

Arctic Fans 140mm x4 120mm x 1

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, atxcyclist said:

Windows 7, it’s what I’m familiar with and had a key.

 

 

You can run WireGuard on that… although I’d really recommend the free upgrade to win 10, if for no other reason than security patches. 
 

But I understand it’s difficult to take down your file system for an OS update. 

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×