{"id":10145,"date":"2016-10-24T18:01:43","date_gmt":"2016-10-25T01:01:43","guid":{"rendered":"http:\/\/www.podfeet.com\/blog\/?page_id=10145"},"modified":"2016-10-30T13:52:39","modified_gmt":"2016-10-30T20:52:39","slug":"how-to-turn-off-nat-pmp-on-airport-routers","status":"publish","type":"page","link":"https:\/\/www.podfeet.com\/blog\/tutorials-5\/how-to-turn-off-nat-pmp-on-airport-routers\/","title":{"rendered":"How to Turn Off NAT-PMP on Airport Routers from macOS"},"content":{"rendered":"<div class=\"clarify-article-content\">\n<div class=\"clarify-article-description\">\n<p>Airport routers from Apple have a service turned on by default called NAT-PMP (Network Address Translation Port Mapping Protocol). &nbsp;This service allows applications and\/or devices inside your network to automatically open ports in your router to make them accessible from the Internet. &nbsp;While this feature does make it easier to set up Internet of Things devices (doorbells, webcams, light bulbs), it makes your network more vulnerable to attack. &nbsp;<\/p>\n<p>The recent (October 2016) Denial of Service attacks on the Domain Name System that pretty much broke the internet for a half a day were due to devices inside peoples&#8217; networks being commandeered to act on behalf of the bad actors. &nbsp;In other words, having NAT-PMP enabled on an Airport router (or UPnP on other manufacturer&#8217;s routers) allowed these Internet of Things devices to be recruited into a botnet.<\/p>\n<p>If you want to learn more, please see this Wikipedia article: <a href=\"https:\/\/en.wikipedia.org\/wiki\/NAT_Port_Mapping_Protocol\">https:\/\/en.wikipedia.org\/wiki\/NAT_Port_Mapping_Protocol<\/a><\/p>\n<p>These instructions show you how to turn NAT-PMP off in an Airport Router using the Airport Utility which is inside your Applications\/Utilities folder. &nbsp;If you have a Netgear Nighthawk Router, please see this tutorial: <a href=\"https:\/\/www.podfeet.com\/blog\/how-to-turn-off-upnp-on-netgear-nighthawk-routers\/\">https:\/\/www.podfeet.com\/blog\/how-to-turn-off-upnp-on-netgear-nighthawk-routers\/<\/a><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p><!--more--><\/p>\n<div class=\"clarify-article-content\">\n<div class=\"clarify-steps-container\">\n<div id=\"clarify-step-1\" class=\"clarify-step-container\">\n<h3 class=\"clarify-step-title\">Open AirPort Utility<\/h3>\n<div class=\"clarify-step-instructions\">\n<p>Click on the image or name of the router (mine is called Tall Dart) which will enable a menu.<\/p>\n<\/div>\n<div class=\"clarify-step-image-wrapper\">\n<div class=\"clarify-step-image-container\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2016\/10\/open-airport-utility.png\" width=\"414\" height=\"320\" class=\"clarify-step-image\" alt=\"\" \/><\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"clarify-clear\"><\/div>\n<div id=\"clarify-step-2\" class=\"clarify-step-container\">\n<h3 class=\"clarify-step-title\">Click on Edit<\/h3>\n<div class=\"clarify-step-image-wrapper\">\n<div class=\"clarify-step-image-container\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2016\/10\/click-on-edit.png\" width=\"414\" height=\"468\" class=\"clarify-step-image\" alt=\"\" \/><\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"clarify-clear\"><\/div>\n<div id=\"clarify-step-3\" class=\"clarify-step-container\">\n<h3 class=\"clarify-step-title\">Select the Network Tab<\/h3>\n<div class=\"clarify-step-image-wrapper\">\n<div class=\"clarify-step-image-container\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2016\/10\/select-the-network-tab.png\" width=\"414\" height=\"415\" class=\"clarify-step-image\" alt=\"\" \/><\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"clarify-clear\"><\/div>\n<div id=\"clarify-step-4\" class=\"clarify-step-container\">\n<h3 class=\"clarify-step-title\">Select Network Options<\/h3>\n<div class=\"clarify-step-image-wrapper\">\n<div class=\"clarify-step-image-container\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2016\/10\/select-network-options.png\" width=\"414\" height=\"415\" class=\"clarify-step-image\" alt=\"\" \/><\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"clarify-clear\"><\/div>\n<div id=\"clarify-step-5\" class=\"clarify-step-container\">\n<h3 class=\"clarify-step-title\">Disable NAT Port Mapping Protocol <\/h3>\n<div class=\"clarify-step-instructions\">\n<ol>\n<li>Uncheck the box next to &quot;Enable NAT Port Mapping Protocol&quot;<\/li>\n<li>Click Save <\/li>\n<\/ol>\n<p>Your Airport router will tell you that it will have to restart. &nbsp;In a few minutes you should be back up and running. &nbsp;<\/p>\n<p>If any of your internal network devices stop working, contact the manufacturer. &nbsp;They should be able to tell you specific ports to open and how to do that. If they tell you that you must have NAT-PMP or UPnP enabled, you&#8217;ll have to make a decision for yourself on whether to re-enable it or get rid of a device that makes your network less secure.<\/p>\n<\/div>\n<div class=\"clarify-step-image-wrapper\">\n<div class=\"clarify-step-image-container\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2016\/10\/disable-nat-port-mapping-protocol-.png\" width=\"414\" height=\"251\" class=\"clarify-step-image\" alt=\"\" \/><\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"clarify-clear\"><\/div>\n<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Airport routers from Apple have a service turned on by default called NAT-PMP (Network Address Translation Port Mapping Protocol). &nbsp;This service allows applications and\/or devices inside your network to automatically open ports in your router to make them accessible from the Internet. &nbsp;While this feature does make it easier to set up Internet of Things [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":4374,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[],"tags":[151],"class_list":["post-10145","page","type-page","status-publish","hentry","tag-networking-tutorials","post"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/10145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/comments?post=10145"}],"version-history":[{"count":3,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/10145\/revisions"}],"predecessor-version":[{"id":10227,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/10145\/revisions\/10227"}],"up":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/pages\/4374"}],"wp:attachment":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media?parent=10145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/categories?post=10145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/tags?post=10145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}