Skip to main content
Question

OSX Builtin IPSec Cisco VPN 10.11.4

  • March 22, 2016
  • 3 replies
  • 16 views

Forum|alt.badge.img+3

Hey all,

We have noticed that 10.10.4 seems to break newly added Cisco IPSec VPN configurations. We tried on different systems, different networks and different firewalls. Manual configurations as well as profiles don't work, only existing configurations continue to work.

My colleague @peterloobuyck already posted a bug report with Apple.

Has anyone else noticed this behaviour? We'll post any progress in the bug report here.

3 replies

peterlbk
Forum|alt.badge.img+11
  • Jamf Heroes
  • March 22, 2016

Cheers, @danielslijper !

Bug report number 25296377 if anyone cares to check..

Cheers!


Forum|alt.badge.img+15
  • Contributor
  • May 5, 2016

@danielslijper and @peterloobuyck ,

We just ran into this and we found that 10.11.4 updated the VPN client and it requires at 2048 or higher bit modulus. We changed our firewall to use a higher DH group number and now it works!

Good explanation here: http://www.cameronbrister.com/mac-os-x-10-11-4-breaks-some-cisco-ipsec-vpn-connections/

-Brad


Forum|alt.badge.img+3

Same, just changed DH to 14, and all is working again!