Problem using IPsec PFS on MAC OSX

Frequently Asked Questions
Post Reply
Peter
Posts: 702
Joined: 10 Apr 2008, 14:14
Location: Clavister HQ - Örnsköldsvik

Problem using IPsec PFS on MAC OSX

Post by Peter » 19 Oct 2020, 08:27

This FAQ applies to:
  • Any cOS Core or cOS Stream version with support for IPsec.

Question:
I have problems using IKEv1 / IKEv2 on MAC OSX, after a re-key the tunnel disconnects after a couple of minutes. On Windows it works fine.

Answer:
We have received feedback from customers that this seems to be a known issue since OSX version 10.12 and up. The problem is when using Perfect-Foward-Secrecy (PFS) on Phase-2. Until such time that Apple has fixed the problem, the solution is to allow "none" to be used on PFS. See below picture for an example.

Clavister_PFS_Settings.png
Clavister_PFS_Settings.png (57.57 KiB) Viewed 76252 times

Post Reply