Skip to main content
danjahner
New Member
September 12, 2015
Solved

FortiClient VPN Problems With OSX 10.11 El Capitan

  • September 12, 2015
  • 21 replies
  • 546876 views

I installed the GM candidate of Mac OS X 10.11 El Capitan and my FortiClient VPN has stopped working. It completes the login, but after connection, no data is transferred - the incoming and outgoing freeze. It is a split tunnel connection and neither network or internet traffic works. 

 

I tried disabling the firewall and System Integrity Protection, but neither had any effect. 

    Best answer by Chris_Lin_FTNT

    There is a new private build here:

    https://dl.dropboxusercontent.com/u/58793690/mac/FortiClient_5.4.0.493_macosx.dmg

     

    Would you guys give it a try?

    21 replies

    tobiacaneschi_work
    New Member
    September 14, 2015

    Same for me. Can we have a beta version ?

     

    danjahner wrote:

    I installed the GM candidate of Mac OS X 10.11 El Capitan and my FortiClient VPN has stopped working. It completes the login, but after connection, no data is transferred - the incoming and outgoing freeze. It is a split tunnel connection and neither network or internet traffic works. 

     

    I tried disabling the firewall and System Integrity Protection, but neither had any effect. 

    nsissrq
    New Member
    September 15, 2015

    I'm having the exact same issue here as well.  It seems to be DNS related, as I am able to ping IP addresses, but cannot ping FQDNs.  I can perform nslookups.  Websites do not load when using FQDN, only when using IP.  I had to add some entries in my /etc/hosts file in order to even do basic work while connected to the company's VPN due to this bug.  It's a workaround for the time being, but we will definitely need a fix soon... El Cap comes Sept 30!

    ecr80
    New Member
    September 16, 2015

    Have exactly the same problem. Hope it's solved soon!

    rwdorman
    New Member
    September 17, 2015

    There is another known bug with both El Cap and Yosemite in the current release that causes kernel panics, we're told its fixed in 5.2.5 but no ETA on release.

    lzs
    New Member
    September 22, 2015

    I've been trying since the first public beta, and now on the final GM Candidate. The VPN problem is there. Basically, what is wrong is that OS X's resolver is sending traffic out through the primary (original) network interface, even though the route table correctly shows that the VPN tunnel (ppp0) should be used.

     

    When you use a command like nslookup, the DNS traffic goes through the VPN tunnel (ppp0) properly.

     

    DNS name resolution  fails because my VPN client is told to use my corporate DNS server, but my corporate DNS server refuses to serve name queries from outside the corporate network. When the FortiClient VPN is connected, OS X's name resolution traffic arrives at the DNS server with the client's public Internet IP address, and hence is refused by my DNS server.

     

    Technically, this looks like an OS X bug. Or, perhaps there really is something wrong that FortiClient is dong. Either way, I hope FortiNet can rectify or take it up with Apple to fix El Capitan.

    danjahner
    danjahnerAuthor
    New Member
    September 22, 2015

    The OSX update released 09/22 (El Capitan Update 10.11.1) resolved this issue.

    lzs
    New Member
    September 22, 2015

    danjahner wrote:

    The OSX update released 09/22 (El Capitan Update 10.11.1) resolved this issue.

    It doesn't for me. Just installed 10.11.1, tested, and had the same issue as before.

    lzs
    New Member
    September 24, 2015

    I logged a support ticket on this issue, and was told the current version of FortiClient was not supported on El Capitan. Pressing further on an update, seeing that El Capitan is GA next week, I got the reply that:

     

    "I'm sorry but we do not have the requested information at the current moment. There no ETA yet on when FortiClient will be supported with Mac OS X 10.11 [El Capitan]."

     

    I'm quite disappointed. It's like saying Windows 10 being due next week, and knowing they have a bug with Windows 10, and yet not having a clue about when that will get fixed. OS X may not be as big in numbers compared with Windows, but still a sizeable population of users are on it these days.

    Chris_Lin_FTNT
    Staff
    Staff
    September 28, 2015

    I have an FortiClient Mac interim build FortiClient_5.3.25.492_macosx.dmg here: https://www.dropbox.com/sh/cb0j4pxw1f8nq84/AABJBxUrmhiRfwHjAIBKe1DSa/mac?dl=0

     

    Please try to see if it works for you.

    lzs
    New Member
    September 28, 2015

    Chris.Lin wrote:

    I have an FortiClient Mac interim build FortiClient_5.3.25.492_macosx.dmg here: https://www.dropbox.com/sh/cb0j4pxw1f8nq84/AABJBxUrmhiRfwHjAIBKe1DSa/mac?dl=0

     

    Please try to see if it works for you.

    Hi Chris, thanks, it's really good to know that someone's working on this issue!

     

    I've just tested the build but the problem is not resolved. It's a bit different now. The resolver's traffic is sent through the tunnel "ppp0", but with the wrong source IP. It's using the source IP of the Mac's physical interface (e.g. "en0") instead of the VPN tunnel IP.

     

    Using the "nslookup" command does see the DNS queries going through the tunnel "ppp0" with the proper source IP address, so this command works.

     

    Hope this helps you! :)

    Chris_Lin_FTNT
    Staff
    Staff
    September 28, 2015

    I see.

     

    How about clearing DNS cache, like this http://osxdaily.com/2014/11/20/flush-dns-cache-mac-os-x/

     

    After this, does it still use wrong source IP?

    lzs
    New Member
    September 28, 2015

    Chris.Lin wrote:

    I see.

     

    How about clearing DNS cache, like this http://osxdaily.com/2014/11/20/flush-dns-cache-mac-os-x/

     

    After this, does it still use wrong source IP?

    Hi Chris,

     

    It's still sending the DNS queries with the wrong source IP after the cache flush. I don't think the cache flush would help anyway, since the resolver is in fact trying to send out the queries.

     

    Hope this helps.

    Chris_Lin_FTNT
    Staff
    Staff
    September 29, 2015

    We have a problem to reproduce this issue :(  Maybe we installed 10.11 on another drive instead of upgrade?

     

    I wonder how do you guys install 10.11?

    Jeff_FCT_FTNT
    Staff
    Staff
    September 29, 2015

    Could you attached

    1. the sslvpn log file

    2. the ifconfig settings

    3. FOS config file

     

    thanks

     

     

     

    Jeff_FCT_FTNT
    Staff
    Staff
    September 29, 2015

    And FCT config file too.