Skip to main content
danjahner
New Member
September 12, 2015
Solved

FortiClient VPN Problems With OSX 10.11 El Capitan

  • September 12, 2015
  • 147 replies
  • 547194 views

I installed the GM candidate of Mac OS X 10.11 El Capitan and my FortiClient VPN has stopped working. It completes the login, but after connection, no data is transferred - the incoming and outgoing freeze. It is a split tunnel connection and neither network or internet traffic works. 

 

I tried disabling the firewall and System Integrity Protection, but neither had any effect. 

    Best answer by Chris_Lin_FTNT

    There is a new private build here:

    https://dl.dropboxusercontent.com/u/58793690/mac/FortiClient_5.4.0.493_macosx.dmg

     

    Would you guys give it a try?

    147 replies

    jweber
    New Member
    September 30, 2015

    Would you advise people not to upgrade to El Capitan if we use a Forticlient SSL VPN?

    jweber
    New Member
    September 30, 2015

    Jeff: I'm having the same DNS problem, on a clean install. I sent you the logs and config files via PM -- let me know if you need anything else.

    Sridhar
    New Member
    October 1, 2015

    Facing the same issue. Latest FortiClient(5.3*) did not fix it.

    But, FortiClient 4.0.2082 did not have any such issues(though it occasionally stops tunneling on its own).

     

    Waiting for a fix like everyone, but 4.0.2082 is letting me work for time being.

    kevinboos
    New Member
    October 1, 2015

    Sridhar wrote:

    Facing the same issue. Latest FortiClient(5.3*) did not fix it.

    But, FortiClient 4.0.2082 did not have any such issues(though it occasionally stops tunneling on its own).

     

    Waiting for a fix like everyone, but 4.0.2082 is letting me work for time being.

     

    I'm having the same issues. Where can we download version 4.0.2082? 

    danielcantwell
    New Member
    October 1, 2015

    I am having the same issue, everything worked perfect yesterday. Updated to El Capiton and now when I connect the VPN I loose connection to everything except the network I am connected to through the VPN. Is there any update when this issue will be resolved. 

    kenneth_Compres
    New Member
    October 1, 2015

    Any solutions to this?

     

    richard451
    New Member
    October 2, 2015

    I'm having the same issue.  Quite annoying.   Hopefully a solution will be available shortly.

    emnoc
    New Member
    October 10, 2015

    FWIW login and go to downloads on the support website. Release notes  dmg files exists.

     

     

    Chris_Lin_FTNT
    Staff
    Staff
    October 13, 2015

    One very experienced Mac user mentioned how he changed the solver manually to make the DNS work. It may worth a try.

     

    "Initial prep: $ mkdir ~/resolver $ echo ""nameserver 172.16.100.100"" > ~/resolver/ca (repeat for com, org and any other TLDs you need to access) $ sudo mkdir /etc/resolver

    After connecting to SSLVPN: $ sudo cp ~/resolver/* /etc/resolver

    When disconnecting from SSLVPN: $ sudo rm /etc/resolver/*

    For some reason, this works, even though /etc/resolv.conf's contents have no effect. "

    hansbogert
    New Member
    October 13, 2015

    I've gotten it to "work" by getting the DNS to use ppp0 and some route magic. Explanation is on: http://serverfault.com/questions/728702/how-to-get-forticlient-working-in-osx-el-capitan/728707#728707

     

    Let's hope either party fixes this, because running scripts after establishing VPN is quite cumbersome.

    mr_brody
    New Member
    October 16, 2015
    Using an older version works. From my dropbox: https://www.dropbox.com/s...cosx_4.0.2297.dmg?dl=0 Tested successfully!
    fortinetstoppedOSXsu
    New Member
    December 16, 2015

    Tried the private build and the published build for 10.11.1 and 10.11.2 

    Nothing works.

     

    This IS a Fortinet problem other VPN Clients like Tunnelblick work without any problems.

    To excuse the non existing effort on their side by waiting for Apple to solve THEIR client problems is ridiculous.

     

    It's a shame that Fortinet leaves it's clients unsupported since months after they have paid for their solution.

    Fortinet hampers our work and is a massive risk now for ongoing projects.

     

    I will support any initiative in our company to get rid of this firewall.

    In other fields we successfully use open source solutions - which do not leave you at the mercy of a commercial provider.

    I hope we find some open source solution for a firewall as well.

     

    Any proposals - or experiences?

     

    KR

     

     

    Chris_Lin_FTNT
    Staff
    Staff
    December 17, 2015

    It may be a good idea to open a tick with Fortinet Support.

    Chriskras
    New Member
    February 23, 2016

    The problems mentioned here playing with me, unfortunately. I have OS X completely up to date, I try the latest version of FortiClient, this gives a kernel panic. Now I downgrade to 5.4.0.499 and 5.4.0.493, but unfortunately the problems remain. What can I do to resolve this? What options do I have? When will there be a new version?

    sid_dawg
    New Member
    February 26, 2016

    Has anyone tried MAC 5.2.5.383? 

     

    We use split tunneling and after trying almost every client this worked for us. We have a 300c 5.2.1 GA618. 

    What's sad is this has been out since Nov and FGT did not mention it. 

    Anyway I'd like to know if this corrects the issue for others as well. 

     

    heller
    New Member
    February 29, 2016

    sid dawg wrote:

    Has anyone tried MAC 5.2.5.383? 

     

    We use split tunneling and after trying almost every client this worked for us. We have a 300c 5.2.1 GA618. 

    What's sad is this has been out since Nov and FGT did not mention it. 

    Anyway I'd like to know if this corrects the issue for others as well. 

     

    Yes, My OS X 10.11.x users are using the 5.2.5 FortiClient with success with regard to the split-tunneling/DNS issue.

    Waiting for an official 5.4.1 build to correct the issue as well.

    jafrancov
    New Member
    March 29, 2016

    This works for me with both native VPN client on El Capitan 10.11.4 and Forticlient 5.4.0.493, just update on phase 1 of your VPN, add DH group 14 and that will fix the issue, it appears that OSX 10.11.4, requires a minimum of a 2048 bit modulus (DH Group 14) to connect to IPSec VPNs.

    jago_ff
    New Member
    July 11, 2016
    Hi! I have 10.12, same problem
    SteveG
    New Member
    July 12, 2016

    5.4.1 is out for macOS....

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!