Skip to main content
New Member
July 20, 2026
Question

Issues with FortiClient (EMS Version) on macOS

  • July 20, 2026
  • 5 replies
  • 157 views

Dear Community,

I am writing you all because in my Company we have massive Issues with FortiClient (EMS) on the macOS Clients. I am working as IT Administrator and I am responsible for the MacBook’s.

The problem:

  • On the Mac Devices we have since many months the problem that when connected with the VPN the Download Speed is extremely low. We have an External Internet Connection at Work with 100 Mbit/s. With WiFi i get WITHOUT VPN like 80-100 Mbit/s. With VPN ON i get like 5 to 10 Mbit/s (with LAN connection it’s a little bit better). There were also days where it was more so its really inaccurate. The Upload Speed is the same with VPN ON and OFF. ~ 40 Mbit/s.
  • For Windows VPN OFF and VPN ON is the same Download Speed. 

Some informations:

  • EMS Policies are the same for the Windows- and the macOS Clients
  • We have this features: Remote Access (SSLVPN with Split Tunneling, Webfilter and Vulnerability Scan)
  • Windows Devices are still on 7.2.14 and macOS Devices are on 7.4.5 (I also tested today 7.4.7 the newest but same problems and also with 7.2.X we have the same problems)
  • The Mac’s are supervised with JAMF Pro. FortiClient Configuration Profile is used and properly configured. 
  • All MacBooks are on macOS 26

 

I tested so much on my Client but it was always the same result. Sadly I never got an improvement. For EMS site i can’t to anything because another Department takes care of that. I would gladly appreciate some solutions. If more informations are needed please let me know and thank you all!

 

Best regards

Adrian

 

5 replies

Stephen_G
Staff & Editor
Staff & Editor
July 23, 2026

Hi AdrianMOP,

Thanks for using Fortinet Community. We’ll look to get you an answer or help. In the meantime, if anyone else has any advice, feel free to respond.

Stephen_G - Fortinet Community Team
AEK
SuperUser
SuperUser
July 24, 2026

Hi Adrian

In your case I’d try 2 troubleshooting ways:

  • Change the enc-auth pair to something like aes128-sha256
  • Modify the MTU size using the <mtu_size> XML option to 1300, 1280 or even less

Hope it helps.

AEK
AdrianMOPAuthor
New Member
July 29, 2026

Dear ​@AEK 

thank you for answering my question. So for the MTU we already have 1300. We also now implemented DTLS but it also didn’t change anything and that was my last idea. For the Encryption is this on EMS site? Because I can’t do there anything. We have a Network & Infrastructure Team for that. Could you explain it to me a little bit more? Many thanks in advance.

 

Kind regards,

Adrian

AEK
SuperUser
SuperUser
July 29, 2026

Hi Adrian

You can still try MTU 1280.

Regarding enc-auth pair, you do it on both FGT IPsec tunnel config and on EMS VPN profile. They must match.

AEK
AdrianMOPAuthor
New Member
August 3, 2026

Dear ​@AEK,

with the MTU change nothing really changed. We don’t use IPsec, we use SSL VPN. But we found maybe something. We tried FortiClient WITHOUT EMS and got like 80mbps. Then with EMS it was only 20mbps. We think the Webfilter could interfere. Because on macOS the Webfilter works directly as Extension and it could interfere. Our biggest problem is with the SMB. We have a Windows Server with Network Shares. With FortiClient on it is soooo slow. Even connecting takes long and then opening a files often freezes the Finder. 

 

BR

Adrian

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!