VPN IPSec macOS Route Issue
Hi everyone, I'm experiencing a strange issue with an IPsec Dial-up VPN after migrating users from SSL VPN. The environment is FortiGate 400F with FortiClient VPN 7.4.3.4323 on macOS Sonoma 14.1. The problem only affects macOS clients; Windows clients using the same VPN configuration and user account work correctly. Split tunneling is enabled, and all firewall address objects are configured correctly as /24. However, after connecting from macOS, one of the split-tunnel routes is installed with an incorrect mask (for example, 10.10.10.0/24 becomes 10.10.10.0/31). If I remove that subnet from the split-tunnel group, the issue moves to the next subnet (10.10.11.0/24 becomes 10.10.11.0/31), so the problem follows the route order rather than a specific network. I also tested with a split-tunnel group containing only three networks, and everything works correctly on macOS. The production split-tunnel group contains around 190–200 routes. Has anyone encountered a similar issue or knows whether this is a FortiClient/macOS limitation or a known bug?
