Description | This article describes what changes to make to fix the error 'Unable to connect to VPN because tunnel configuration is unsupported' when connecting to IPsec VPNs from a MacOS device. |
Scope | FortiClient (MacOS) 7.4.2. |
Solution |
When connecting to a dial-up IPsec VPN tunnel from a MacOS device, the following error may be encountered:
This error is because FortiClient on MacOS does not support DH group values above 18 for ikev1 configurations. For FortiClient version 7.4.2, the default DH group value is 20 which is unsupported for MacOS.
To resolve this, a value of 18 or lower simply needs to be chosen. An example is provided below.
On FortiClient, navigate to Remote Access, then edit the connection using the icon
In FortiClient version 7.4.3, the default has been set to DH group 5 for IKEv1 to avoid this issue. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.