Hi,
I am trying to migrate IKEv1 to IKEv2 Dial-UP VPN tunnels for devices that use Forticlient and that do not use Forticlient(e.g. MacOS).
The configuration includes a split tunnel setup.
When a Forticlient enabled client attempts an IPSec connection the client acquires a split tunnel VPN session.
I can see the following few lines in the debug session that indicate routes will be installed in the routing table of the device.
However, when a MacOS client connects with the Fortigate, using the Native Mac-OS client, the client does not acquire a split tunneling configuration and only receives an default route.
In the following KB there's an explanation how to configure IPSec VPN using IKEv2 using Native MAC-OS client:
However, the "Configuration Attribute Internal IP Subnet" is nowhere to be found.
Is there a possibility to have a functioning IKEv2 setup without running Forticlient? IKEv1 works just fine with split tunneling.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
hi,
have a look at ~/Library/Preferences/com.apple.networkextension.plist and the attribute UseConfigurationAttributeInternalIPSubnet
Hey,
Thanks for the updates.
Unfortunately "~/Library/Preferences/com.apple.networkextension.plist" does not exist on my MAC.
I am running MacOS Sequioa 15.7.2.
With kind regards,
Jeroen
sry, my bad, remove the ~ , /Library/Preferences/com.apple.networkextension.plist is the location/file and open it from Finder w/ a text editor.
| User | Count |
|---|---|
| 2808 | |
| 1427 | |
| 812 | |
| 764 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.