Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JvLeur
New Contributor

Dial-UP IPSec IKEv2 Split Tunnel

Hi,

 

I am trying to migrate IKEv1 to IKEv2 Dial-UP VPN tunnels for devices that use Forticlient and that do not use Forticlient(e.g. MacOS).
The configuration includes a split tunnel setup.
When a Forticlient enabled client attempts an IPSec connection the client acquires a split tunnel VPN session.

 

I can see the following few lines in the debug session that indicate routes will be installed in the routing table of the device.

 

ike 2:QDIPS_0:10843292: processed INITIAL-CONTACT
ike 2:QDIPS_0:10843292: mode-cfg assigned (1) IPv4 address 172.28.12.1
ike 2:QDIPS_0:10843292: mode-cfg assigned (2) IPv4 netmask 255.255.255.128
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:10.0.0.0/255.0.0.0:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:172.16.0.0/255.240.0.0:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:192.168.0.0/255.255.0.0:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:91.200.16.0/255.255.254.0:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:141.176.34.0/255.255.255.0:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:185.55.137.0/255.255.255.128:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:193.105.144.0/255.255.255.0:0
ike 2:QDIPS_0:10843292: mode-cfg send (13) 0:185.206.27.2/255.255.255.255:0

 

However, when a MacOS client connects with the Fortigate, using the Native Mac-OS client, the client does not acquire a split tunneling configuration and only receives an default route.

 

In the following KB there's an explanation how to configure IPSec VPN using IKEv2 using Native MAC-OS client:


https://community.fortinet.com/t5/FortiGate/Technical-Tip-Apple-IOS-native-VPN-using-IKEv2-connectio...

 

However, the "Configuration Attribute Internal IP Subnet" is nowhere to be found.

 

Is there a possibility to have a functioning IKEv2 setup without running Forticlient? IKEv1 works just fine with split tunneling.

5 REPLIES 5
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
funkylicious
SuperUser
SuperUser

hi,

have a look at ~/Library/Preferences/com.apple.networkextension.plist and the attribute UseConfigurationAttributeInternalIPSubnet

"jack of all trades, master of none"
"jack of all trades, master of none"
JvLeur
New Contributor

Hey,

 

Thanks for the updates.

Unfortunately "~/Library/Preferences/com.apple.networkextension.plist" does not exist on my MAC.

I am running MacOS Sequioa 15.7.2.

With kind regards,
Jeroen

funkylicious

sry, my bad, remove the ~ , /Library/Preferences/com.apple.networkextension.plist is the location/file and open it from Finder w/ a text editor.

"jack of all trades, master of none"
"jack of all trades, master of none"
JvLeur

The .plist file cannot be opened with a text editor as its a binary.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors