Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
terry1
New Contributor

Mac connects to IPsec VPN but no traffic

I am a new Fortigate 30E owner and still learning it. I am able to connect to our IPsec VPN from a MacBook Pro running 10.10 and a MacPro running 10.11 but am unable to connect to or ping anything on the network. I am only able to ping the Fortigate's external IP. The MacBook Pro is connecting via a Verizon LTE hotspot so I can sit at my desk and look at the Fortinet admin page. The MacPro is at home on a Cox network. The odd thing is Fortinet support was able to connect to the VPN with a MacBook (I forgot to ask the MacOS) and were able to ping machines on the network.

 

So it appears to be something on my two different Macs running two different OSes that are not routing packets to the VPN. Neither the MacBook Pro nor the MacPro are running any AV software. Their firewalls have been disabled. What else can I look for that could be causing packets not to make it to the VPN?

 

Thanks for any pointers.

-Terry

 

Another data point in case it's relevant: The IPsec VPN was originally created by the Wizard, but connection attempts failed from the MacPro and an iPhone. Fortinet support was also unable to connect and made some changes to the Phase 1 Proposal Encryption and Authentication list and now we are both are able to connect.

 

 

1 REPLY 1
terry1
New Contributor

So after some investigating last night it turns out that on the home MacPro the Application firewall was disabled BUT I forgot about the packet filter firewall and had an old pf setting that was only allowing PPTP VPN traffic. Once I replaced that with an IPsec rule everything worked fine. The MacBook Pro on the other hand does not have pf enabled so I'm trying to figure out why it's not sending traffic.

Labels
Top Kudoed Authors