Migrated VPN Service Broken with Catalina

My Mac mini has been working just fine with macOS Mojave as a VPN server following the migration method described in https://developer.apple.com/support/downloads/macOS-Server-Service-Migration-Guide.pdf , but after upgrading to macOS Catalina there is trouble:


The VPN clients connect just fine on the internal network, but not on an external network; which makes the VPN server a bit pointless! I can confirm that all was working well with the server running macOS Mojave, and my iOS 13 and iPadOS 13 clients have been connecting just fine; it is the upgrade to macOS Catalina on the server that has caused this problem.


Here are the log entries for a failed connection:





Posted on Oct 11, 2019 9:42 AM

Reply
Question marked as Top-ranking reply

Posted on Nov 15, 2019 1:54 AM

I have tried VPN Enabler mention by lcrooks earlier and have managed to get the connection working back to my Catalina OS Mac Mini. I have done this locally from another desktop and remotely from my iphone. The later needed the OpenVPN app installed.

I also needed to edit the config file created by VPN Enabler as it didn't want to work by default. This was a bit of trial and error really as I am certainly no expert on this, but noticed when using the client part of VPN Enabler that the config file didn't seem to reference my server url but the port number instead. I simply replaced the port number with my url and it worked. The lines I changed are below


<key>RemoteAddress</key>

<string>xxx.ddns.net</string> This simply contained "REMOTE"


<key>remote</key>

<string>xxx.ddns.net</string> Note: this is where the port number 1194 was


Similar questions

120 replies

Apr 14, 2020 3:03 PM in response to TrainsAndWellbeing

Tried that method back in October and it did not work.


Tried one more time now, copied vpnd from 10.14.6, made sure that everything was correct (vpn.ppp.l2tp.plist updated to specify the new path, macOS asked me if I wanted to open a file when reloading vpnd so the new file was actually used) and it still does not work for external connections.


If anyone else wants to try - please go ahead but don't have your hopes high.

May 20, 2020 2:11 PM in response to TrainsAndWellbeing

If anyone is looking for an alternative solution to a home VPN server, I would recommend considering setting up a Raspberry PI with strongSwan.


I know that it seems like an obvious answer (I knew about it before too), however, what I did not realise is that you can actually have a better VPN server this way (compared to what we had on macOS).


You can actually use "VPN on demand" rules which are super cool (e.g. you can make your iPhone to connect to your VPN whenever you get on an unknown Wi-Fi network). The downside is that you need to be tech savvy to set it up.

May 20, 2020 2:32 PM in response to Ivan Pavlov

I recently bought a DrayTrek router mainly because I wanted the LTE failover, but as an added perk the router has a highly configurable VPN server. By not forwarding the VPN port to my Mac mini the router is resolved to the same URL and I just duplicated the settings from the Mac mini so that my clients work just as they did. So not only have I gotten rid of an Apple Server but I’ve also demoted the Apple Router to a simple access point.

The Raspberry PI sounds good though, and I think you can power it by USB so it could be a very handy option.

Oct 30, 2019 12:37 AM in response to Ivan Pavlov

Well that’s just brilliant! Well done Apple for imposing their networking hardware on every network to get things working. Ohh wait: they’ve discontinued their routers!

So all we need is a time machine so that we can visit the Apple Store in the past and buy all the AirPort hardware we can, and who says Apple don’t care about their loyal customers?


Thanks Ivan for letting us know about your experiment, perhaps you’ve helped narrow things down a little. It could be that there is something going on relating to Bonjour since AirPort routers are the only routers I know of that use it.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Migrated VPN Service Broken with Catalina

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.