Migrated VPN Service Broken with Catalina

My Mac mini has been working just fine with macOS Mojave as a VPN server following the migration method described in https://developer.apple.com/support/downloads/macOS-Server-Service-Migration-Guide.pdf , but after upgrading to macOS Catalina there is trouble:


The VPN clients connect just fine on the internal network, but not on an external network; which makes the VPN server a bit pointless! I can confirm that all was working well with the server running macOS Mojave, and my iOS 13 and iPadOS 13 clients have been connecting just fine; it is the upgrade to macOS Catalina on the server that has caused this problem.


Here are the log entries for a failed connection:





Posted on Oct 11, 2019 9:42 AM

Reply
Question marked as Top-ranking reply

Posted on Nov 15, 2019 1:54 AM

I have tried VPN Enabler mention by lcrooks earlier and have managed to get the connection working back to my Catalina OS Mac Mini. I have done this locally from another desktop and remotely from my iphone. The later needed the OpenVPN app installed.

I also needed to edit the config file created by VPN Enabler as it didn't want to work by default. This was a bit of trial and error really as I am certainly no expert on this, but noticed when using the client part of VPN Enabler that the config file didn't seem to reference my server url but the port number instead. I simply replaced the port number with my url and it worked. The lines I changed are below


<key>RemoteAddress</key>

<string>xxx.ddns.net</string> This simply contained "REMOTE"


<key>remote</key>

<string>xxx.ddns.net</string> Note: this is where the port number 1194 was


Similar questions

120 replies

Dec 2, 2019 9:26 AM in response to VDalto

Thanks for your input but unfortunately it doesn't help us in this thread:

Our problem is that we used macOS as a VPN server and upgrading our server computers to Catalina has broken our ability to connect from anywhere that is not our internal network.

I suspect quite a few of us might move to Windows Server or a POSIX style system other than macOS.

Dec 20, 2019 2:34 AM in response to Ivan Pavlov

I have, but I'm not expecting to see a fix at this stage. I've reported issues with migrated server services before and including this one, and been in e-mail contact with support and nothing seems to get fixed. Given that Apple removed the DNS service that Profile Manager depends on I suspect they want us to use and ISP hosting solution for things like DNS and VPN's which is something I won't be spending money on. I also don't want to surrender my security and privacy to an external provider. I suppose one solution would be to replace macOS with an open source alternative and running Linux systems on Mac's was quite popular at a time.

I'm using an older mac now for my VPN but if this issue does get resolved I'd appreciate it if somebody posted here if that happened.

Thanks

Mar 19, 2020 1:16 PM in response to lcrooks

Why unbelievable? They've triaged this and decided that only a relative few of us use it, and so our screams won't be loud enough to rock the prioritizers. Just because that's true doesn't make it right or good, of course, but Apple's the biggest gorilla in this jungle, so…. And honestly, there are worse bugs which go unresolved forever, although I'd guess this one would be pretty easy to identify and fix. Maybe we should scream louder, but given the stripping Apple gave MacOS Server, I'm guessing it wouldn't help.

Apr 16, 2020 7:19 AM in response to Ivan Pavlov

I thought I had solved the problem, but not quite. I can get the Mojave vpnd to work fine on Catalina *IF* I connect from my local network which is not much use. If I connect from the Internet I get 7 incoming calls, and then 7 hangups. I assumed there might have been a port forwarding problem, so I tried forwarding to the Mojave Parallels client I had been using to get around this problem and that worked fine. If I forwarded back to Catalina... NG. VPN Log extracts follow.








This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Migrated VPN Service Broken with Catalina

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.