Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

VPN (Cisco IPSec)

Since the update to Big Sur Mac OS 11.0.1 VPN Cisco IPSec does not work anymore.


My VPN services created on the default system VPN Type Cisco IPSec still do connect, but afterwards there is no IP traffic possible. Not even pings to IP addresses are possible.

I've looked into potential firewall issues, re-created the services on Big Sur and checked from Catalina and iOS where the VPN entries are still working flawlessly.


Any ideas?


Best Regards


MacBook Pro 13″, macOS 10.14

Posted on Nov 24, 2020 6:37 AM

Reply
Question marked as Best reply

Posted on Nov 25, 2020 9:22 AM

Solved:

The problem is related to the Little Snitch version 5 Network Extension.

There is a bug in macOS Big Sur 11.0.1 where VPNs of type Cisco IPSec won’t work when a Network Extension is installed. This affects Little Snitch 5 (not older versions!) and many other products based on Network Extensions. The VPN will connect successfully, but no data is transferred.
The bug has been reported to Apple and will be fixed in macOS 11.1.
If you rely on this type of VPN, please consider installing Little Snitch 4.6, which is based on a Network Kernel Extension and is therefore not affected.




Similar questions

7 replies
Question marked as Best reply

Nov 25, 2020 9:22 AM in response to joesflow

Solved:

The problem is related to the Little Snitch version 5 Network Extension.

There is a bug in macOS Big Sur 11.0.1 where VPNs of type Cisco IPSec won’t work when a Network Extension is installed. This affects Little Snitch 5 (not older versions!) and many other products based on Network Extensions. The VPN will connect successfully, but no data is transferred.
The bug has been reported to Apple and will be fixed in macOS 11.1.
If you rely on this type of VPN, please consider installing Little Snitch 4.6, which is based on a Network Kernel Extension and is therefore not affected.




Nov 25, 2020 12:26 AM in response to KiltedTim

Hi Tim,

yes I did that. I even created and successfully deployed a profile in Apple Configurator 2. All with same result.

I can successfully connect and afterwards no IP traffic can pass thru any route until I disconnect the VPN link.


Here are the most likely relevant console messages from racoon, neagent, nesessionmanager


racoon(40882) deny(1) system-privilege 10006
racoon	none message must be encrypted, status 0x14a1, side 0
racoon	sending vpn_control ike failed message - code=14  from=remote.
    
nesessionmanager	Failed to load configuration with ID 5A9D0B7D-35BE-40F6-9A33-4F72D2F7DEE.   nesessionmanager	Failed to add a pending session request or failed to load session for 5A9D0B7D-35BE-40F6-9A33-4F72D2F7DEE5 (1), canceling new connection







VPN (Cisco IPSec)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.