VPN / DNS Issues With macOS Ventura

After upgrading MacBook Air M1 to Ventura I noticed that several of our internal business sites, RDP connections and Network SMB folders which require a VPN to access would not resolve, even after a successful VPN connection. and would only work via their respective IP addresses


Usual troubleshooting including...


  • Home router reboots
  • Mac reboots
  • Re-creating VPN connection
  • Different browsers
  • Different VPN account
  • macOS DNS cache clear
  • Switching to a mobile data (tethered) connection and then connecting to the vpn did not resolve


In desperation had to resort to manually editing the HOSTS file

sudo nano /etc/hosts


... which allowed the respective sites, folders and connections to resolve.

It's clear that Apple devs have broken DNS networking stuff which worked in Monterey and before.


Users should not have to manually edit the macOS HOSTS file to use DNS names whilst connected to a VPN in Ventura

MacBook Air 13″, macOS 13.0

Posted on Oct 26, 2022 5:48 PM

Reply
Question marked as Top-ranking reply

Posted on Apr 6, 2023 4:43 PM

Hi,

I have been having this problem also but I just solved it. I actually only joined to post the solution


Indeed the /etc/resolv.conf is over-written props to the user who pointed that out on page 3). For me it was overwritten with an internal 10.x address so obviously DNS was failing.


What is causing the overwrite is after upgrading apple turns on by default limit ip tracking.


01) Go to settings

02) Go to networks

03) Click details next to the network name In my case my wireless

04) Turn off limit ip tracking

05) Try your vpn again


That one thing fixed the automatic overwriting of the conf file.


I work in cloud security arch and while I am a big believer in secure defaults it is obnoxious to roll something like that out breaking people's vpns without some kind of warning.


Good luck to everyone!

Similar questions

89 replies

Apr 6, 2023 7:01 AM in response to mprush12

I love how Apple broke it but the entire world has to fix it.


And while providing no public redundant DNS servers can fix internal located Ventura computers - it cannot fix the VPN connected Ventura computers. The end user's Ventura Mac will always have public DNS servers available to them through their internet connection. And Ventura likes to use those public DNS servers before the VPN connected DNS servers.

Feb 1, 2023 4:59 AM in response to hamacardo

FWIW after a few days of problem free use, DNS issues have reappeared after updating to 13.2 (from 13.1) and now we have no public DNS server listed in our DHCP options, so the only DNS should be private


I am able to `nslookup` or `dig` a hostname, but when I try to curl I get a host cannot be found error


I have raised this with the support team of our VPN provider to see if they can suggest anything else, I will try to update this thread if I get anything useful back

Mar 2, 2023 9:18 AM in response to hamacardo

I can add that this DNS problem is not only related to VPN. Happens also on Wi-Fi and Ethernet when the (more than one?) DNS is provided via DHCP.


For example when using Safari I can load a web page that requiers our (my company’s) custom DNS and it works the first time, but if I reload the page it can't reach the page (as if ignoring the custom DNS) and a second reload makes it load again – so it works every other time(!).


The behavior is different in Chrome and Firefox. It's all pretty confusing.


In Monterey it all works as expected I think.

Apr 3, 2023 6:20 AM in response to mprush12

I spoke to Apple Enterprise Support on March 14 and gave them as much information regarding this issue as I possibly could. Logs, screen captures, demonstrations of the issue. I shared them support forum posts, reddit posts, MacRumors posts, VPN company support forum posts (including from major security vendors like FortiNet).


And yet, some how 2 weeks later they still "were not aware of an issue."


This tells me that Apple did nothing with everything I gave them because they don't care.


Apr 3, 2023 7:26 AM in response to ge-apple

ge-apple wrote:

I spoke to Apple Enterprise Support on March 14 and gave them as much information regarding this issue as I possibly could. Logs, screen captures, demonstrations of the issue. I shared them support forum posts, reddit posts, MacRumors posts, VPN company support forum posts (including from major security vendors like FortiNet).

And yet, some how 2 weeks later they still "were not aware of an issue."

This tells me that Apple did nothing with everything I gave them because they don't care.

Perhaps there is another explanation. I'm sure that Apple doesn't care about support forum posts, reddit posts, MacRumors posts, or VPN company support forum posts. Mention any of that and your report goes straight to the bit-bucket, as it should.


If you had specific information about your own experiences, such as logs, screen captures, and demonstrations, then they will pay attention to that. But I strongly suggest you limit the information you provide to your own experiences. If it sounds like you did your own "internet research", that's another one-way trip to the bit-bucket. People with jobs have no time for the internet.


Finally, and most importantly, this thread is 5 pages long. It was started in October of last year. Early posts consisted of people complaining that their VPNs were functioning correctly. Since then, it's become a dumping ground for any random complaints about DNS, mostly in an enterprise context, which can be really complicated. Any statements that anyone could make about "this issue" are self-evidently invalid. There are multiple issues. Some are totally invalid. Some are obviously related to configuration problems. To expect Apple to do anything, in two weeks no less, is completely outside the bounds of reality.


There is a good chance that whatever problems you are experiencing are, in fact, configuration problems. If you start your own thread discussion your own specific problem, then people will help you resolve it. This thread is the bit-bucket, the sewer of the Apple Support communities. You can contribute as much content as you want. Just don't expect anyone to drink from it. The only meaningful responses you will get are replies like this, suggesting that you leave the sewer if you want to get help.

Apr 4, 2023 2:05 PM in response to etresoft

Early posts consisted of people complaining that their VPNs were functioning correctly. Since then, it's become a dumping ground for any random complaints about DNS, mostly in an enterprise context, which can be really complicated.


An important thing to remember is that this is a change in behavior from Monterey to Ventura with no other external changes.


The same via DHCP deployed DNS settings behaves differently in Ventura compared to Monterey whether VPN is involved or not.

Jun 29, 2023 3:04 PM in response to Zykki

Guys, I don't know why VPN is involved here - I'm having the problem with just DNS on a new Mac Mini that came with Ventura installed (so I can't downgrade).


DNS resolution doesn't work but I can ping addresses (including DNS servers such as 1.1.1.1 or 8.8.8.8) and as others noted, dig is able to resolve domain names.


For a while, I was able to solve this by killing the mDNSResponder and helper but after the most recent Ventura update, even that only worked sometimes.




No problems with any other Mac, Windows or Linux box on my LAN


Apr 26, 2024 6:22 AM in response to hamacardo

Hi guys,


I still have similar issues with Sonoma 14.4.1. on Macbooks 18,2.

However, I only added 3 internal DNS servers and 3 internal search domains in the wired and Wi-Fi network configurations. We aren't using any external DNS servers, so the workarounds in this thread aren't solutions for us. And like others mentioned, all worked fine in previous macOS version (Monterey, Big Sur, Mojave, High Sierra...).


Another annoying fact about Ventura/Sonoma, you can't enable Apple Remote Desktop with scripts using MDM. You can only enable it directly on the computer.


Que Apple sera, sera.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

VPN / DNS Issues With macOS Ventura

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.