VPN / DNS Issues With macOS Ventura

After upgrading MacBook Air M1 to Ventura I noticed that several of our internal business sites, RDP connections and Network SMB folders which require a VPN to access would not resolve, even after a successful VPN connection. and would only work via their respective IP addresses


Usual troubleshooting including...


  • Home router reboots
  • Mac reboots
  • Re-creating VPN connection
  • Different browsers
  • Different VPN account
  • macOS DNS cache clear
  • Switching to a mobile data (tethered) connection and then connecting to the vpn did not resolve


In desperation had to resort to manually editing the HOSTS file

sudo nano /etc/hosts


... which allowed the respective sites, folders and connections to resolve.

It's clear that Apple devs have broken DNS networking stuff which worked in Monterey and before.


Users should not have to manually edit the macOS HOSTS file to use DNS names whilst connected to a VPN in Ventura

MacBook Air 13″, macOS 13.0

Posted on Oct 26, 2022 5:48 PM

Reply
Question marked as Top-ranking reply

Posted on Apr 6, 2023 4:43 PM

Hi,

I have been having this problem also but I just solved it. I actually only joined to post the solution


Indeed the /etc/resolv.conf is over-written props to the user who pointed that out on page 3). For me it was overwritten with an internal 10.x address so obviously DNS was failing.


What is causing the overwrite is after upgrading apple turns on by default limit ip tracking.


01) Go to settings

02) Go to networks

03) Click details next to the network name In my case my wireless

04) Turn off limit ip tracking

05) Try your vpn again


That one thing fixed the automatic overwriting of the conf file.


I work in cloud security arch and while I am a big believer in secure defaults it is obnoxious to roll something like that out breaking people's vpns without some kind of warning.


Good luck to everyone!

Similar questions

89 replies

Feb 1, 2023 6:56 AM in response to f1r3s4l3

Oh, sorry about that. All the – I think in total about eight – 13" M1 we have in use at work has been fine so far. been in used for two years soon. Have a few M1 Max machines too and all also fine as of yet. Which M1 machine do you have? I guess there are always a certain amount that experience trouble, but that it is common with motherboard issues on them was new info to me.

Jun 29, 2023 4:49 PM in response to nvssm

With all due respect, @nvssm, your issue is different from what is being discussed here. In our case, DNS resolution works both with and without VPN, except that at some point, Apple starts using the DNS servers provided by the outside connection (WiFi, ethernet, etc.) instead of the ones provide by the VPN which breaks resolution of names for internal hosts.


Mar 23, 2024 3:26 PM in response to hamacardo

Some dns servers encrypt their conversations, like 1.1.1.1. Some non-encrypted dns servers do not so it is all readable to whomever. Maybe when one selects do not track or limit IP tracking macos will prefer encrypted dns conversations and override using a local non-encrypted dns server because of the limit IP tracking request.

Apr 14, 2024 3:44 AM in response to hamacardo

I have the solution - but you won't like it.


Background


I have an Apple macOS laptop alongside Microsoft Windows laptop.


Both macOS and Windows connect to the tunnel and work.


Windows will attempt using the VPN's DNS first, then if that fails, falls back to the next resovler (which is usually just internet).


macOS recognizes the VPN's DNS resolver - it just won't use it.


I've seen countless posts from so many forums of people second guessing themselves and their skills, when really it's the Apple macOS that is the problem. They simple don't offer the solutions that Microsoft do - they are simply non-existent. Sure - they give you the option of putting in your own DNS server to use - they just won't use it. This must be by design, because it's hard to imagine the bug is this serious and so pervasive. This is why people go crazy wondering 'why isn't it working?'


YOU are not going crazy, because the behavior you expect and want, is perfectly available and working on a Microsoft Windows laptop. THAT is the solution! I'm running both side-by-side - macOS is THE problem.


ps.

I repaired and programmed Apple computers from 1988 to the early '90's and it's very surprising to me how little the computers have changed over the years compared to Microsoft. Honestly, I just use them for their light-weight and battery life, I'm seriously considering installing windows on my mac. Hmmm...

May 3, 2024 5:00 AM in response to peterwilson_69

Just a quick update; my Mac has an Intel CPU so I used BootCamp to install Windows 10 on it - and honestly wish I had done so earlier. I feel like I have a brand new modern laptop, with awesome battery life! I was so impressed I converted my wife’s too (at her request), and one of my best mates is upset because he doesn’t have the Intel CPU in his MacBook Air. Best of luck everyone.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

VPN / DNS Issues With macOS Ventura

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.