Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Built-in Cisco VPN on Lion still doesn't work - and now neither does the Cisco Client :-(

Until today, I've always used the Cisco client to setup the VPN - mostly because I could never get the built-in Cisco VPN (IPSec) to work in Snow Leopard. But even that stopped working with Lion (I saw some posts elsewhere that suggest that if you boot the O/S into 32-bits it might still work; others who've had the problem in the past also suggest re-installing the client). But I don't want to do either of these things - after all, what good is Apple's built-in Cisco support if it doesn't work?


Here's what I did so far: I created a VPN (Cisco IPSec) and put in our vpn's server address and my account id. Under "Authentication Settings..." I entered the shared secret and our Group Name. I then tried to connect. It seems to do so as it asks for my account's password (presumably the shared secret for the group has already been trasmitted). But when I give it the password, the VPN quietly disconnects again after a second or so. No warnings, no error messages - nothing!


Can someone here point me to where this network setup tool writes logs that I might look into to get a clue as to what's going on?


Better yet - if you know what (if anything) I'm doing wrong, please tell me? Any help is much appreciated.


Dead in the water,

Tom

Posted on Jul 20, 2011 11:11 AM

Reply
Question marked as Best reply

Posted on Jul 20, 2011 11:45 AM

Tom,


I just tried this on my Lion client. I was able to set up a Cisco IP sec VPN from my Lion client to my Cisco ASA. I used a shared secret and group config, vs a certificate and group config.


Open a console and click on all messages (on the left). Then try to connect with your VPN client. Copy and past from the first message from the racoon service that says IPSec connecting to server X.X.X.X to last message after the VPN connection attempt fails. That might give us a better idea of what is going on.

32 replies

Jul 22, 2011 6:45 AM in response to anluis

Angel,

I'm glad you got your setup working. It seems to depend on what kind of Cisco equipment you're using. It definitely isn't working on a Cisco 3000 VPN concentrator series. And it's not because I didn't provide the right shared secret. As the logs indicate, authentication is fine - the problem appears somewhere past that - possibly during negotiation for encryption protocol. I'm hoping DrVenture can take a look at the VPN server logs I posted and help decipher them.

Jul 22, 2011 6:55 AM in response to eduhightrance

Mac OS X's VPN has always been flaky, and getting it to work is more luck than science. I have to connect to a /12, which involved several false starts, and I have no idea how I managed to get it to eventually work. But FYI, mine's working fine on Lion with a 64-bit kernel, so that's not the problem. One other thing: There are some daemons involved in the VPN, and they can crash. If it worked and then a few minutes later stops working, a reboot will fix it (or you can figure out how to restart the service from a terminal). In fact, the service will crash after some configuration changes, meaning that no matter what you do after that point, it will always fail.

Jul 22, 2011 11:01 AM in response to tjwolf

Tom,


If you are willing, I can ping you offline (if you give me an email address) and we can try to see if you can connect to my ASA. I will provide you with login details. That way we can figure out if this is an incompatability with Lion and the Cisco 3000 VPN.


Also, you might want to ask your network admin if there are any newer release of Cisco IOS he can try.


Another thought is to sign up with a free Cisco ID and ask on their discussion forums, posting the logs from the Cisco 3000.

Jul 22, 2011 11:15 AM in response to DrVenture

@DrVenture,

My e-mail is tjwolf at gmail dot com. Thanks a bunch for trying to help.


My "network admin" knows less about the Cisco router he's supposed to administer than I, it seems. And, as you can plainly see, I don't know a heck of a lot :-( He told me that the Cisco 3000 is running 4.7.2A - according to him, that's the latest.


I'm almost resigned to gettying that Cisco AnyConnect (v. 3.0.3050 and above supposedly supports Lion).

Jul 30, 2011 1:46 PM in response to tjwolf

Check out this link:

When going to a 64 bit OS (For me, it broke with Lion) the Cisco VPN no longer works because it is a 32 bit application.

http://jmilbery.wordpress.com/2011/07/26/cisco-vpn-with-macos-lion/

The native OS VPN works fine for me connecting to an ASA. Conencting to a VPN 3k concentrator can have mixed results, because they haven't updated those things in a while, and they will be end of support from Cisco next year.

The OS VPN can be configured in your network properties, and you get to stay in 64 bit mode.

Aug 4, 2011 6:36 PM in response to moosecow

An Apple engineer contacted me about this problem and suggested what DrVenture just did: check the version of the Cisco IOS software. The latest is 4.7.2P - we were running an old version: 4.7.2B. Unfortunately, we no longer have support on this device, so we couldn't get the update :-( We also have an ASA - apparently that is newer equipment and is more likely to work - the Apple engineer let me try on his ASA and I was able to setup a VPN with my Mac. But my IT guy doesn't know much about how to setup ASAs either, so I'm still waiting for him to get up to speed.

Aug 10, 2011 9:23 AM in response to tjwolf

I am having a similar issue as everyone here. I have managed to get the built in VPN link to nearly work with my MacBook Pro running Lion. However, after I enter my log-on information I get this message after a brief pause.


The negotiation with the VPN server failed. Verify the server address and try reconnecting.


Is this something I can fix on my machine or is our hardware too lod for the Mac to connect to? I'm very new to the world of VPN and the tech supporting the Cisco 800 Series router doesn't no jack about macs (no surprise).


Any guidance would be helpful, Thanks.

Aug 10, 2011 10:13 AM in response to azfotoman

As a result of talking to an Apple engineer who saw my post here, I asked my IT guy to upgrade our Cisco 3000 series to the latest firmware (IOS 4.7.2P I think) to see if that helps things. We apparently had a very old version of the software (I was able to use the built-in VPN to log into Apple's Cicso ASA machine - it was running the latest). Since I can't wait for him to figure out how/when to do the upgrade, we also went ahead and bought Cisco's AnyConnect VPN software - version 3.0.3 (or later) is supposed to support Lion. I just got the s/w today, so I will try it tonight and post my results.

Aug 31, 2011 10:48 AM in response to tjwolf

This whole ordeal sounds incredibly similar to what I'm going through with our VPN. We're running a Cisco ASA 5505. I tried downloading Cisco AnyConnect 3.0.3054 but cannot get that to work at all. (By the way, you can download AnyConnect for free if you have a Cisco Service Agreement number.)


It looks like has gone dormant for a couple of weeks. Hopefully some updates will come through. I really need help with this problem!

Sep 9, 2011 6:33 AM in response to diedoggie

Hi Mark,

I have not gotten the built-in VPN client to work. I did get a 3rd-party client (NCP Secure Client) to work. NCP had a 30-day trial period and I have not yet bought it - that was a good thing because two of my colleagues got the built-in VPN client to work! The "trick" was not to pick the "IPSec" VPN type - they used PPTP. I can tell you - there's no small amount of laughter at me: here I am - a "senior" software engineer - can't get the VPN working, talking to Apple engineers, posting on the web.....and two sales guys in my company had no trouble at all :-} My only defence is that I thought that because the Cisco VPN client used "IPSec", I needed to as well - therefore I never considered trying PPTP.


Hope this helps folks.

Tom

Built-in Cisco VPN on Lion still doesn't work - and now neither does the Cisco Client :-(

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.