OS X Lion (10.7) VPN changes?

I haven't read anything about changes to the VPN client going from OS X 10.6.8 to 10.7, but ever since I upgraded to Lion my MacBook Pro will not establish a VPN connection on the first try. I didn't make any changes to settings on my end or settings on the server end. When I try to connect it'll tell me to verify the address and try again. I click "OK" and then I try again and it connects almost instantly (the way it used to).


Anyone know of any changes to the VPN client or experiencing the same issues?


Thanks,

Jeff

MacBook Pro 17, Mac OS X (10.7)

Posted on Jul 22, 2011 8:18 AM

Reply
37 replies

Jul 22, 2011 7:38 PM in response to Asatoran

I'm not sure about the server side, but I'll give you the info I have from my end.


1. When I set up the VPN connection on my MBP I set it up as a Cisco IPSec.

2. I have a Windows machine that I remote into once I'm on the VPN.


I don't know much more than that. The VPN belongs to a government agency so they won't tell me too much about it =/.

Jul 23, 2011 12:25 PM in response to jtweezy

Since it's a Cisco connection, it's not likely to be a "lower end" VPN that has caused other people issues in the past. (i.e.: PPTP to DD-WRT.)


To confirm: you are using OSX's built-in VPN? Not using any Cisco supplied software?


You could try contacting whoever is managing the VPN endpoint and see if they're willing to try working with you, or are already working on Lion compatibility. I have been receiving notifications from many of the banks I have business dealing with that Safari in Lion has not been approved for their sites, so it's possible that there may be some timeout adjustments that need to be made either on OSX or on the VPN endpoint. It may take awhile before everyone gets up to speed with Lion. (And if it's a government agency, that could be a long wait. 😉 ) Maybe the VPN admin may recommend using Cisco AnyConnect, which does appear to work correctly with Lion. (There are config and licensing concerns so not all Cisco VPNs would use AnyConnect.)


Other than that, at least you're able to connect. 🙂

Jul 25, 2011 9:23 AM in response to Asatoran

Yes, I'm using OS X's built-in VPN. I asked the IT department and they said that no changes have been made to the VPN server configuration. I even deleted the VPN connection and set it up again, but it's still giving me the failed connect on the first try.


I guess I'll just have to deal with connecting twice to get it to actually work for now. Thanks for all the info, guys!

Jul 25, 2011 10:00 AM in response to jtweezy

...I asked the IT department and they said that no changes have been made to the VPN server configuration....

They may have not made a change, but like I said, they may need to make a change to work better with Lion since it was your end that made a change. (e.g.: went from OSX 10.6 to 10.7.) And keep an eye out for anyone that posts tweaks to the Lion VPN settings.

Jul 28, 2011 7:15 AM in response to jtweezy

Also same connection problem as bwarncke.


Log (personal info removed):


Snow Leopard 10.6 (success):


Jul 27 14:41:17 hostname racoon[85299]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).


Jul 27 14:41:17 hostname racoon[85299]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).

Jul 27 14:41:17 hostname racoon[85299]: IKEv1 Phase2 Initiator: success. (Initiator, Quick-Mode).

Jul 27 14:41:17 hostname racoon[85299]: Connected.


Lion 10.7 (fail):


Jul 27 11:42:29 hostname racoon[415]: IKE Packet: transmit success. (Phase2 Retransmit).


Jul 27 11:42:41: --- last message repeated 3 times ---

Jul 27 11:42:41 hostname UserEventAgent[11]: ServermgrdRegistration cannot load config data

Jul 27 11:42:41 hostname UserEventAgent[11]: ServermgrdRegistration oldConfig is nil during net changed notification

Jul 27 11:42:41 hostname racoon[415]: IKE Packet: transmit success. (Phase2 Retransmit).

Jul 27 11:42:56: --- last message repeated 4 times ---

Jul 27 11:42:56 hostname configd[14]: IPSec disconnecting from server x.x.x.x

Jul 30, 2011 4:02 PM in response to BSDinit

Pretty much the same here, with a few added wrinkles:


Connecting from 10.5 to 10.5 server, both PPTP and L2TP worked fine.


Connecting from 10.7 to 10.5 server, both worked, although the icon on menu bar didn't. I had to connect from within System Preferences.


Now, 10.7 MBP to 10.6 server, only PPTP works, although the icon on the menu bar is working again, I'm the one that configured the 10.6 server, and I entered the password in both the server's field and y MBP's field at the same time, no typos.


Very weird. It should be added, that al connections are going out/in via Airport Extreme, (at home & in the office).

Aug 15, 2011 9:35 AM in response to jtweezy

I upgraded to Lion from Snow Leopard this morning. I was able to connect to our Cisco IPSec vpn just fine (shared secret / group name auth) from home. I came into work (with a different, internal IP over Cisco routers in the building) and I can't get a session established at all. I'm off to go talk to our IT group to see what can be done on the Cisco infrastructure side, if anything. They may not have a good idea what to change at this point.


So, yes, there is an issue when connecting to some Cisco IPSec VPN sessions/concentrators after the Lion upgrade. Any information people can share on a possible solution would be greatly appreciated. If I find out anything from our IT group, I will do the same.


Thanks.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

OS X Lion (10.7) VPN changes?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.