OS X Lion (10.7) VPN changes?

I haven't read anything about changes to the VPN client going from OS X 10.6.8 to 10.7, but ever since I upgraded to Lion my MacBook Pro will not establish a VPN connection on the first try. I didn't make any changes to settings on my end or settings on the server end. When I try to connect it'll tell me to verify the address and try again. I click "OK" and then I try again and it connects almost instantly (the way it used to).


Anyone know of any changes to the VPN client or experiencing the same issues?


Thanks,

Jeff

MacBook Pro 17, Mac OS X (10.7)

Posted on Jul 22, 2011 8:18 AM

Reply
37 replies

Jan 10, 2012 2:59 AM in response to jtweezy

I have the exact opposite problem.


I connect to a VPN (not sure about the remote setup, my company is in a different country) via PPTP.


I own a Late 2008 MacBook Pro, and (until recently) I was planning to keep Snow Leopard.


With SL 10.6.8 my VPN connection shows erratic behaviour: it always connects at the first attempt, but after a few minutes (and way before session timeout) becomes unresponsive. I have to disconnect and re-connect for 2/3 times before I get a stable connection again.


I happened to try the same connection with Lion 10.7.2, and even though the VPN still hangs from time to time, it starts working again by itself in 20/30 seconds.


So I think I might be forced to upgrade to Lion.

Feb 20, 2012 5:16 AM in response to jtweezy

this has been causing me no end of issues also... im on Lion 10.7.2

Just want to use the builtin Cisco ipsec VPN to access the office from my MBP. would work sometimes, then in times of emergency it would fail.


So after trailing the internet and trying every suggestion i could find i thought i would remove Parallels from my MBP. Restarted and i can connect perfectly with the original Cisco ipsec vpn profiles i created.


Thought it was worth noting considering the hair pulling i have been doing. Now to get Parallels back on without messing up my vpn profiles... I hope some of you find this useful.

Apr 24, 2012 10:48 AM in response to jtweezy

I also cannot connect to our VPN with 10.7.2... but, our IT guy doesn't know what the shared secret is, so I think that's the problem. This is the first time I'm attempting to connect to our Cisco VPN with my laptop, so I don't have the old software installed to find any preferences. Any ideas how to find a shared secret?

Jul 24, 2013 12:00 AM in response to jtweezy

I know I'm reviving a bit of a dead horse here, but I ran into the same problem and fixed it! In my case the situation was a little unique, as I had a MacBook Pro running 10.8.4 that could connect just fine while an iMac, also running 10.8.4, on the same network was failing every time. Deleting the VPN service from the iMac, exporting the working service from the MacBook Pro (with the "include items from the user's keychain" checked), and then importing it on the iMac didn't work.


The iMac's error was "configd: IPSec Controller: IKE FAILED. phase 5, assert 0". The important thing was the iMac's logs showed prior to this error it was making a connection, getting an internal IP and DNS servers, and then racoon was successively reporting:


IKE Packet: transmit failed. (Information message).

IKEv1 Information-Notice: transmit failed. (Delete ISAKMP-SA).

Connecting.

IPSec Phase1 started (Initiated by me).

IKE Packet: transmit success. (Initiator, Aggressive-Mode message 1).

IKEv1 Information-Notice: transmit success. (Without ISAKMP-SA).

IT's VPN server logs didn't show any issues and that the iMac was initiating the disconnection.


I did a fresh install of 10.8.4 to an external USB2 drive, and booting from that the VPN worked the first time. Looking at the variables that could be different between a fresh install and an existing one, I systematically changed each that I could think of: permissions, caches (system, network, and user), preferences, and Keychains. The last was the one that fixed it.


I cleared out my Keychain and the VPN worked when booting from my existing iMac user. I used Migration Assistant to transfer the Keychain from my MacBook Pro user to the iMac, and the VPN continued to reliably work. There may have been some other interaction going on, as making a new user on the iMac prior to all this other troubleshooting did not fix the issue. The Cisco IPSec VPN service, including all settings, did carry over from one user to the next though, so the password, shared secret, etc. were probably accessed by all users.


Hope this helps others!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

OS X Lion (10.7) VPN changes?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.