all computers can login to vpn, except one.

At my office I am running an Apple server (El Capitan with server 5.2). VPN is enabled and running.

When I connect to the VPN from home with my ancient MacBook Pro (2009, Sierra) everything works as expected. When my wife logs in using her MacBook Air (2015, Sierra) everything works as expected. So do all other computers and iPhones at home.

But when I try to log in using my MacBook Air (2015, Sierra), I cannot connect.

The server log shows this:


2018-01-04 17:25:53 CET Incoming call... Address given to client = 192.168.1.200

Thu Jan
4 17:25:53 2018 : Directory Services Authentication plugin initialized

Thu Jan
4 17:25:53 2018 : Directory Services Authorization plugin initialized

Thu Jan
4 17:25:53 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:53 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:53 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:53 2018 : L2TP incoming call in progress from ‘xxx.xxx.xxx.xxx’…

Thu Jan
4 17:25:53 2018 : L2TP received SCCRQ

Thu Jan
4 17:25:53 2018 : L2TP sent SCCRP

2018-01-04 17:25:54 CET Incoming call... Address given to client = 192.168.1.201

Thu Jan
4 17:25:54 2018 : Directory Services Authentication plugin initialized

Thu Jan
4 17:25:54 2018 : Directory Services Authorization plugin initialized

Thu Jan
4 17:25:54 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:54 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:54 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:54 2018 : L2TP incoming call in progress from 'xxx.xxx.xxx.xxx'...

Thu Jan
4 17:25:54 2018 : L2TP received SCCRQ

Thu Jan
4 17:25:54 2018 : L2TP sent SCCRP

2018-01-04 17:25:56 CET Incoming call... Address given to client = 192.168.1.202

Thu Jan
4 17:25:56 2018 : Directory Services Authentication plugin initialized

Thu Jan
4 17:25:56 2018 : Directory Services Authorization plugin initialized

Thu Jan
4 17:25:56 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:56 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:56 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:25:56 2018 : L2TP incoming call in progress from 'xxx.xxx.xxx.xxx'...

Thu Jan
4 17:25:56 2018 : L2TP received SCCRQ

Thu Jan
4 17:25:56 2018 : L2TP sent SCCRP

2018-01-04 17:26:00 CET Incoming call... Address given to client = 192.168.1.203

Thu Jan
4 17:26:00 2018 : Directory Services Authentication plugin initialized

Thu Jan
4 17:26:00 2018 : Directory Services Authorization plugin initialized

Thu Jan
4 17:26:00 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:00 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:00 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:00 2018 : L2TP incoming call in progress from 'xxx.xxx.xxx.xxx'...

Thu Jan
4 17:26:00 2018 : L2TP received SCCRQ

Thu Jan
4 17:26:00 2018 : L2TP sent SCCRP

2018-01-04 17:26:04 CET Incoming call... Address given to client = 192.168.1.204

Thu Jan
4 17:26:04 2018 : Directory Services Authentication plugin initialized

Thu Jan
4 17:26:04 2018 : Directory Services Authorization plugin initialized

Thu Jan
4 17:26:04 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:04 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:04 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:04 2018 : L2TP incoming call in progress from 'xxx.xxx.xxx.xxx'...

Thu Jan
4 17:26:04 2018 : L2TP received SCCRQ

Thu Jan
4 17:26:04 2018 : L2TP sent SCCRP

2018-01-04 17:26:08 CET Incoming call... Address given to client = 192.168.1.205

Thu Jan
4 17:26:08 2018 : Directory Services Authentication plugin initialized

Thu Jan
4 17:26:08 2018 : Directory Services Authorization plugin initialized

Thu Jan
4 17:26:08 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:08 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:08 2018 : publish_entry SCDSet() failed: Success!

Thu Jan
4 17:26:08 2018 : L2TP incoming call in progress from 'xxx.xxx.xxx.xxx'...

Thu Jan
4 17:26:08 2018 : L2TP received SCCRQ

Thu Jan
4 17:26:08 2018 : L2TP sent SCCRP

2018-01-04 17:26:13 CET
--> Client with address = 192.168.1.200 has hungup

2018-01-04 17:26:14 CET
--> Client with address = 192.168.1.201 has hungup

2018-01-04 17:26:16 CET
--> Client with address = 192.168.1.202 has hungup

2018-01-04 17:26:18 CET
--> Client with address = 192.168.1.203 has hungup

2018-01-04 17:26:21 CET
--> Client with address = 192.168.1.204 has hungup

2018-01-04 17:26:24 CET
--> Client with address = 192.168.1.205 has hungup


So at least there is communication between my computer and the server. Why it assigns 5 IP addresses is beyond me though.

On my Air, var/log/ppp/log shows:


Mon Dec
4 18:59:38 2017 : publish_entry SCDSet() failed: Success!

Mon Dec
4 18:59:38 2017 : publish_entry SCDSet() failed: Success!

Mon Dec
4 18:59:38 2017 : l2tp_get_router_address

Mon Dec
4 18:59:38 2017 : l2tp_get_router_address 192.168.0.1 from dict 1

Mon Dec
4 18:59:38 2017 : L2TP connecting to server ‘yyy.yyy.yyy.yyy’ (yyy.yyy.yyy.yyy)...

Mon Dec
4 18:59:38 2017 : IPSec connection started

Mon Dec
4 18:59:38 2017 : IPSec phase 1 client started

Mon Dec
4 18:59:38 2017 : IPSec phase 1 server replied

Mon Dec
4 18:59:39 2017 : IPSec phase 2 started

Mon Dec
4 18:59:39 2017 : IPSec phase 2 established

Mon Dec
4 18:59:39 2017 : IPSec connection established

Mon Dec
4 18:59:39 2017 : L2TP sent SCCRQ

Mon Dec
4 18:59:59 2017 : L2TP cannot connect to the server

I know the timestamps don't match, but I tried many times to connect and just could not find matching times anymore.

But this does not always happen. Sometimes I try to connect and it just works. When I disconnect and try again 5 minutes later it times out again.

Where to start looking for what causes this? It's not very practical to ask for my wife's computer or dig out the old MacBook Pro every time I need to do something on one of my office computers...

Thanks,

Arjen

MacBook Air (13-inch, Early 2015), macOS Sierra (10.12.6)

Posted on Jan 4, 2018 9:41 AM

Reply
Question marked as Top-ranking reply

Posted on Jan 4, 2018 10:18 AM

Are all the clients and servers on the same two networks, or are different networks in use for some of the VPN connection tests?


Make sure both ends of the VPN are not in the same subnet. I avoid the two lowest /24 subnets and the address range 192.168.0.1 to 192.168.1.254 as those two /24 subnets are in common use in homes and coffee shops and hotels, and VPNs do not work well when both ends of the connection are in the same subnet. Other subnets in the rest of the 192.168/16 private block are a better choice, as can be subnets elsewhere in the 172.16/12 and 10/8 private blocks.

6 replies
Question marked as Top-ranking reply

Jan 4, 2018 10:18 AM in response to arjena

Are all the clients and servers on the same two networks, or are different networks in use for some of the VPN connection tests?


Make sure both ends of the VPN are not in the same subnet. I avoid the two lowest /24 subnets and the address range 192.168.0.1 to 192.168.1.254 as those two /24 subnets are in common use in homes and coffee shops and hotels, and VPNs do not work well when both ends of the connection are in the same subnet. Other subnets in the rest of the 192.168/16 private block are a better choice, as can be subnets elsewhere in the 172.16/12 and 10/8 private blocks.

Jan 4, 2018 11:16 AM in response to arjena

You're going to have to hunt for any potentially subtle differences in the VPN configuration and settings among the client systems, and for any differences in the installed software and particularly any add-on security or networking or kernel-modifying packages (remove any that might be present, as a test), and see if the VPN can be established from either a clean Sierra installation on a USB device or from a restored copy of a working installation from one of the other Macs restored on a bootable device and booted from the problematic MacBook Air

Jan 4, 2018 12:27 PM in response to arjena

Try booting from one of the other devices' disks temporarily, and see if that works. I'm not referring to a wholesale reinstallation of the existing macOS boot device, but booting from an external copy of macOS from the App Store or from one of the other local systems. That'll tell you if there's a local issue with the software or (unlikely, but possible) a more general problem with the hardware. As for recreating the configurations, I've yet to have to reload a system. Adding a test VPN configuration works, and removing and re-adding problematic VPN configurations has always been enough to resolve problems. Among the worst cases I've encountered (and these are rare, and usually older releases), a reboot resolved the network wackiness. Not needed a reinstallation.


And in more recent times, I've found VPN profiles handy for some of this stuff. For adding and removing VPN definitions across Apple devices. The Apple Configurator 2 tool is free from Apple, and helps set up a VPN profile as Apple devices tend to prefer it. (That's not always the way that an arbitrary VPN server is always configured, but it's usually possible to get the VPN server configured to allow Apple devices access. Most folks with VPN servers have details published on that, too. And yours already works with some Apple devices, so that's not likely a factor here.)


This first tutorial refers to iOS devices https://www.howtogeek.com/216137/create-a-configuration-profile-to-simplify-vpn- setup-on-iphones-and-ipads/ but the profiles now work with macOS.


Related tutorial...

https://help.netmotionsoftware.com/support/docs/MobilityXG/1130/help/mobilityhel p.htm#page/Mobility%20Server/setup.03.44.html


Profile details...

https://developer.apple.com/library/content/featuredarticles/iPhoneConfiguration ProfileRef/Introduction/Introduction.html

Jan 4, 2018 10:26 AM in response to MrHoffman

Thanks for replying and trying to help figure this out.

All clients are on the same network, the server is on another. At home I use the 192.168.0.x range, at the office 192.168.1.x.

While I am typing this message I have both my wife's MacBook Air and my own in front of me. Both are on WiFi, run on the same system software (Sierra 10.12.6) and get their IP from my routers DHCP server.

My MacBook Air will not connect, my wife's connects without a problem every try.

Beats me...

Jan 4, 2018 12:11 PM in response to MrHoffman

Which is of course exactly what I'm trying to avoid ;-).

I just cannot stand the fact that I don't remember when this started. Was it after a system update? After another software install or update? I just don't know. The oldest entry in var/log/ppp.log is from sept 24, the oldest mention of 'L2TP cannot connect to the server' is from dec 4th. On dec 2 and 3 I logged in several times without a problem. But I'm pretty sure I did not alter anything on my computer that day or even that week. Too busy with other things.

I'm just hoping somebody can point me to a log file hidden somewhere that tells me what's going wrong.

But I guess I already know better. If I can find the time I will do a clean install. Until then I'll just have to learn to live with it.

Thanks again,


Arjen

Jan 4, 2018 12:55 PM in response to MrHoffman

Thanks for the links. I'll have a look at profiles.

I realise did not yet tell what I already tried to resolve my problems. Of course I already deleted the VPN configuration from my Mac and recreated it from scratch (more than once...). Not too difficult, but not much of a resolution either. As were rebooting, zapping Pram, deleting all repairing permissions and such.

Of course for the last two hours connecting works every time I try, so booting from another device's disk will only make me wiser if I do so for several days or longer. Nothing is as difficult to resolve as a problem that is not always there...

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

all computers can login to vpn, except one.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.