VPN access on 10.9?

Advanced feature discussion, beta programs and unsupported "Labs" features.
9 posts Page 1 of 1
by adamlang » Sat Nov 23, 2013 7:13 pm
Was recently forced to upgrade to 10.9 (so I could finish my iOS app!) and it appears that my VPN has stopped working. I had it set up the way you recommend on your Wiki for Lion, with the built-in VPN client rather than the Cisco one, but I have tried connecting from a couple of places that I'm fairly certain I could connect from before, including my home Fusion service, and it refuses to connect. ("The VPN server did not respond. Verify the server address and try reconnecting.")

I've tried creating a new VPN connector with the settings on the wiki page but it does the same thing.

Relevant log lines are here:
Nov 23 19:08:42 Portabullo.local configd[18]: IPSec connecting to server ipsec.vpn.sonic.net
Nov 23 19:08:42 Portabullo.local configd[18]: SCNC: start, triggered by (367) SystemUIServer, type IPSec, status 0, trafficClass 0
Nov 23 19:08:42 Portabullo.local configd[18]: network changed.
Nov 23 19:08:42 Portabullo.local configd[18]: IPSec Phase1 starting.
Nov 23 19:08:42 Portabullo.local racoon[314]: accepted connection on vpn control socket.
Nov 23 19:08:42 Portabullo.local racoon[314]: IPSec connecting to server 208.201.249.242
Nov 23 19:08:42 Portabullo.local racoon[314]: Connecting.
Nov 23 19:08:42 Portabullo.local racoon[314]: IPSec Phase 1 started (Initiated by me).
Nov 23 19:08:42 Portabullo.local racoon[314]: IKE Packet: transmit success. (Initiator, Main-Mode message 1).
Nov 23 19:08:42 Portabullo.local racoon[314]: >>>>> phase change status = Phase 1 started by us
Nov 23 19:08:42 Portabullo.local configd[18]: network changed.
Nov 23 19:08:46 Portabullo.local racoon[314]: IKE Packet: transmit success. (Phase 1 Retransmit).
Nov 23 19:08:49 Portabullo.local racoon[314]: IKE Packet: transmit success. (Phase 1 Retransmit).
Nov 23 19:08:52 --- last message repeated 1 time ---
Nov 23 19:08:52 Portabullo.local configd[18]: IPSec disconnecting from server 208.201.249.242
Nov 23 19:08:52 Portabullo.local racoon[314]: IPSec disconnecting from server 208.201.249.242
Nov 23 19:08:52 --- last message repeated 1 time ---
Nov 23 19:08:52 Portabullo.local configd[18]: network changed.
Nov 23 19:08:57 --- last message repeated 1 time ---

Anyone have any clues?
by bobrk » Mon Nov 25, 2013 12:24 pm
No clues other than it's working fine for me on 10.9 connecting to Sonic's VPN.

I'm using server address ipsec.vpn.sonic.net
by simx » Tue Dec 24, 2013 1:13 am
I'm having the same problem. On my Mac with OS X 10.9 Mavericks, using the recommended VPN settings, it's giving me the "VPN server did not respond" message. On my iPhone, on the same Wi-Fi network, with the same recommended settings using the built-in iOS 7 VPN client, the iPhone connects fine. Not sure why there would be a difference.

The VPN description page here <http://www.sonic.net/features/vpn/> says that "To use the VPN service provided by Sonic.net, you will need a Sonic.net account in good standing, and VPN client software that supports IPsec VPN, without PPTP, or L2TP." Are there alternative settings that allow connections via the L2TP protocol? If so, what are they? Maybe they would allow a 10.9 Mac to connect properly?
by adamlang » Wed Dec 25, 2013 9:00 pm
So here's an interesting observation: some places I can still connect to the VPN after upgrading to 10.9. Some places it worked on 10.7 but NOT 10.9. And some places it doesn't work with either. I assume the latter is because of specific blocked ports. But I have no idea why some places would work with 10.7 but not with 10.9, with the same VPN settings.
by virtualmike » Thu Dec 26, 2013 8:07 pm
Is it possible that one machine has a firewall that the other doesn't? Or the two are configured differently?

viewtopic.php?f=10&t=1484
by adamlang » Fri Dec 27, 2013 10:53 am
They're the same computer, just taken to different places.
by virtualmike » Sat Dec 28, 2013 12:04 am
One issue I've had with my iPad a couple of times is when it updated the O/S, it corrupted the VPN and networking settings. Deleting the settings and configuring from scratch (the wifi settings as well as the VPN) solved the problem.
by simx » Sat Dec 20, 2014 8:27 pm
This problem is still happening to me, a year later. Here are some additional details, though:

• On OS X 10.9.5, the error message has changed slightly. It now says, "The negotiation with the VPN server failed. Verify the server address and try reconnecting."

• If I put the wrong username in the VPN settings, the VPN client correctly prompts me for authentication (presents a username/password dialog). If I put an incorrect shared secret, it tells me "The VPN Shared Secret is incorrect." So it is clearly establishing a connection to the VPN server.

• On OS X 10.10 on the same Mac, the VPN connects correctly.

• I saw this thread <viewtopic.php?f=10&t=1484> and turned off the firewall manually by issuing the Terminal command `sudo pfctl -d`. No change to the VPN issue.

Anybody else have any suggestions? This will fast become an academic issue because soon I will move to 10.10 full-time, but I'm still using 10.9 for the moment.
by simx » Sat Dec 20, 2014 8:58 pm
I just figured it out, in case anybody is interested. I turned off "Back to My Mac" in iCloud System Preferences (on a random suggestion from user Alex.Rendon here: https://discussions.apple.com/thread/54 ... 0&tstart=0 ), and now the Sonic VPN works perfectly on Mavericks.
9 posts Page 1 of 1