Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What is correct Policy for Mac OS X VPN ?

I'm trying to prepare my SF box for remote access. I successfully configured it for SSL VPN (OpenVPN) and surprisingly Cisco IPSec (on iOS 9 device). But I wan't my Mac to connect without OpenVPN using either L2TP or IPSec options.

Unfortunately I can't figure out what policy should be chosen for Apple OS X 10.11 VPN client (it is racoon based). I'm geting: "EST-P1: System did not accept any proposal received." in both "IPSec" and "L2TP" SF VPN modes.

Anyone succeeded connecting OS X to SF XG ?



This thread was automatically locked due to age.
Parents
  • Slawek - I think I found something that will help: kb.cyberoam.com/default.asp.  There is a VPN configuration guide for OS X: http://kb.cyberoam.com/default.asp?SID=&Lang=1&id=2914 and a .pdf available for download with instructions.  The guide is for a different gui, but the steps are very similar to XG.

    I was at a location where I couldn't use the Cisco VPN config I listed below, so I tried out an L2TP configuration. I was continually getting an error that no active connection is defined ... it was as if I hadn't defined a connection in XG.

    The instructions on the cyberoam site show that I have to go to System > VPN > L2TP and click the red dot under "active" ... it was not obvious to me in the GUI, but I clicked it and the dot turned green. I assume that means that there is now an active connection defined.

    I tried the connection and it now works with L2TP from OS X 10.11.2 with the built-in VPN client.

    *suggestion for Sophos* -> modify the GUI under System > VPN > L2TP to make it more obvious that the red dot is something that needs to be clicked to enable the connection.  As it is now, it appears to be a status light rather than an enable button to me.

  • It finally worked. But I still don't know why it was not working the first time since as i looked at the KB they haven't provided anything I had already tried. I the meantime OS X 10.11.2 arrived... maybe they patched something... who knows? Now I have yet to try to configure raw IPSec connection :)

    Regards,
    Slawek

Reply
  • It finally worked. But I still don't know why it was not working the first time since as i looked at the KB they haven't provided anything I had already tried. I the meantime OS X 10.11.2 arrived... maybe they patched something... who knows? Now I have yet to try to configure raw IPSec connection :)

    Regards,
    Slawek

Children
No Data