IKEv2 VPN not working on new M1 MBP, exact same config works on previous one

UPDATE: I managed to fix this. For reasons unknown my M1 Mac would only send 1 “security proposal” when connecting to the VPN, the 2019 one would send 5 - one of which included SHA1 and DES protocols. This was apparently what my Windows Server 2019 was using, which worked fine on Windows (typically) but not on Mac. Hardening the IKEv2 policy got it working on the new Mac.

These are the instructions I followed: Windows Server 2012R2 VPN IKEv2 hardening RRAS service | IT's a passion - good luck!

Hi,

Hoping someone might be able to help me with this one which has me completely puzzled.

I’ve been using an IKEv2 based VPN (to a Windows server) for years. I’m using the built in VPN client, with the following things configured:

I imported the .pfx certificate to my “login” store in Keychain Access, which adds vpn.company.co.uk and the server (e.g. vpnserver-CA) as certificates. I then set the server certificate to “Always Trust”.

When trying to connect on the new MBP the VPN instantly disconnects - with no error message. If I change the server address to nonsense it sits on “Connecting” for a bit longer before silently disconnecting.

I’m at a complete loss to understand what is going wrong here, or where to look in terms of fixing it, when the configuration on my Intel MBP is identical. I’m not running any kind of firewall or proxy on either computer.

A Cisco IPSec VPN to a different server (my backup one) works fine.

Thanks in advance for any help provided :slight_smile:

Here are the pertinent “Errors and Faults” from both machines:

2019 Intel MBP (connects): https://pastebin.com/7gVeaVu3

2021 Apple Silicon MBP (doesn’t connect): https://pastebin.com/AXhxf9cR

maybe you need to generate a new cert (via their website??). Often the certs are generated withyour mac serial or similar.

I have exact same issue with same error. Any solution?

Mac device and os:

Apple M1

13.2.1 (22D68)

Can you elaborate on “Hardening the IKEv2 policy got it working on the new Mac.”?

Thanks.

The certificate is from the VPN server (Windows Server 2019). It is for the FQDN for the VPN server, and the server itself (as a CA). This has been installed the same on both laptops :frowning:

Really sorry for the massive delay - these are the instructions I followed on our Windows Server 2019 VPN server:

After doing this I was able to connect my M1 Mac to the VPN. Windows clients needed the PowerShell command listed on that page.

Sorry, didn’t realise I didn’t include the link in my original post. How frustrating.

This is what I followed:

After doing this I was able to connect my M1 Mac to the VPN. Windows clients needed the PowerShell command listed on that page.