MacOS VPN architecture from System Preferences down to nesessionmanager
blog.timac.org
blog.timac.org
For example, even though you can create a basic IKEv2 config, most of the parameters that are needed to actually make it work with a given router are not accessible except in Configurator. You cannot configure the encryption or hash algos, DH Group, group identifiers, etc.
And there is no access at all to other VPN types, such as a number of vendor-specific options, custom SSL, etc., even though they are supported.
Why can't there be advanced options for this stuff? It makes no sense.
1. You navigate your device to the MDM web portal served from the Mac running Server.app;
2. the MDM portal recognizes your MAC address as a new device, and allows you to register it;
3. an MDM profile is auto-generated for you, which you download and install;
4. the MDM profile transparently manages/updates a real (Apple Configurator) profile, which has been customized by the MDM for any settings keyed specifically to your computer's MAC address.
Using Apple Configurator without MDM, just using Configurator .profile files, would be like using Windows Group Policy without Active Directory, just using GPO .cab files. It's possible, but just kinda silly.
I totally agree. But let's say that I setup an IKEv2 server in pfSense on some VPS. And now I want to connect to that with my macOS VM. There's no Mac server anywhere involved. And Apple Configurator is in fact the only way to configure the macOS client.
And I understand MDM perfectly well. I am the CIO of a company with 350 Macs managed through JAMF. Also, nobody in enterprise who knows what they are doing uses Mac Server. It's been a toy and a joke ever since Mavericks.
But what if I need a VPN connection for somewhere else? What if I'm a consultant with a Mac and trying to connect to a Windows shop?
Why silly? In one .mobileconfig file, I created complex VPN config for my provider, with my own preferences, and loaded it without any MDM, to all my macs and iPhones.
Much easier to just leave Server.app running on my iMac. (It's basically what Server.app is built for; it's certainly not targeted at enterprises!)
What if I'm a consultant, with a Mac, and I need to access a client's VPN? They aren't going to change their router just for me, and they aren't going to provide me an MDM profile.
The fact that opaque configuration makes it harder for randos to get temporary access to VPNs does not seem like a hardship from my vantage point of managing security teams.
It seems like some of these, such as encryption, hash algorithm, and DH group, should be configured on the server side, not the client side. I know that in the IPSec world the peers are roughly equal, but in this scenario the Mac is definitely playing the role of client. Likewise, there is no ability to configure the traffic selectors, and I'd argue that there probably shouldn't be.
I agree that there should be more configuration exposed in the UI though.
EDIT: I spent about a half hour trying, unsuccessfully, to configure an IKEv2 connection on MacOS to a StrongSwan server. I suspect a configuration problem on the StrongSwan side, but the MacOS side is so opaque that it makes it hard to match up the configs properly.
EDIT2: I remember why I stopped trying to get IKEv2 working - the fact that Split-DNS is not in the protocol yet, but with IKEv1 I can use the Cisco Unity extensions to do it.
However, with a Mac you are most likely using the VPN in a roadwarrior scenario. In this case, I'd argue that one of the peers should decide on what encryption, authentication, etc should be used and the other peer (the roadwarrior Mac, in this case) should accept it.
In server-to-server or network-to-network scenarios, configuring both peers to match makes sense.
The goal of proposals in not matching - it is finding minimum security both sides agree on. I would not accept it, if previously strong settings were suddenly downgraded. I, roadwarrior, have same rights and requirements as any server :)
I can't imagine why they've done this. I suppose that it makes sense for enterprises that setup employees' devices. But if I'm using some third-party VPN service, it's a pain. And it's a special pain if I'm not using the latest macOS release, because then there's no way to install Apple Configurator!
Or an app. But it works fine without installing 3p app, more secure.
Server install is fully automated, spits out profile files that install and work clientside on both iOS and OS X.
More specifically, it is L2TP over IPSec on MacOS and iOS devices.
Tunnelblick and http://www.pivpn.io/ work great. PiVPN targets Pi installations, but I found it works just fine on any modern ubuntu install. The cli tools to generate / revoke configs are very easy to use.
I wish there were so that I can have one for iOS, but I've been using OpenVPN easily since long enough on macOS that the alternatives always seem terribly cumbersome and brittle.
I've been meaning to try tinc since forever, but it won't integrate with Apple clients either.
For anyone who is reasonable at *nix configuration, setting up OpenVPN, IKEv2 or classic IPSec tunnels is not 'easier' than any SSL/TLS VPN, which makes it lose a lot of it's value vs. other VPN options.