Hi Tom,

I installed OS X 10.8.1 (Mountain Lion) and saw the same problem as you.  I 
discovered the 'fix', actually just more security hurdles by Apple.

As mentioned here: "IPsec VPN for Apple iOS & OS X"
http://doc.astlinux.org/userdoc:tt_ipsec_vpn_apple_ios

It shows to File -> Get Info on the ca.crt, an make "Always Trust" for "When 
using this certificate"... I assume you did that already.

For OS X 10.8, you need to do the same thing for the client certificate, File 
-> Get Info for client certificate, then click "Access Control"

<<inline: os-x-10.8-access-control.jpg>>


Then select "Allow all applications to access this item" (as shown above).  The 
{ Save Changes } and follow the prompts.

Cisco IPsec now works.  If anyone knows a more specific access control please 
comment.

You can view the logs from racoon in the system log by:

$ sudo tail -n50 /var/log/system.log

Let me know if this works for you.

Lonnie

PS:  Thanks for testing Window 7, good to know that also works.



On Sep 12, 2012, at 2:52 PM, Tom Mazzotta wrote:

> FYI, I was able to successfully connect using the Cisco VPN client
> (v5.0.07.0440) running under a Windows 7 (Fusion) VM on my Mac. I used the
> same CA and person cert's I had generated for OSX. I guess Mountain Lion
> is just a Bear in this case :)
> 
> On 9/12/12 2:42 PM, "Tom Mazzotta" <tmazzo...@titanmicro.com> wrote:
> 
>> I thought I did, and I just restarted IPsec again now and tried to
>> connect with the same negative results. Let me know how you make out
>> after upgrading to Mountain Loin. BTW, has anyone tried Cisco's VPN
>> client running on Windows?
>> 
>> tm

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Astlinux-users mailing list
Astlinux-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/astlinux-users

Donations to support AstLinux are graciously accepted via PayPal to 
pay...@krisk.org.

Reply via email to