6 ms·
MacOS VPN architecture from System Preferences down to nesessionmanager
- blacksmith_tb 8y agoInteresting - do I remember that macOS 10.12 (or maybe 10.13) was supposed to allow for per-app VPN access? Does that use this API, or something else (assuming it actually exists)? Also, quite the cliffhanger on VPNStatus, which sounds promising (any chance it could also support Wireguard?)
- pvg 8y agoThe Network Extension framework mentioned in the post is that API. It's been an iOS thing for a while and came to macOS more recently (10.12, I think).
- teilo 8y agoWhat boggles me about the VPN implementation on Mac is the massive amount of functionality that is not accessible unless you are using Apple Configurator to create a profile. Then you have to install the profile, and for any configuration change, you have to repeat the process. For example, even though you can create a basic IKEv2 config, most of the parameters that are needed to actually make it work with a given router are not accessible except in Configurator. You cannot configure the encryption or hash algos, DH Group, group identifiers, etc. And there is no access at all to other VPN types, such as a number of vendor-specific options, custom SSL, etc., even though they are supported. Why can't there be advanced options for this stuff? It makes no sense.
- pvg 8y agoAn opaque profile file that you double click and your VPN connectivity works makes as much, if not more sense for end users than endless screens of incomprehensible parameters.
- teilo 8y agoNo. There are plenty of setting an end user shouldn't normally poke around in, that are still accessible under something like an Advanced button, or are an Option-click away. This should be no different. What if I'm a consultant, with a Mac, and I need to access a client's VPN? They aren't going to change their router just for me, and they aren't going to provide me an MDM profile.
- tptacek 8y agoWhy wouldn't they provide you an MDM profile? Lots of companies have committed in writing to ensuring that anyone with access to prod is using an endpoint registered with MDM; that comes up on self-assessment questionnaires. The fact that opaque configuration makes it harder for randos to get temporary access to VPNs does not seem like a hardship from my vantage point of managing security teams.
- auslander 8y agoYou can do all that in Apple Configurator profile. For IKEv2, all crypto parameters, DH, for child SA too, perfect forward secrecy, connect on demand, EAP auth. Works for me, I use same profile for Mac and iOS.
- izacus 8y agoUmm, did you miss the point of the post you're answering to?
- auslander 8y agoYes. He wants a GUI for all possible options. I say no need, VPN providers can just provide mobileconfig file, or you can always make your own. Or an app. But it works fine without installing 3p app, more secure.
- sargun 8y agoDoes anyone know if there are any plans to standardize (d)TLS VPNs?
- oneplane 8y agoI highly doubt it. Most vendors try to sell it as an USP and as an "it is easy because it is TLS and runs over 443 so inflexible environments will allow you to work"-type of solution which is trying to fix symptoms instead of causes. For anyone who is reasonable at *nix configuration, setting up OpenVPN, IKEv2 or classic IPSec tunnels is not 'easier' than any SSL/TLS VPN, which makes it lose a lot of it's value vs. other VPN options.
- dguido 8y agoThis might be useful for Algo! It's been a pain in the ass that IKEv2 has been a second class citizen on macOS. https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- striking 8y agoAlgo already provides .mobileconfig files. Works great. https://github.com/trailofbits/algo#apple-devices https://github.com/trailofbits/algo#apple-devices
- closeparen 8y agoAre there any reasonably straightforward open source VPN servers compatible with Apple’s clients? For cloud and VPS setups, I always end up mucking around with OpenVPN/Tunnelblick.
- rz2k 8y agoI found SoftEther easy to install on a bargain VPS. Supposedly it has much better throughput than OpenVPN, but I am not certain that it has had enough scrutiny to insure that it as worthy of trust as OpenVPN. Since I don't really know anything about my bargain VPS provider either, I am not using it for great privacy, I just turned it on when I imagined there was suspicious throttling, which probably didn't exist anyway. (Getting the latest cable modem model from Comcast seemed to solve more of my latency issues than opening a VPN tunnel ever did.) More specifically, it is L2TP over IPSec on MacOS and iOS devices.
- pvg 8y agohttps://github.com/trailofbits/algo https://github.com/trailofbits/algo Server install is fully automated, spits out profile files that install and work clientside on both iOS and OS X.
- pilif 8y agoThe strongSwan configuration generated by pfSense works out of the box with macOS and iOS IKEv2 support in its default config. This has quickly become my VPN solution of choice as it works without a third party app, it’s extremely quick to connect and the connection is super stable.
- latchkey 8y agoI tried the OSX VPN stuff and gave up really quickly. It all just felt really clunky, without much control. Tunnelblick and http://www.pivpn.io/ http://www.pivpn.io/ work great. PiVPN targets Pi installations, but I found it works just fine on any modern ubuntu install. The cli tools to generate / revoke configs are very easy to use.
- auslander 8y ago
- dqh 8y agoIt's possible to build a macOS app that manages an IKEv2 connection using the public NEVPNManager, NEVPNProtocolIKEv2 and related APIs. This also gives you full control over DH group, algorithms, dead peer detection etc.