Bug ID 666454: Edge client on Macbook Pro with touch bar cannot connect to VPN after OS X v10.12.5 update

Last Modified: Jul 13, 2024

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.5.4, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4, 11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5, 11.6.0 HF6, 11.6.0 HF7, 11.6.0 HF8, 11.6.1, 11.6.1 HF1, 11.6.1 HF2, 11.6.2, 11.6.2 HF1, 11.6.3, 11.6.3.1, 12.0.0, 12.0.0 HF1, 12.0.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1

Fixed In:
13.1.0, 12.1.3, 11.6.3.2, 11.5.5

Opened: May 24, 2017

Severity: 2-Critical

Related Article: K05520115

Symptoms

Edge client running on Macbook Pro 2016 with a touch bar interface cannot connect to VPN in a full tunneling configuration with 'Prohibit routing table modification' option selected. Edge client's svpn.log shows an error entry similar to 2017-05-18,13:55:17:000, 16637,16638,svpn, 1, , 870, CMacOSXRouteTable::UpdateIpForwardEntry2(), EXCEPTION - write failed, 22, Invalid argument.

Impact

VPN connection will fail.

Conditions

This occurs when all of the following conditions are met: 1) Edge client is running on Macbook Pro that has the iBridge interface (e.g., one with the touch bar). 2) VPN is configured in full tunneling configuration 3) Mac OS X version is v10.12.5. Note: You can find the interface on the Macbook Pro in the Network Utility under the Info tab.

Workaround

Use one of the following workarounds: - Disable 'Prohibit Routing table change' in the network access configuration. - Enable 'Allow access to local subnets'. - Enable a split tunneling configuration.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips