We are experiencing an issue with internet connectivity when using the Azure VPN client on macOS to connect to a Virtual WAN Point-to-Site (P2S) VPN gateway.
Issue Details:
Environment:
- Virtual WAN with Point-to-Site VPN gateway configured for forced tunnelling.
- Azure Firewall is used to allow and control internet access for VPN traffic. macOS Client Behaviour:
- The client can successfully RDP into a Virtual Machine located in a spoke VNet connected to the Virtual Hub.
- However, the macOS client cannot access the internet. The VPN client statistics on macOS show zero bytes of inbound traffic, despite outbound traffic being routed to the Azure Firewall.
- Azure Firewall logs show that rules are being triggered, indicating that traffic is reaching the firewall, but no return traffic is coming back to the macOS client.
- Windows Client Behaviour:
- The same Azure VPN client, when installed on a Windows machine, connects to the VPN without issues and has full internet access.
- The Windows client shows expected inbound and outbound traffic stats, with internet connectivity functioning normally.
Troubleshooting Steps Taken:
- Verified that both the macOS and Windows VPN clients are subject to the same network and firewall rules.
- Confirmed that RDP and other internal network access work correctly on macOS, but internet access does not.
- Compared routing tables and DNS settings between macOS and Windows clients, finding no apparent discrepancies that would cause this issue.
- No firewall logs indicate that return traffic is being blocked for the macOS client.
We would like assistance in diagnosing and resolving why internet traffic is not functioning on macOS when connected to the Azure Virtual WAN P2S VPN gateway, despite similar setups working on Windows. Specifically, we need to understand why the macOS client shows zero inbound traffic and cannot access the internet while other functionalities (like RDP) work correctly. We are experiencing an issue with internet connectivity when using the Azure VPN client on macOS to connect to a Virtual WAN Point-to-Site (P2S) VPN gateway.