# Installation Guides (MacOS)

# VPN for Mac

For using VPN on Mac you have to install the Sophos *Client Authentication Agent* and the *FortiClient*! For both you need to Device to connect with LAN cable inhouse!

I'm not sure if the FortiClient needs the Sophos Client Authentication Agent! But for security reason we need the Sophos Endpoint Protection Software:

### Sophos Endpoint Protection

1. Download zip-file from `smb://vogelwarte.ch/dfs/` *Teamwork/IT/SophosInstall.zip*
2. Install the Sophos Installer.app
3. Follow this guide to enable all required permissions for Sophos: [https://docs.sophos.com/central/customer/help/en-us/PeopleAndDevices/ProtectDevices/EndpointProtection/MacSecurityPermissions/index.html#grant-permissions-for-scanning-and-web-protection](https://docs.sophos.com/central/customer/help/en-us/PeopleAndDevices/ProtectDevices/EndpointProtection/MacSecurityPermissions/index.html#grant-permissions-for-scanning-and-web-protection)

### FortiClientVPN Installation

1. Download the VPN client software: [FortiClient Onlineinstaller / Updates](https://www.fortinet.com/support/product-downloads#vpn).
2. Install it - Zertifikat should be automatically installed (or not needed)
3. You need to allow in the *System Settings* following entries:
4. Switch off all Inhouse Network LAN and also WLAN "Vogelwarte" or "VoWa\_public"

### FortiClient uninstall
The problem is that the Uninstaller is only working if FortNet is not running. You have to run the MacOS in the Safe Mode

#### Safe Mode procedure
1. Shutdown
2. Press Power Butten for long time till "System ..." appears
3. Press on "HardDrive" symbol
4. Press on Shift and then the "click"-button changes to "...start into Safe Mode..."
5. The system starts into the safe mode
6. Now you can run the "Uninstaller"
7. Reboot the machine

# Configure the network for VPN

For various internal services, e.g. QGIS plugins, a standard domain **vogelwarte.ch** must be specified in the network settings.

   
[![Screenshot 2025-08-14 at 09.36.36.png](https://wiki.vogelwarte.ch/uploads/images/gallery/2025-08/scaled-1680-/screenshot-2025-08-14-at-09-36-36.png)](https://wiki.vogelwarte.ch/uploads/images/gallery/2025-08/screenshot-2025-08-14-at-09-36-36.png)

1. Go to the Network details
2. Select DNS on the left side
3. In **Search Domains** add `vogelwarte.ch`. You have to press **+** on the bottom of the listbox.

# Problem after Active Directory (Windows/entra) Password change

When I changed my ActiveDirectory password on the MacOS - everything worked. OK, I had to give the new password on serveral Online Services from Microsoft365 and I've to restart my Teams and so on... But one problem on MacOS keept me a little bit stocked. 

The **passwords** on MacOS are stored in the **Keychain Access** Tool and is encrypted with the AD password and this is not changed automatically - so you have to change it manually:

Type into a Terminal:
```bash
security set-keychain-password
```

And you have to enter the **old** and then the **new** Active Directory Password.