Installation Guides (MacOS) VPN for Mac For using VPN on Mac you have to install the Sophos Client Authentication Agent and the FortiClient! For both you need to Device to connect with LAN cable inhouse! I'm not sure if the FortiClient needs the Sophos Client Authentication Agent! But for security reason we need the Sophos Endpoint Protection Software: Sophos Endpoint Protection Download zip-file from smb://vogelwarte.ch/dfs/ Teamwork/IT/SophosInstall.zip Install the Sophos Installer.app Follow this guide to enable all required permissions for Sophos: https://docs.sophos.com/central/customer/help/en-us/PeopleAndDevices/ProtectDevices/EndpointProtection/MacSecurityPermissions/index.html#grant-permissions-for-scanning-and-web-protection FortiClientVPN Installation Download the VPN client software: FortiClient Onlineinstaller / Updates. Install it - Zertifikat should be automatically installed (or not needed) You need to allow in the System Settings following entries: Switch off all Inhouse Network LAN and also WLAN "Vogelwarte" or "VoWa_public" FortiClient uninstall The problem is that the Uninstaller is only working if FortNet is not running. You have to run the MacOS in the Safe Mode Safe Mode procedure Shutdown Press Power Butten for long time till "System ..." appears Press on "HardDrive" symbol Press on Shift and then the "click"-button changes to "...start into Safe Mode..." The system starts into the safe mode Now you can run the "Uninstaller" Reboot the machine Configure the network for VPN For various internal services, e.g. QGIS plugins, a standard domain vogelwarte.ch must be specified in the network settings. Go to the Network details Select DNS on the left side In Search Domains add vogelwarte.ch. You have to press + on the bottom of the listbox. Problem after Active Directory (Windows/entra) Password change When I changed my ActiveDirectory password on the MacOS - everything worked. OK, I had to give the new password on serveral Online Services from Microsoft365 and I've to restart my Teams and so on... But one problem on MacOS keept me a little bit stocked. The passwords on MacOS are stored in the Keychain Access Tool and is encrypted with the AD password and this is not changed automatically - so you have to change it manually: Type into a Terminal: security set-keychain-password And you have to enter the old and then the new Active Directory Password.