Great article. Just 2 small steps of advice are missing for anyone on a Mac Big Sur.
I couldnt connect from Mac OSX Big Sur and these steps fixes it …
I was getting this error: “DH group MODP_2048 inacceptable, requesting MODP_1024”. It was an issue with the ike settings in ipsec.conf. The “3des-sha1-modp1024!” restricts the algorithm to one that isnt used by default on Mac OSX Big Sur. After removing that and replacing 1024 algorithms with “aes256-sha1-modp2048,aes128-sha1-modp2048,3des-sha1-modp2048” that error disappears
Mac Big Sur will not trust certificates automatically in Keychain. Find the cert in Keychain Access, double click and set the cert to always trust.
Hope this helps.
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.