Complete Mac VPN Setup Guide: Built-in vs Third-Party Apps

16 min read

Switching to Mac is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

Setting up a VPN on a Mac can feel confusing if you’re used to downloading a Windows app and clicking Connect. macOS offers two routes: its built-in VPN client or the provider’s app. Your VPN provider or network administrator will usually tell you which one to use.

This guide covers manual setup, imported files, and commercial VPN apps. You’ll also test the connection. A green “Connected” label doesn’t prove your traffic is taking the right route.

What Is macOS VPN?

macOS has a built-in VPN client. It can connect your Mac to compatible work, school, self-hosted, or commercial VPN servers. Apple doesn’t include a free consumer VPN server network with your Mac.

The built-in client manages the connection. A consumer VPN service supplies the servers and account, usually through its own app. Current macOS settings support IKEv2, L2TP over IPSec, and Cisco IPSec. Apple no longer supports the old PPTP protocol.

iCloud Private Relay doesn’t replace a VPN. This iCloud+ feature helps hide Safari browsing activity and related traffic. It doesn’t cover your whole Mac or provide workplace access, server controls, or selectable locations.

Prerequisites

Make sure you have:

  • A Mac running macOS 13 Ventura or later
  • A working internet connection
  • Administrator access if an app needs a network extension
  • The VPN protocol, server address, and account name for manual setup
  • The password, shared secret, certificate, Remote ID, or Local ID required by the connection
  • A trusted .vpn or .mobileconfig file if importing a configuration
  • An active provider account if using a third-party app
  • A backup way to contact your workplace IT team or VPN provider
RequirementDetails
DeviceAny Intel or Apple silicon Mac supported by your macOS release
OS versionmacOS 13 Ventura or later; provider apps may have different requirements
Manual setupExact connection details from an administrator or provider
App setupAn account and the provider’s official macOS installer
Time requiredAbout 10-20 minutes

To check your version, choose Apple menu > About This Mac. You can also open Applications > Utilities > Terminal and run:

sw_vers

Expected result: Terminal shows the macOS product name, version, and build number. Compare that version with the provider’s compatibility page before downloading its app.

Step-by-Step Guide

Step 1: Choose the Right Setup Method

Use manual setup when an administrator gives you exact IKEv2, L2TP over IPSec, or Cisco IPSec settings. You can also use it when a compatible provider supplies manual connection details.

Import a configuration when the administrator supplies a .vpn or .mobileconfig file. Importing reduces the chance of typing errors. It also keeps the intended login and routing settings.

Choose a third-party app for a consumer VPN, public Wi-Fi use, or quick server changes. Provider apps are often easier for streaming, but no VPN can promise access to a given service.

Expected result: You’ve chosen the import, manual, or provider-app route below.

Step 2: Collect the Manual Connection Details

Before opening Settings, ask your administrator or provider for:

  • VPN type: IKEv2, L2TP over IPSec, or Cisco IPSec
  • Display name
  • Server address
  • Account name
  • Password or certificate
  • Shared secret, if required
  • Remote ID and Local ID for IKEv2, if required
  • Whether all traffic should use the VPN
  • Any special DNS, proxy, or connect-on-demand settings

Don’t guess a Remote ID or use your normal password as a shared secret. These values have different jobs, even though the form makes them look similar.

Warning: Never publish or share screenshots containing real server addresses, usernames, passwords, certificates, shared secrets, public IP addresses, or organization names.

Expected result: You have every required value exactly as IT or the provider supplied it.

Step 3: Import a Supplied VPN Configuration

If you received a trusted configuration file, use it instead of rebuilding the connection by hand.

  • Save the .vpn or .mobileconfig file somewhere familiar, such as Downloads.
  • Choose Apple menu > System Settings > Network.
  • Click the three-dot Action menu.
  • Select Import Configurations.
  • Select the supplied file, then click Import.
  • Follow the macOS prompts to finish adding the configuration.

You can also double-click a compatible file in Finder. A .mobileconfig file may send you to Apple menu > System Settings > Privacy & Security > Profiles for review and installation.

Current System Settings Network page with the three-dot Action menu open and Add VPN Configuration and Import Configurations highlighted

Install only a profile you expected to receive. Configuration profiles can control more than the VPN. If macOS mentions device management or unknown settings, stop and check with the sender.

Expected result: The imported service appears under System Settings > VPN. If it’s missing, ask the sender whether the file supports your macOS release.

Step 4: Start a Manual VPN Configuration

Skip this step if you imported a configuration.

  • Choose Apple menu > System Settings.
  • Select Network in the sidebar.
  • Click the three-dot Action menu.
  • Point to Add VPN Configuration.
  • Choose the protocol specified by your administrator: IKEv2, L2TP over IPSec, or Cisco IPSec.
Add VPN Configuration submenu showing IKEv2, L2TP over IPSec, and Cisco IPSec, with a note that the selection must match the supplied instructions

Older guides may mention System Preferences > Network and a plus button. On macOS 13 Ventura and later, use the three-dot Action menu instead.

Expected result: macOS opens a form for the selected protocol.

Step 5: Configure an IKEv2 Connection

For IKEv2:

  • Enter a clear Display Name, such as Work VPN.
  • Enter the supplied Server Address.
  • Enter the supplied Remote ID. It may differ from the server address.
  • Enter Local ID only if your administrator supplied one.
  • Open Authentication Settings.
  • Select the required authentication method, such as a username or certificate.
  • Enter the supplied account details.
  • Click Create or OK, depending on your macOS version.
IKEv2 configuration form showing Display Name, Server Address, Remote ID, Local ID, and authentication controls, with every sensitive value redacted

The Remote ID causes many failed connections because it often looks like the server address. Copy the given value exactly. Don’t swap these fields.

Expected result: The IKEv2 service appears as a reusable VPN connection in System Settings.

Step 6: Configure L2TP over IPSec or Cisco IPSec

For L2TP over IPSec:

  • Enter the Display Name, Server Address, and Account Name.
  • Open Authentication Settings.
  • Enter the user password and shared secret, or select the certificate method specified by the administrator.
  • Review advanced options only if you received exact instructions.
  • Click Create or OK.
L2TP over IPSec configuration and authentication controls with Account Name highlighted and password and shared-secret fields hidden

For Cisco IPSec, enter the server, account, group, shared secret, or certificate details exactly as provided. The fields you see depend on the chosen login method.

L2TP over IPSec remains available for compatibility. However, many current services prefer IKEv2 or a protocol in their own app. The protocol must match the server, so don’t choose one because its name looks familiar.

Expected result: The service appears under System Settings > VPN without an error badge.

Step 7: Review Routing and Connection Options

Select the new service under System Settings > VPN, then open its details.

Possible settings include:

  • Connect on demand: Starts the VPN when matching rules require it.
  • Send all traffic over VPN connection: Routes general internet traffic through the tunnel when the setup allows it.
  • DNS: Controls the servers that translate domain names.
  • Proxies: Sends supported traffic through a separate proxy.
  • TCP/IP: Contains network address options.

Leave DNS, proxy, TCP/IP, and routing values alone unless your administrator gives you exact settings. Extra changes can cause trouble. One wrong DNS address can leave the VPN connected while every website fails to load.

A workplace VPN may use split tunneling by design. Company traffic enters the VPN, while normal internet traffic uses your usual connection.

Expected result: The configuration matches the supplied instructions and contains no guessed values.

Step 8: Connect and Disconnect in System Settings

  • Open Apple menu > System Settings > VPN.
  • Find the configured service.
  • Turn on its connection switch or click Connect.
  • Enter a password if requested.
  • Wait for the status to change to Connected.
System Settings VPN page showing a configured service row and its connection control, with identifying service names redacted

If you’ve been staring at the spinning connection indicator for 10 minutes, don’t panic. A working connection usually completes within seconds. Disconnect, check the server and login details, then try once more.

To disconnect, return to System Settings > VPN and turn off the service. Some setups also add a VPN status control to the menu bar.

macOS menu-bar VPN status interface showing the connect and disconnect control without unrelated menu-bar details

Expected result: macOS reports that the service is connected and shows an active status indicator.

Step 9: Choose a Reputable Third-Party Provider

If manual setup doesn’t meet your needs, check each provider before installing its app.

Look for:

  • A clear privacy and no-logs policy
  • Independent audits or court-tested evidence where available
  • A plain explanation of stored diagnostic and account data
  • Clear ownership and contact details
  • Recent macOS release notes
  • Support for your exact macOS version and Mac processor
  • Clear details about the kill switch, DNS, protocols, and auto-connect
  • A refund policy you can check before subscribing

A “no-logs” slogan proves little by itself. Check what the policy excludes and how long the company keeps limited data. Also check whether an audit covers the current apps and server systems.

For example, NordVPN’s support page says its latest app needs macOS 12 or newer. That rule applies only to NordVPN. Check the support page for any other provider.

Expected result: You’ve selected a provider whose privacy terms, Mac support, and connection controls suit your needs.

Step 10: Download and Install the Provider App

  • Visit the provider’s official website or verified Mac App Store listing.
  • Confirm that the page names your supported macOS version.
  • Download the Mac app. Avoid unofficial mirrors and sponsored download buttons on unrelated sites.
  • If you downloaded a .dmg, double-click it in Finder.
  • Drag the provider app into Applications when prompted.
  • Open Finder > Applications, then double-click the app.
  • Sign in with your provider account.

For an App Store version, open the listing, click Get, and then click Install. The process feels much like installing an iPhone app. macOS may ask for your Apple Account password or Touch ID.

Some providers have separate App Store and website builds. Their protocols or connection tools may differ because of App Store rules. Read the provider’s guide before choosing a build.

Expected result: The app opens and displays its main connection screen.

Step 11: Authorize the VPN Configuration and Components

The first time you connect, macOS may ask to add VPN configurations.

  • Confirm that the prompt names the provider app you installed.
  • Click Allow.
  • Authenticate with Touch ID or your Mac login password if macOS requests it.
  • If the app reports a blocked network or system extension, click Open System Settings.
  • Find the component bearing the expected provider or developer name.
  • Approve it, then return to the app.
Stable macOS System Settings section containing an expected VPN provider network or system component, with the component highlighted and no password, Touch ID, or sign-in dialog visible

This prompt can look alarming because the app wants permission to handle network traffic. Check the developer name carefully. Don’t approve an unknown component, even if the app pressures you to continue.

If the name doesn’t match the provider’s support guide, cancel and contact its support team.

Expected result: The app can create its VPN tunnel without showing a permission warning.

Step 12: Configure the Provider’s Protection Settings

Open the app’s Settings, Preferences, or gear menu. Review the controls it offers:

  • Automatic connection on untrusted Wi-Fi
  • Launch at login
  • VPN protocol
  • DNS protection or custom DNS
  • Local network access
  • Split tunneling
  • Kill switch
Stable provider app settings page showing its verified connection, protocol, DNS, automatic-connection, and protection controls without assuming any control is enabled

A kill switch limits open traffic when the VPN drops. Not every provider has one, and its behavior can vary. Some versions block all internet traffic. Others cover certain apps or work only after you start a VPN session.

Auto-connect is useful on public Wi-Fi, but it can block captive portal pages. If the Wi-Fi login page won’t appear, pause auto-connect. Finish signing in to the network, then reconnect the VPN.

Don’t assume the app sends all Mac traffic through its tunnel. Read the provider’s full-tunnel and split-tunnel guide, then test the result yourself.

Expected result: The app matches your preferred balance of protection, local-device access, and convenience.

Step 13: Connect Through the Provider App

  • Return to the app’s main window.
  • Choose a server location, or click Connect or Quick Connect.
  • Wait for the status to change to Connected.
  • Open Safari and load a normal website.
Stable third-party VPN app main window showing server selection and a Connect or Quick Connect control

For work resources, use your organization’s approved VPN. A random consumer server can’t give you access to private company systems.

For streaming, choose a server in the needed location. Access can change without warning, and no provider can promise permanent access to a streaming catalog.

Expected result: The app reports a successful connection and websites still load.

Step 14: Verify the VPN Connection

Test before and after connecting.

  • Disconnect the VPN.
  • Open IPLeak and note the displayed country and internet provider. Don’t share the exact IP publicly.
  • Connect the VPN.
  • Reload the page.
  • Confirm that the reported public IP or location changed as expected.
  • Run a DNS check at DNSLeakTest.
  • Confirm that the DNS results match the VPN provider’s documented behavior.
  • For a workplace VPN, open a required internal site or server.
Public IP and DNS test results after connecting, with exact IP addresses and identifying network values obscured
Completed standard DNS test with provider or location highlighted and identifying network values obscured

Don’t focus only on the country name. IP databases can report a nearby city or region. Check the provider name, changed public IP, DNS results, and access to required resources.

A work VPN with split tunneling may leave your public IP unchanged. Internal traffic can still use the VPN correctly. In that case, access to the required work resource is the useful test.

Expected result: The public IP, DNS behavior, and resource access match the VPN’s intended design.

Configuration

SettingRecommended approach
VPN typeUse the exact protocol supplied by IT or the provider
Connect on demandEnable only when you understand the connection rules
Send all trafficUse for full-tunnel protection when supported; workplace profiles may require split tunneling
DNSKeep the supplied or app-managed setting unless troubleshooting
ProxiesLeave off unless an administrator provides values
Kill switchCheck its scope and default state in the provider’s documentation
Local network accessEnable only if you need printers or other trusted local devices
Protocol selectionKeep the provider’s automatic choice unless support recommends another
Auto-connectUseful on public Wi-Fi, but it may affect captive portals and local devices

Manual setup works best for a known server with fixed access rules. It adds fewer components, but you’ll need to maintain the settings yourself.

A provider app is often easier for travel, public Wi-Fi, privacy, or changing locations. It manages server lists, protocols, and updates. That convenience means trusting another background app with your network traffic.

Tips and Troubleshooting

The VPN option or old plus button is missing

Why it happens: Older instructions use System Preferences and a plus button.

Fix: Open Apple menu > System Settings > Network, click the three-dot Action menu, and choose Add VPN Configuration. The VPN sidebar item may stay hidden until you create or import a service.

The manual VPN will not connect

Why it happens: The protocol, server, identity, certificate, password, or shared secret may be wrong.

Fix: Open System Settings > VPN, select the service, and compare every field with the supplied instructions. Remove extra spaces. Ask the administrator whether the account, server, or certificate has changed.

Copy and paste can add a trailing space that’s hard to see. If a field looks correct but still fails, clear it and type the value again.

The app says its extension is blocked

Why it happens: macOS requires approval before some network components can run.

Fix: Use the app’s Open System Settings button. Approve only the component that matches the expected provider, then restart the app.

The VPN connects, but websites do not load

Why it happens: DNS, proxy, routing, another network filter, or a failed server may be causing trouble.

Fix: Disconnect and check that normal Wi-Fi works. Reconnect to another provider server. Restore custom DNS and proxy settings to their documented values. Quit other VPN or filter apps, then restart the Mac if needed.

A Connected label only means macOS created the tunnel. It doesn’t prove that DNS works or that the remote server can reach the internet.

Workplace resources remain unavailable

Why it happens: A required route may be missing. Your home network may also use the same private address range as the workplace.

Fix: Test from another Wi-Fi network or a phone hotspot. Tell IT which internal resource fails and ask for corrected routing or a new configuration. Don’t add Terminal routes unless IT gives you exact commands.

This conflict often occurs when both networks use ranges such as 192.168.1.x. A phone hotspot is a quick test because it usually assigns a different local range.

Printers disappear while connected

Why it happens: The VPN may block local network traffic or route everything through its tunnel.

Fix: Look for a documented Local Network Access, LAN Access, or split-tunneling setting. On a managed work VPN, ask IT whether local access is allowed.

Local access makes printers and network storage available again, but it reduces isolation from the local network. I’d leave it off on public Wi-Fi.

The connection keeps dropping

Why it happens: Weak Wi-Fi, server load, sleep and wake, protocol issues, or security software can break the tunnel.

Fix: Test the connection without the VPN, move closer to the router, and try another server. Update macOS through Apple menu > System Settings > General > Software Update, then update the provider app. If the app offers documented protocol choices, try another supported option.

If drops happen only after the Mac wakes, quit and reopen the VPN app. Report ongoing wake problems to the provider. Include the macOS version shown by sw_vers.

Streaming still shows the wrong region

Why it happens: The selected server may not work with the service. The browser may also keep old cookies and location data.

Fix: Check the public IP and try another server in the intended location. Then reopen the browser or app. Clear the site’s cookies if needed. Follow the streaming service’s terms, and don’t expect guaranteed access.

Two VPN apps interfere with each other

Why it happens: Several profiles, filters, and network extensions can compete for traffic.

Fix: Disconnect every VPN, quit unused apps, and connect with one service only. Remove old items only after you confirm that you no longer need them.

Check Apple menu > System Settings > VPN for old configurations. Provider apps may also install filters or extensions. Deleting the app may leave those parts behind, so follow the provider’s uninstall steps.

Wrapping Up

StepActionApplies To
1Obtain settings or choose a providerAll setups
2Import or create the connectionBuilt-in client
3Install and authorize the appThird-party apps
4Connect and test IP, DNS, and resourcesAll setups

The built-in macOS client works well for connections supplied by work or an administrator. A trusted provider app makes server changes and daily use easier. Check its privacy evidence, Mac support, traffic coverage, and kill switch before relying on it.

Keep the original settings or installer details somewhere safe. If an update breaks the connection, you’ll know what macOS should use and what a successful test looks like.

For more information on Mac VPN not working or setting up a VPN on iPhone, visit our website. You can also learn about setting up a VPN connection on Mac or connecting your Mac to a VPN on Apple’s support website.