Android 12 and ikev2
All Replies
-
Hi @Peppino,
Thanks for feedback. We can refer to this FAQ to set up Strongswan in Android phone.
https://community.zyxel.com/en/discussion/12522/remote-access-vpn-wizard-for-secuextender-ipsec-and-non-secuextender-ipsec-vpn-clients#latest
1 -
Thanks Cooldia, I did not notice there is a whitepaper on this. :-)0
-
I'm trying to use the wizard to connect an android phone (samsung!) to an ATP with latest firmware, the firewall is under a router, I modified phase 1: in my address instead of "interface" i selected "domain name/IPv4" and entered my public (static) ip.
this is what i get on the firewall:
this is what i get from strongswan:
any help?
0 -
Is that same ip included in the certificate too?
0 -
update: i tried the same configuration on another firewall with the same firmware, the only difference is that the 2nd fw is not under NAT. In this case it works (same phone).
0 -
0
-
Well client VPN needs a fw exposed to a public IP. Hidden behind a NAT will obviously not work. The only exception is when this FW will act as a client to another one that has public IP, then they can build a tunnel between themselves.
0 -
actually the firewall it's not hidden: the ISP router is configured so that the Firewall ip (router lan / firewall wan) is in DMZ so that (theorically) all the traffic to the ISP router is redirected to the firewall.
I suppose that in this scenario one's able to connect via VPN, am I wrong?
0 -
If the certificate says a IP then the fw needs to have that IP and be WAN
for IPsec identifier on phone need to be:
ikev2
for IPSec pershared key
0 -
With strongswan I was able to setup on Zywall 110 a IKEv2 certificate VPN with a DNS by no-ip
0
Categories
- All Categories
- 347 Beta Program
- 2.1K Nebula
- 114 Nebula Ideas
- 77 Nebula Status and Incidents
- 5K Security
- 44 USG FLEX H Series
- 246 Security Ideas
- 1.2K Switch
- 64 Switch Ideas
- 901 WirelessLAN
- 33 WLAN Ideas
- 5.8K Consumer Product
- 204 Service & License
- 326 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.8K FAQ
- 831 Nebula FAQ
- 401 Security FAQ
- 219 Switch FAQ
- 190 WirelessLAN FAQ
- 45 Consumer Product FAQ
- 136 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 71 About Community
- 61 Security Highlight