Android 13/IPAD IOS 15.7 and USG40 with IKEv2
I have used earlier L2TP/IPSEC tunneling but now newer andoids doesn't support that one.
I did IKEv2 configuration according these.
https://support.zyxel.eu/hc/en-us/articles/8805317185298-VPN-Configure-IKEv2-with-Pre-Shared-key-on-Mobile-Devices-Instead-of-L2TP-
When I try make a connection I will get always error message in both devices android (SAMSUNG S20) and IPAD.
Any Ideas? KR,J
"
Best Answers
-
Hi @Jokke,[SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatchHere is Phase 1 and Phase 2 proposal that match the iOS setting for your reference.iOS: 15.6.1 on iPhone 8 PlusPhase 1
Phase 2
Test Result
IKEv2 is connected on iPhone.See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Zyxel_Emily said:Hi @Jokke,[SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatchHere is Phase 1 and Phase 2 proposal that match the iOS setting for your reference.iOS: 15.6.1 on iPhone 8 PlusPhase 1
Phase 2
Test Result
IKEv2 is connected on iPhone.0
All Replies
-
Hi @Jokke,[SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatchHere is Phase 1 and Phase 2 proposal that match the iOS setting for your reference.iOS: 15.6.1 on iPhone 8 PlusPhase 1
Phase 2
Test Result
IKEv2 is connected on iPhone.See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
In a thread of some day ago we discussed about parameters setting:Now a question arise: is there a way to disable, on Android and Apple devices, vpn password save? I'd like to have users input it every time.0
-
The VPN secret and password setting are saved on Apple device. Maybe you should check with Apple if these settings are able to be not saved.0
-
Zyxel_Emily said:Hi @Jokke,[SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatchHere is Phase 1 and Phase 2 proposal that match the iOS setting for your reference.iOS: 15.6.1 on iPhone 8 PlusPhase 1
Phase 2
Test Result
IKEv2 is connected on iPhone.0 -
Hi @Jokke,For Android 13, set proposal "AES128-SHA256-DH2" in phase 1 and "AES128-SHA256" in phase 2.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Unfortenately this does not work :( also Even this would work I shoud creat own VPN tunnel for IOS and android because Zyxel support only one IKE Diffie-Hellman (DH) group per tunnel
0 -
I am wondering is that something what is Samsung spefic, my phone is Samsung s20 with android 13
0 -
Hi @Jokke,
It seems Samsung needs two DNS server in phase 2 settings. Hence, try to configure both First DNS server and Second DNS server in VPN Connetion > Configuration Payload on USG40.See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 150 Nebula Ideas
- 97 Nebula Status and Incidents
- 5.7K Security
- 268 USG FLEX H Series
- 273 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 41 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 388 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 74 Security Highlight