Android 13/IPAD IOS 15.7 and USG40 with IKEv2

Hi,

I have used earlier L2TP/IPSEC tunneling but now newer andoids doesn't support that one. 

I did IKEv2 configuration according these.
https://support.zyxel.eu/hc/en-us/articles/8805317185298-VPN-Configure-IKEv2-with-Pre-Shared-key-on-Mobile-Devices-Instead-of-L2TP-


When I try make a connection I will get always error message in both devices android (SAMSUNG S20) and IPAD.

Any Ideas? KR,J

"
[SA] : No proposal chosen
 84.250.110.101:500
 221.210.110.200:39676
IKE_LOG
5
2022-12-23 05:15:26
info
IKE
[SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatch
 84.250.110.101:500
 221.210.110.200:39676
IKE_LOG
6
2022-12-23 05:15:26
info
IKE
The cookie pair is : 0xe2c0fb51341291dc / 0xfc79f4663830a392 [count=3]
 84.250.110.101:500
 221.210.110.200:39676
IKE_LOG
7
2022-12-23 05:15:26
info
IKE
Recv IKE sa: SA([0] protocol = IKE (1), AES CBC key len = 256, AES CBC key len = 128, HMAC-SHA512-256, HMAC-SHA384-192, HMAC-SHA256-128, HMAC-SHA1-96, HMAC-SHA512 PRF, HMAC-SHA384 PRF, HMAC-SHA256 PRF, HMAC-SHA1 PRF, RFC5114 2048-256 bit MODP, 384 bit ECP
 221.210.110.200:39676
 84.250.110.101:500
IKE_LOG
8
2022-12-23 05:15:26
info
IKE
[INIT] Recv: [SA][KE][NONCE][NOTIFY][NOTIFY][NOTIFY][NOTIFY]
 221.210.110.200:39676
 84.250.110.101:500
IKE_LOG
9
2022-12-23 05:15:26
info
IKE
Receiving IKEv2 request
 221.210.110.200:39676
 84.250.110.101:500
IKE_LOG
10
2022-12-23 05:15:26
info
IKE
The cookie "

Best Answers

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,376  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    edited December 2022 Answer ✓
    Hi @Jokke,
    [SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatch
    Here is Phase 1 and Phase 2 proposal that match the iOS setting for your reference. 
    iOS: 15.6.1 on iPhone 8 Plus
    Phase 1 


    Phase 2



    Test Result
    IKEv2 is connected on iPhone.

  • Jokke
    Jokke Posts: 4
    First Comment Friend Collector
    Answer ✓
    Hi @Jokke,
    [SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatch
    Here is Phase 1 and Phase 2 proposal that match the iOS setting for your reference. 
    iOS: 15.6.1 on iPhone 8 Plus
    Phase 1 


    Phase 2



    Test Result
    IKEv2 is connected on iPhone.

    Ipad IOS 16.2 worked when chanhed key group from DH2 to DH14. Anyway my android 13 still cannot establish connection. 

All Replies

Security Highlight