Android 13/IPAD IOS 15.7 and USG40 with IKEv2

Hi,

I have used earlier L2TP/IPSEC tunneling but now newer andoids doesn't support that one. 

I did IKEv2 configuration according these.
https://support.zyxel.eu/hc/en-us/articles/8805317185298-VPN-Configure-IKEv2-with-Pre-Shared-key-on-Mobile-Devices-Instead-of-L2TP-


When I try make a connection I will get always error message in both devices android (SAMSUNG S20) and IPAD.

Any Ideas? KR,J

"
[SA] : No proposal chosen
 84.250.110.101:500
 221.210.110.200:39676
IKE_LOG
5
2022-12-23 05:15:26
info
IKE
[SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatch
 84.250.110.101:500
 221.210.110.200:39676
IKE_LOG
6
2022-12-23 05:15:26
info
IKE
The cookie pair is : 0xe2c0fb51341291dc / 0xfc79f4663830a392 [count=3]
 84.250.110.101:500
 221.210.110.200:39676
IKE_LOG
7
2022-12-23 05:15:26
info
IKE
Recv IKE sa: SA([0] protocol = IKE (1), AES CBC key len = 256, AES CBC key len = 128, HMAC-SHA512-256, HMAC-SHA384-192, HMAC-SHA256-128, HMAC-SHA1-96, HMAC-SHA512 PRF, HMAC-SHA384 PRF, HMAC-SHA256 PRF, HMAC-SHA1 PRF, RFC5114 2048-256 bit MODP, 384 bit ECP
 221.210.110.200:39676
 84.250.110.101:500
IKE_LOG
8
2022-12-23 05:15:26
info
IKE
[INIT] Recv: [SA][KE][NONCE][NOTIFY][NOTIFY][NOTIFY][NOTIFY]
 221.210.110.200:39676
 84.250.110.101:500
IKE_LOG
9
2022-12-23 05:15:26
info
IKE
Receiving IKEv2 request
 221.210.110.200:39676
 84.250.110.101:500
IKE_LOG
10
2022-12-23 05:15:26
info
IKE
The cookie "

Best Answers

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,402  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    edited December 2022 Answer ✓
    Hi @Jokke,
    [SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatch
    Here is Phase 1 and Phase 2 proposal that match the iOS setting for your reference. 
    iOS: 15.6.1 on iPhone 8 Plus
    Phase 1 


    Phase 2



    Test Result
    IKEv2 is connected on iPhone.

    See how you've made an impact in Zyxel Community this year!
    https://bit.ly/Your2024Moments_Community

  • Jokke
    Jokke Posts: 4
    First Comment Friend Collector
    Answer ✓
    Hi @Jokke,
    [SA] : Tunnel [IKEv2_Connection] Phase 1 proposal mismatch
    Here is Phase 1 and Phase 2 proposal that match the iOS setting for your reference. 
    iOS: 15.6.1 on iPhone 8 Plus
    Phase 1 


    Phase 2



    Test Result
    IKEv2 is connected on iPhone.

    Ipad IOS 16.2 worked when chanhed key group from DH2 to DH14. Anyway my android 13 still cannot establish connection. 

All Replies