How to configure IKEv2 VPN beštween Samsung Android and USG 60?

emika56
emika56 Posts: 6
Friend Collector First Comment

Is there any guide/white paper/config sample how to configure IKEv2 VPN with pre-shared key between Android 13 on Samsung device (phone/tablet) and USG firewall (USG 60/USG 210) running 4.73 firmware?

«1

All Replies

  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited May 1

    try here

    https://support.zyxel.eu/hc/en-us/articles/8805317185298-IKEv2-VPN-with-Pre-Shared-key-on-Mobile-Devices-Instead-of-L2TP

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment

    I tried that one but it does not seem to work on Samsung device with Android 13. I found on the internet several people reporting the same problem but no one who has found a workable solution.
    it starts to "talk" but the only result is line 60 below.


  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    Have no problem here with Android 12 and IKEv2

    post your settings

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment
  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    set local policy to 0.0.0.0

    Phase 2 PFS to DH2

    Phase 1 key group may need to be higher

    Encryption to AES128

    check logs if Phase 1 show done

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment
    edited May 2

    Thanks a lot for your help but doesn't work.

    I adjusted config per your recommendation. But with DH14, DH19 and DH20 gateway gets disconnected. Other values return proposal mismatch.

  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    try a simple Pre-shared key

    on phone is IPsec identifier 0.0.0.0

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment

    Tried both already to no avail.

  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    So your phone is by 4G/5G to your USG60?

    keep trying till you see Phase 1 done

  • mMontana
    mMontana Posts: 1,351  Guru Member
    Fifth Anniversary Community MVP 50 Answers 1000 Comments

    Sorry for being picky. It's a "pure IPSec" connection or an L2TP/IPsec connection between samsun phone and USG60? (which by the way is out of support but whatever…)

Security Highlight