ATP200 VPN on Iphone stays stuck on "connection starting"
Hello,
I had a IKEv2 VPN with certificate working at my home, i'm not sure if the issue started after i upgraded the ATP to release 5.39 or my upgrade to IOS 18, but i;m not able to get the VPN working again, i tried new phase 1 and 2 settings a new certificate but nothing is working, i think it has something to do with the PEER IP adress mismatch message , but im not able to fix it.
PS, the certificate is created with a FQDN and the FQDN is working
Does this look similar for someone, see the debug log file:
All Replies
-
For the VPN gateway rule in Advance set peer ID type to any
0 -
Hi Peter,
It is already on "ANY"
see screenshot below, i already found a topic online about this, but it doesn't solve my problem.
0 -
Is the certificate Self-signed? imported to phone?
disable other VPN's for testing
0 -
Yes certificate is self signed and imported to the iphone, i already created a new certificate and imported it, but the same problem.
for testing also disconected the other site to site vpn's and the VPN for the laptop, but stil no connection, every time the Peer ID mismatch, very strange can't find the root cause, it worked before more then a year without any issue, noticed the problem a few days after the upgrade of the ATP200 and the IPhone to IOS 18, but don't know witch is causing the issue.
its only the Iphone, other site to site vpn's are working, and the other VPN for the laptop, is also using the same certificate and is working..
0 -
Maybe a update on the phone caused it?
can you try strongswan VPN client?
0 -
Hi Peter, i searched for strongswan VPN client in the appstore, i only found Brooog IKEv2
instaled it, but here i can't use the certificate , so maybe i'm doing something wrong.
It is very strange, maybe more people are reading this problem on the forum, so i'm courious if more people got the same issue when using a ATPxxx router with a IOS 18 devive and a IKEV2 VPN with a certificate, i can't believe i'm the only one with this combination :-)
0 -
Hi @Jarno_Smits,
It seems like iOS/macOS has changed the proposal in the new version. Could you follow this FAQ to configure the phase 1 and phase 2 proposals and test remote access again?
Also, please help collect the VPN event log if you still cannot connect to the remote access VPN. Thanks~0 -
Hello Melen,
Thank you for the feedback, i changed the phase 1 and 2 settings as described in the document, but still the same issue.
I also created a new certificate wit the WAN IP, and changed the setting to use the WAN IP instead but thas also don't make any diferense.
So I changed it but to the old settings with the FQDN
Below the settings how i have set it up at this moment, and the debug logging.
And the Debug loggng, when i enable the VPN on my ipone ( Iphone is offcourse at a 5G connection and not on the local wifi)
0 -
Try setting Domain name/ IPv4 to 0.0.0.0
0 -
Hi Peter,
No, when changing Domain name/ IPv4 to 0.0.0.0 still got the same error in de debug logging.
0
Categories
- All Categories
- 414 Beta Program
- 2.3K Nebula
- 139 Nebula Ideas
- 92 Nebula Status and Incidents
- 5.5K Security
- 195 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 40 Wireless Ideas
- 6.2K Consumer Product
- 240 Service & License
- 379 News and Release
- 80 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 81 About Community
- 70 Security Highlight