ATP200 VPN on Iphone stays stuck on "connection starting"

Jarno_Smits
Jarno_Smits Posts: 23  Freshman Member
First Comment Friend Collector Sixth Anniversary

Hello,

I had a IKEv2 VPN with certificate working at my home, i'm not sure if the issue started after i upgraded the ATP to release 5.39 or my upgrade to IOS 18, but i;m not able to get the VPN working again, i tried new phase 1 and 2 settings a new certificate but nothing is working, i think it has something to do with the PEER IP adress mismatch message , but im not able to fix it.

PS, the certificate is created with a FQDN and the FQDN is working

Does this look similar for someone, see the debug log file:

«1

All Replies

  • PeterUK
    PeterUK Posts: 3,251  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    For the VPN gateway rule in Advance set peer ID type to any

  • Jarno_Smits
    Jarno_Smits Posts: 23  Freshman Member
    First Comment Friend Collector Sixth Anniversary

    Hi Peter,

    It is already on "ANY"

    see screenshot below, i already found a topic online about this, but it doesn't solve my problem.

  • PeterUK
    PeterUK Posts: 3,251  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited September 24

    Is the certificate Self-signed? imported to phone?

    disable other VPN's for testing

  • Jarno_Smits
    Jarno_Smits Posts: 23  Freshman Member
    First Comment Friend Collector Sixth Anniversary
    edited September 24

    Yes certificate is self signed and imported to the iphone, i already created a new certificate and imported it, but the same problem.

    for testing also disconected the other site to site vpn's and the VPN for the laptop, but stil no connection, every time the Peer ID mismatch, very strange can't find the root cause, it worked before more then a year without any issue, noticed the problem a few days after the upgrade of the ATP200 and the IPhone to IOS 18, but don't know witch is causing the issue.

    its only the Iphone, other site to site vpn's are working, and the other VPN for the laptop, is also using the same certificate and is working..

  • PeterUK
    PeterUK Posts: 3,251  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited September 24

    Maybe a update on the phone caused it?

    can you try strongswan VPN client?

  • Jarno_Smits
    Jarno_Smits Posts: 23  Freshman Member
    First Comment Friend Collector Sixth Anniversary
    edited September 25

    Hi Peter, i searched for strongswan VPN client in the appstore, i only found Brooog IKEv2

    instaled it, but here i can't use the certificate , so maybe i'm doing something wrong.

    It is very strange, maybe more people are reading this problem on the forum, so i'm courious if more people got the same issue when using a ATPxxx router with a IOS 18 devive and a IKEV2 VPN with a certificate, i can't believe i'm the only one with this combination :-)

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,220  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited September 27

    Hi @Jarno_Smits,

    It seems like iOS/macOS has changed the proposal in the new version. Could you follow this FAQ to configure the phase 1 and phase 2 proposals and test remote access again?


    Also, please help collect the VPN event log if you still cannot connect to the remote access VPN. Thanks~

    Zyxel Melen

    Don't miss this great chance to upgrade your Nebula org. for free! 


  • Jarno_Smits
    Jarno_Smits Posts: 23  Freshman Member
    First Comment Friend Collector Sixth Anniversary

    Hello Melen,

    Thank you for the feedback, i changed the phase 1 and 2 settings as described in the document, but still the same issue.

    I also created a new certificate wit the WAN IP, and changed the setting to use the WAN IP instead but thas also don't make any diferense.

    So I changed it but to the old settings with the FQDN

    Below the settings how i have set it up at this moment, and the debug logging.

    And the Debug loggng, when i enable the VPN on my ipone ( Iphone is offcourse at a 5G connection and not on the local wifi)

  • PeterUK
    PeterUK Posts: 3,251  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Try setting Domain name/ IPv4 to 0.0.0.0

  • Jarno_Smits
    Jarno_Smits Posts: 23  Freshman Member
    First Comment Friend Collector Sixth Anniversary

    Hi Peter,

    No, when changing Domain name/ IPv4 to 0.0.0.0 still got the same error in de debug logging.

Security Highlight