Why can't I establish a VPN connection after updating to iOS 18? How can I resolve this issue?

Zyxel_Jeff
Zyxel_Jeff Posts: 1,316  Zyxel Employee
100 Answers 500 Comments Friend Collector Fourth Anniversary
edited October 2024 in VPN

Question :

Why can't I establish an IKEv2 VPN connection after updating to iOS 18? How can I resolve this issue?

Answer :

Since there are changes to the VPN Phase 1 and Phase 2 parameters for iOS's native VPN client, please modify them accordingly to allow the remote VPN to work.

USG Flex/ATP firewall model settings:

Please navigate to Configuration > VPN > IPsec > VPN Gateway > To add the VPN phase 1 setting. Please configure Phase 1 Encryption and Authentication settings to AES256/SHA256 DH2/DH14/DH19.

VPN_Gateway_phase1.png

Please navigate to Configuration > VPN > IPsec > VPN Connection > To add the VPN phase 2 setting. Please configure Phase 2 Encryption and Authentication settings to AES256/SHA256 Perfect Forward Secrecy(PFS) : None.

VPN_Connection_phase2.png

USG Flex H firewall model settings:

Please navigate to VPN > IPsec VPN > To set the IKEv2-related information, as shown below:

gui.png VPN IP range.png

Please configure Phase 1 Encryption and Authentication settings to AES256/SHA256 DH2/DH14/DH21 and Phase 2 Encryption and Authentication settings to AES256/SHA256 Perfect Forward Secrecy(PFS) : None.

gui-2_.png

How to verify the result?

Install the VPN configuration script (.mobileconfig file) that was downloaded from the firewall.

Install_edit.png

Establish the IKEv2 VPN connection from the iPhone to the Zyxel firewall.

IKEV2 .png

USG Flex/ATP firewall:

Please navigate to the path: Monitor > VPN Monitor> IPSec, you will find that the IKEv2 VPN connection has been established.

VPN connection_ATP200.png

USG Flex H firewall:

Please navigate to the path: VPN Status > IPsec VPN > Remote Access VPN, you will find that the IKEv2 VPN connection has been established.

VPN connection_500H_edit.png
Tagged: