How Do I Fix The VPN Configuration Download?

Painted_Turtle
Painted_Turtle Posts: 8  Freshman Member
Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

If you configure an IPSec VPN Remote Access VPN on a USG FLEX H series, you have the option for a “VPN Configuration Download for Native VPN Client” for Windows, iOS/macOS, and Android (strongSwan).

The iOS/macOS download produced an Apple style .mobileconfig profile. Since it did not work on one of the test Macs, I opened it with the Apple Configurator tool.

The Apple Configuration Tool indicated that a required value was missing.

Local Identifier

FQDN, UserFQDN, Address or ASN1DN local identifier

Apple Configurator says the field is[required]

But the USG FLEX I've got a router generated  .mobileconfig profile for which that field is missing. I’m hoping if I add the correct value to this field, that it will work in some machines that it is not working in.

IKEv2 MDM settings for Apple devices - Apple Support

Found the following on the above Apple site, but I'm still not certain exactly what this value is or where to get it.

Local Identifier

This value should usually match the user/device certificate’s identity (Subject Alternative Name or Subject Common Name), since server implementation may require that match to validate the client’s identity.

Rather than wait for a bug fix, I'd like to put in the right value. But, I'm not sure exactly what goes here, or how to get it.

All Replies