Why Can't I Connect to VPN on Windows 11 When Using DH14?

Options
Zyxel_Stanley
Zyxel_Stanley Posts: 1,435 image  Zyxel Employee
100 Answers 1000 Comments Friend Collector Eighth Anniversary

Question:
I cannot connect to my IKEv2 VPN on Windows 11, even though the setup is correct. Why is the VPN connection failing?

Answer:
Windows 11 no longer supports the DH14 encryption group used in some VPN configurations. If your Zyxel firewall VPN proposal still includes DH14, Windows 11 will reject the connection.
To fix this, edit your VPN settings on the firewall, remove DH14, and replace it with a supported option such as DH2 or DH5. After updating the settings, re-import the VPN profile into Windows 11 and try connecting again.

image.png