Zyxel Flex 200 - Android/Apple remote vpn

Options
mm_bret
mm_bret Posts: 71 image  Ally Member
First Comment Fifth Anniversary

Since the L2TP tunnels are no longer supported by android, what is a working

remote vpn tunnel that does work.

We have lots of l2tp tunnels in use to our FLEX 200, but newer Android devices

don't work/support L2TP tunnels.

Hoping to see a native solution, otherwise we probably need to implement NetBird

or equivalent or perhaps use an alternative hardware solution.

I would like to see a link to a solution. Thanks in advance.

Bret

All Replies

  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    You can setup IKEv2 with Pre-Shared Key for android IKEv2/IPSec PSK

    Phase 1
    AES128 SHA256
    DH14

    Phase 2
    AES128 SHA256
    DH2

    on android IPSec identifier is ikev2

  • mm_bret
    mm_bret Posts: 71 image  Ally Member
    First Comment Fifth Anniversary

    PeterUK,

    Attached three images for my connection sample. (Gateway and Connection, log)

    Set per your comment. Currently, the android connects, then immediately drops:

    For the Connection side on site-to-site ipsec tunnels, local policy is typically the local subnet… For this configuration there is no remote policy. Assuming this is because the peer is dynamic.

    What should the local policy be for this ikve2 configuration? Do I need to create a pool for these

    tunnel users?

    Also, on l2tp tunnels (which the android no longer supports) we would typically have a user/passwrd setup. None of this exists on the IKVE2 psk config on the android device.

    I do appreciate anything you have to offer in terms of a solution.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,669 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @mm_bret

    The current suggestion is to use strongSwan for Android. Please reference this FAQ:

    Remote Access VPN Wizard for SecuExtender IPSec and Non-SecuExtender IPSec VPN Clients — Zyxel Community

    Zyxel Melen


  • mm_bret
    mm_bret Posts: 71 image  Ally Member
    First Comment Fifth Anniversary

    Thanks. I will look for alternative solutions.