IKEv2
To set up a VPN which supports IKEv2 I have used the following instructions:
http://onesecurity.zyxel.com/img/uploads/Next-Gen_IKEv2_VPN_Server_Role_CR.pdf
http://www.zyxel-tech.de/files/New-Gen_USG_IKEv2_iPhone.pdf
https://www.google.de/url?sa=t&rct=j&q=&esrc=s&source=web&cd=4&ved=2ahUKEwiL2J24hprfAhXloYsKHT5hAH8QFjADegQIABAC&url=https%3A%2F%2Fus.v-cdn.net%2F6029482%2Fuploads%2Feditor%2Fzx%2F8vcjgzsm4487.pdf&usg=AOvVaw2BsE372QdIYpioYkLUW-XV
The setup works on my Windows 10 device (manual configuration) and on my iPhone (iOS 12.1.1) using the handy provisioning feature.
Now the question is how to provision the profile on my iPad? Safari is not displaying the webpage of the ZyXEL in a mobile version (/access.cgi?mobile=1), therefore the profile is not visible to install. Manually configuring the VPN tunnel does not work (no proposal chosen).
What I am doing wrong? Many thanks for any hints in advance.
Regards
Best Answers
-
Hi @alehzn,
In the current version, iOS provisioning supports iPhone only.
We will evaluate the enhancement for iPad and move the request to the ideas section.
5 -
Hi @alehzn,
Go to Object > Certificate > My Certificates and export the certificate for IKEv2.
Use SSL converter to convert the certificate to .crt file.
Send the .crt file to email on your iPhone/iPad.
Click the .crt file and follow steps on iPhone/iPad to install the certificate.
On iPhone/iPad, go to Settings > VPN > Add VPN Configuration with Type "IKEv2".
Enter the Server of the ZyWALL and Remote ID. The Remote ID is the content in VPN Gateway for IKEv2.
7
All Replies
-
Hi @alehzn,
In the current version, iOS provisioning supports iPhone only.
We will evaluate the enhancement for iPad and move the request to the ideas section.
5 -
Hello @Zyxel_Emily
Thank you for your reply.
Do you have also an answer on how to manually configure the IKEv2 tunnel on iPhone/iPad? Apperently it is not possible to set it up manually. All provided information seems to be not sufficient.
Thanks in advance.
0 -
Hi @alehzn,
Go to Object > Certificate > My Certificates and export the certificate for IKEv2.
Use SSL converter to convert the certificate to .crt file.
Send the .crt file to email on your iPhone/iPad.
Click the .crt file and follow steps on iPhone/iPad to install the certificate.
On iPhone/iPad, go to Settings > VPN > Add VPN Configuration with Type "IKEv2".
Enter the Server of the ZyWALL and Remote ID. The Remote ID is the content in VPN Gateway for IKEv2.
7 -
0
-
Hi, I would love to get this working ! However, I'm in the US and can't download the referenced PDF,
http://www.zyxel-tech.de/files/New-Gen_USG_IKEv2_iPhone.pdf
Could anyone please share all of the specified settings for phase 1 & phase 2 ?
Thank-you in advance, be it @Zyxel_Emily or anyone else.
0 -
Hi @CoreSG,Currently iOS supports the following proposals:In phase 1:AES256+SHA256, Key Group=DH14In phase 2:AES256+SHA256, PFS=none
How iOS device get the IKEv2 VPN configuration from device0 -
Thanks very much !
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight