How to configure IKEv2 VPN beštween Samsung Android and USG 60?

Options
emika56
emika56 Posts: 6
Friend Collector First Comment

Is there any guide/white paper/config sample how to configure IKEv2 VPN with pre-shared key between Android 13 on Samsung device (phone/tablet) and USG firewall (USG 60/USG 210) running 4.73 firmware?

«1

All Replies

  • PeterUK
    PeterUK Posts: 2,848  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited May 1
    Options

    try here

    https://support.zyxel.eu/hc/en-us/articles/8805317185298-IKEv2-VPN-with-Pre-Shared-key-on-Mobile-Devices-Instead-of-L2TP

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment
    Options

    I tried that one but it does not seem to work on Samsung device with Android 13. I found on the internet several people reporting the same problem but no one who has found a workable solution.
    it starts to "talk" but the only result is line 60 below.


  • PeterUK
    PeterUK Posts: 2,848  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Have no problem here with Android 12 and IKEv2

    post your settings

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment
    Options
  • PeterUK
    PeterUK Posts: 2,848  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    set local policy to 0.0.0.0

    Phase 2 PFS to DH2

    Phase 1 key group may need to be higher

    Encryption to AES128

    check logs if Phase 1 show done

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment
    edited May 2
    Options

    Thanks a lot for your help but doesn't work.

    I adjusted config per your recommendation. But with DH14, DH19 and DH20 gateway gets disconnected. Other values return proposal mismatch.

  • PeterUK
    PeterUK Posts: 2,848  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    try a simple Pre-shared key

    on phone is IPsec identifier 0.0.0.0

  • emika56
    emika56 Posts: 6
    Friend Collector First Comment
    Options

    Tried both already to no avail.

  • PeterUK
    PeterUK Posts: 2,848  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    So your phone is by 4G/5G to your USG60?

    keep trying till you see Phase 1 done

  • mMontana
    mMontana Posts: 1,337  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Sorry for being picky. It's a "pure IPSec" connection or an L2TP/IPsec connection between samsun phone and USG60? (which by the way is out of support but whatever…)

Security Highlight