Zyxel Flex 100H - VPN Apple mobileconfig returns error on importing on Apple OSX
Freshman Member
Here is the screenshot.
Apple OSX version Tahoe 26.3
Accepted Solution
-
Hi @MitjaS3NEXT
Thanks for sharing. After checking, the issue is due to the phase 1 Diffie-Hellman Groups. Mac OS and iOS don't support DH2 in recent version.
Please help to remove the DH2 in phase 1 setting and add DH 19.
Zyxel Melen0
All Replies
-
Hi @MitjaS3NEXT
I tried to replicate with USG FLEX 200H in V1.37 P1 and iPhone 15PRO iOS 26.3, I didn't encounter this issue. Please check:
- Your firewall's firmware version.
- Your IPSec remote access VPN advanced settings. Here is my lab's setting:
Hope this helps.
Zyxel Melen0 -
The firmware version is : V1.37(ABXF.1)
You tryed on on the phone iOS, but the problem is on the computer Apple osX version Tahoe 26.3?
0 -
Hi @MitjaS3NEXT
Thanks for pointing out. Let us have a further investigation.
And the current workaround could be used the SSL VPN with OpenVPN instead.
Additionally, MAC OS X 26.2 is working for importing the mobileconfig.
Zyxel Melen0 -
If I understand you right, you have tested on MAX OS X 26.2 and it works, but haven't tested on 26.3?
I probably can't use SSL VPN since there is a license needed, if I understand the zyxel flex H series licensing right?0 -
Hi @MitjaS3NEXT
SSL VPN on USG FLEX H series supports OpenVPN. You can import the VPN profile to the OpenVPN software.
If I understand you right, you have tested on MAX OS X 26.2 and it works, but haven't tested on 26.3?
Not yet but is under verifying now.
Zyxel Melen0 -
Please answer if we need to buy any licenses with enabling SSL VPN on USG FLEX 100H that supports OpenVPN?
0 -
Hi @MitjaS3NEXT
You don't need to buy a license since OpenVPN is a free software.
Additionally, in our test, we can import the USG FLEX 100H V1.37 Patch 1 mobileconfig file to our test MAC with MAC OS X 26.3. To investigate this issue, please help to share your mobileconfig file with us. I will send you a private message and you may upload the file in the message.
Zyxel Melen0 -
I sent you the config file as requested 👍
0 -
Hi @MitjaS3NEXT
Thanks for sharing. After checking, the issue is due to the phase 1 Diffie-Hellman Groups. Mac OS and iOS don't support DH2 in recent version.
Please help to remove the DH2 in phase 1 setting and add DH 19.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 220 Nebula Ideas
- 128 Nebula Status and Incidents
- 6.5K Security
- 606 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 299 Service & License
- 482 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight

Zyxel Employee
