Zyxel Flex 100H - VPN Apple mobileconfig returns error on importing on Apple OSX

Options
MitjaS3NEXT
MitjaS3NEXT Posts: 17 image  Freshman Member
First Comment Friend Collector Second Anniversary

Here is the screenshot.
Apple OSX version Tahoe 26.3

image.png

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,616 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @MitjaS3NEXT

    Thanks for sharing. After checking, the issue is due to the phase 1 Diffie-Hellman Groups. Mac OS and iOS don't support DH2 in recent version.

    Please help to remove the DH2 in phase 1 setting and add DH 19.

    Untitled Image
    Zyxel Melen


All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,616 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @MitjaS3NEXT

    I tried to replicate with USG FLEX 200H in V1.37 P1 and iPhone 15PRO iOS 26.3, I didn't encounter this issue. Please check:

    1. Your firewall's firmware version.
    2. Your IPSec remote access VPN advanced settings. Here is my lab's setting: image.png

    Hope this helps.

    Zyxel Melen


  • MitjaS3NEXT
    MitjaS3NEXT Posts: 17 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    The firmware version is : V1.37(ABXF.1)

    You tryed on on the phone iOS, but the problem is on the computer Apple osX version Tahoe 26.3?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,616 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited February 26

    Hi @MitjaS3NEXT

    Thanks for pointing out. Let us have a further investigation.

    And the current workaround could be used the SSL VPN with OpenVPN instead.

    Additionally, MAC OS X 26.2 is working for importing the mobileconfig.

    Zyxel Melen


  • MitjaS3NEXT
    MitjaS3NEXT Posts: 17 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    If I understand you right, you have tested on MAX OS X 26.2 and it works, but haven't tested on 26.3?
    I probably can't use SSL VPN since there is a license needed, if I understand the zyxel flex H series licensing right?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,616 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @MitjaS3NEXT

    SSL VPN on USG FLEX H series supports OpenVPN. You can import the VPN profile to the OpenVPN software.

    If I understand you right, you have tested on MAX OS X 26.2 and it works, but haven't tested on 26.3?

    Not yet but is under verifying now.

    Zyxel Melen


  • MitjaS3NEXT
    MitjaS3NEXT Posts: 17 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    Please answer if we need to buy any licenses with enabling SSL VPN on USG FLEX 100H that supports OpenVPN?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,616 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @MitjaS3NEXT

    You don't need to buy a license since OpenVPN is a free software.

    Additionally, in our test, we can import the USG FLEX 100H V1.37 Patch 1 mobileconfig file to our test MAC with MAC OS X 26.3. To investigate this issue, please help to share your mobileconfig file with us. I will send you a private message and you may upload the file in the message.

    Zyxel Melen


  • MitjaS3NEXT
    MitjaS3NEXT Posts: 17 image  Freshman Member
    First Comment Friend Collector Second Anniversary

    I sent you the config file as requested 👍

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,616 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @MitjaS3NEXT

    Thanks for sharing. After checking, the issue is due to the phase 1 Diffie-Hellman Groups. Mac OS and iOS don't support DH2 in recent version.

    Please help to remove the DH2 in phase 1 setting and add DH 19.

    Untitled Image
    Zyxel Melen