Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    iPhone failing to connect to IPSec VPN after updating to 23.09-RELEASE (amd64)

    Scheduled Pinned Locked Moved IPsec
    12 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      teverett
      last edited by

      I have the same issue

      Nov 22 16:31:01 charon 40560 15[IKE] <con-mobile|4> XAUTH-SCRIPT failed to execute script '/etc/inc/ipsec.auth-user.php'.
      Nov 22 16:31:01 charon 40018 15[ENC] <con-mobile|4> parsed TRANSACTION response 2115188573 [ HASH CPRP(X_USER X_PWD) ]
      Nov 22 16:31:01 charon 40018 15[NET] <con-mobile|4> received packet: from 207.228.78.237[10482] to 198.166.24.90[4500] (92 bytes)
      Nov 22 16:31:01 charon 40018 15[ENC] <con-mobile|4> parsed INFORMATIONAL_V1 request 3180770281 [ HASH N(INITIAL_CONTACT) ]
      Nov 22 16:31:01 charon 40018 15[NET] <con-mobile|4> received packet: from 207.228.78.237[10482] to 198.166.24.90[4500] (92 bytes)
      Nov 22 16:31:01 charon 40018 15[NET] <con-mobile|4> sending packet: from 198.166.24.90[4500] to 207.228.78.237[10482] (76 bytes)
      Nov 22 16:31:01 charon 40018 15[ENC] <con-mobile|4> generating TRANSACTION request 2115188573 [ HASH CPRQ(X_USER X_PWD) ]

      T 1 Reply Last reply Reply Quote 0
      • T
        teverett @teverett
        last edited by teverett

        I may have found a solution. Looking at the file system I see this:

        -rw-r--r--  1 root wheel 3638 Oct 31 13:54 ipsec.auth-user.php
        

        It seems that strongswan needs that file to be executable. So I made it executable by owner and IPSEC seems to work again

        chmod 744 /etc/inc/ipsec.auth-user.php
        

        I dont know if there are security implications to doing this, and I also see that the file is writable by root which seems strange to me since its a script which I dont expect would change other than during upgrades. I left it writable for now since every file in /etc/inc seems to be 644.

        J 1 Reply Last reply Reply Quote 1
        • J
          jonsteinmetz @teverett
          last edited by

          @teverett Excellent, that fixed my issue as well. Thank you very much.

          T 1 Reply Last reply Reply Quote 1
          • T
            teverett @jonsteinmetz
            last edited by

            @jonsteinmetz do you happen to have this problem?

            https://forum.netgate.com/topic/184293/unable-to-save-group-authentication

            J 2 Replies Last reply Reply Quote 0
            • J
              jonsteinmetz @teverett
              last edited by

              @teverett I will check shortly when I get home. Interestingly, while I can connect from my mobile device to my IPSec VPN I do not have access to the devices on my local network. Accessing the WAN while on VPN still seems to work. Accessing my local network did work previously. Hopefully there is some rule change I can make to access the local network.

              T 1 Reply Last reply Reply Quote 0
              • J
                jonsteinmetz @teverett
                last edited by

                @teverett said in iPhone failing to connect to IPSec VPN after updating to 23.09-RELEASE (amd64):

                https://forum.netgate.com/topic/184293/unable-to-save-group-authentication

                Yep, mine is also displaying this issue.

                T 1 Reply Last reply Reply Quote 0
                • T
                  teverett @jonsteinmetz
                  last edited by

                  @jonsteinmetz Hopefully both issues are fixed soon. I have an LDAP challenge too, but I don't know if that's related to the new release, an old bug or I'm just doing it wrong.

                  1 Reply Last reply Reply Quote 0
                  • T
                    teverett @jonsteinmetz
                    last edited by

                    @jonsteinmetz I seem to have a similar issue. I used to be able to ping the default GW on my LAN, now I can't.

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      jonsteinmetz @teverett
                      last edited by

                      @teverett I found a solution for my routing issue. Under "VPN/IPsec/Advanced Settings/Auto-exclude LAN address" there is a checkbox "Enable bypass for LAN interface IP". In my case it was checked and unchecking it allowed my VPN client to see devices on the local network. I have no idea if that was checked before the update or not.

                      See https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/advanced.html.

                      T 1 Reply Last reply Reply Quote 1
                      • T
                        teverett @jonsteinmetz
                        last edited by

                        @jonsteinmetz In my case I had the network mask wrong in my phase 2. :)

                        The file permissions issue and the group authentication issue are still there however.

                        1 Reply Last reply Reply Quote 0
                        • maverickwsM maverickws referenced this topic on
                        • JonathanLeeJ
                          JonathanLee
                          last edited by

                          My android will not even connect to even external AP WiFi in 23.09. Other devices connect just fine.

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.