Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Visual Guide to Configuring IPSec VPN using RSA + Xauth and iOS Roadwarriors

    Scheduled Pinned Locked Moved IPsec
    23 Posts 5 Posters 39.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      twaldorf
      last edited by

      There is only one last thing, which is a little bit annoying:

      If I uncheck the box with "Provide login banner to clients", there comes an empty login banner up. Is there no possibility to completly disable the banner? I use VPN on demand and so I have to click all the time on "OK" on the iPhone…

      1 Reply Last reply Reply Quote 0
      • A
        azzido
        last edited by

        If you are talking about the message 'VPN Connection' with buttons OK and disconnect that iOS shows after connection is established then I don't think there is a way to disable that.

        1 Reply Last reply Reply Quote 0
        • H
          hagak
          last edited by

          Thanks for the guide using it and iphone Configuration utility I was able to setup my iphone with VPN on demand, which is a slick feature with one issue.  I can not figure out how to make it save my password.  Everytime I connect to the VPN it prompts for the user password.  It appears if you create the VPN connection on the phone manually via this guide it will save the user password, however if you do it via the iphone configuration utility I do not see a way to save the password.

          Any ideas?

          1 Reply Last reply Reply Quote 0
          • T
            twaldorf
            last edited by

            @hagak:

            Thanks for the guide using it and iphone Configuration utility I was able to setup my iphone with VPN on demand, which is a slick feature with one issue.  I can not figure out how to make it save my password.  Everytime I connect to the VPN it prompts for the user password.  It appears if you create the VPN connection on the phone manually via this guide it will save the user password, however if you do it via the iphone configuration utility I do not see a way to save the password.

            Any ideas?

            Create an unsigned .mobileconfig and edit it with any text editor. Add these two lines behind the XAuthName-Block:

            <key>XAuthPassword</key> 
            <string>Your Password</string>
            

            Best regards,

            Thorsten

            1 Reply Last reply Reply Quote 0
            • H
              hagak
              last edited by

              Sweet will give that a shot this info.  Odd that if the configs support such a feature that the tool would not have the interface to use it.  Course Apple is known for lack of options.

              1 Reply Last reply Reply Quote 0
              • T
                twaldorf
                last edited by

                @hagak:

                Odd that if the configs support such a feature that the tool would not have the interface to use it.  Course Apple is known for lack of options.

                I think it's just because everybody could read the password as clear text…

                1 Reply Last reply Reply Quote 0
                • H
                  hagak
                  last edited by

                  @twaldorf:

                  @hagak:

                  Odd that if the configs support such a feature that the tool would not have the interface to use it.  Course Apple is known for lack of options.

                  I think it's just because everybody could read the password as clear text…

                  Well there are ways they could encrypt the password to at least make it more difficult to see.

                  1 Reply Last reply Reply Quote 0
                  • H
                    hagak
                    last edited by

                    @twaldorf:

                    Create an unsigned .mobileconfig and edit it with any text editor. Add these two lines behind the XAuthName-Block:

                    <key>XAuthPassword</key> 
                    <string>Your Password</string>
                    

                    Best regards,

                    Thorsten

                    This did not seem to work.  I assume after I edit the file I open the file with iphone configurator to load it on the iphone.

                    1 Reply Last reply Reply Quote 0
                    • H
                      hagak
                      last edited by

                      If I export the conf back out the added lines are not there

                      1 Reply Last reply Reply Quote 0
                      • H
                        hagak
                        last edited by

                        I figured it out:)

                        You need to email the mobileconfig file to your phone and install it via the email on the phone.  Success.

                        1 Reply Last reply Reply Quote 0
                        • S
                          seattle-it
                          last edited by

                          For whatever reason, racoon segfaults when I run RSA+Xauth after the client sends back the XAUTH_USER_PASSWORD. This doesn't happen with PSK+Xauth oddly. >:(

                          My tech blog - seattleit.net/blog

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.