Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN for iOS - Finally Available!

    Scheduled Pinned Locked Moved OpenVPN
    52 Posts 17 Posters 44.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      Yeah there's not a ton of room there to write it all out. I had to make room to put in what is there. I'm hoping someone is smart enough that if they installed OpenVPN Connect they'll at least consider the option of clicking the name of the client they did install.

      Or they'll be smarter and not install OpenVPN Connect on Android :p

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • A
        asterix
        last edited by

        Well I tried OpenVPN for Android.. as you recommended.. now I get this error while importing the android config

        Error reading config file
        Option tls-remote has 2 parameters, expected between 1 and 1

        Moving back to my iOS config on the Android. That works on this new client as well.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          check the box to quote the server cn before exporting.

          And in the future, don't put spaces in your certificate common names. :-)

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • A
            asterix
            last edited by

            Finally.. that worked. Thanks!

            Why is the iOS config not affected by the space?

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              It doesn't support tls-remote so that line is left out entirely for the OpenVPN Connect config.

              The OpenVPN connect config will also work in the OpenVPN for Android client but it is missing a few lines that can be beneficial for security reasons (like tls-remote)

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • J
                JoeGTN1
                last edited by

                My fix to continual:

                Jan 21 13:38:51 openvpn[26787]: xyz123/xxx.xxx.xxx.xxx:xxxxx TLS Error: incoming packet authentication failed from [AF_INET]xxx.xxx.xxx.xxx:xxxxx
                Jan 21 13:38:51 openvpn[26787]: xyz123/xxx.xxx.xxx.xxx:xxxxx Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #120 / time = (1358793515) Mon Jan 21 13:38:35 2013 ] – see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings

                Was to not use: reneg-sec 0 in the client config.  Most clients think this means to use what the server uses.  Apparently iOS and Android think this means just keep renegotiating forever. reneg-sec 21600 works fine.  It would be nice if renegotiation didn't require re-entry of a (new) OTP…

                1 Reply Last reply Reply Quote 0
                • X
                  x2desmit
                  last edited by

                  I can't believe how easy this was. Worked the first time, except for a restrictive firewall rule. This is great work!  8)

                  1 Reply Last reply Reply Quote 0
                  • T
                    trans_lux
                    last edited by

                    Wow works great!
                    Am I missing something or can you only have one profile in the phone/app at a time?
                    Every time I import another cofig for a different router it blows out the one that's installed.

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      Do your firewalls have unique hostnames? I thought I had multiple profiles in the other day when testing, but I think all of mine had different hostnames and thus different exported filenames and such.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • T
                        trans_lux
                        last edited by

                        Yes different host names, confirmed on the iPad as well, only one profile at a time ???

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          I currently have 4 profiles to the same box.  One is tcp on 443, and other is udp on standard 1194 port.  Then 2 more with those same settings other routing all traffic through the vpn.

                          You could have as many configs as you would I would think all pointing to the same server if you just just call the ovpn file something different for import.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • A
                            athurdent
                            last edited by

                            There's an update for the iPhone Configuration Utility, OpenVPN can now be preconfigured, too.

                            1 Reply Last reply Reply Quote 0
                            • J
                              JanG
                              last edited by

                              Hello,

                              the default config works well since my first try. Nice Work!
                              Just one Question: Is is possible to require a password before the VPN-Connection is established?

                              Jan

                              1 Reply Last reply Reply Quote 0
                              • jimpJ
                                jimp Rebel Alliance Developer Netgate
                                last edited by

                                If you use user auth on the server side, and you don't save the password on the client side, yes.

                                If you are only doing certificate auth, probably not.

                                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                Need help fast? Netgate Global Support!

                                Do not Chat/PM for help!

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.