Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec client mobile

    Scheduled Pinned Locked Moved IPsec
    8 Posts 3 Posters 789 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sasa1
      last edited by

      Hi, I have already a "Site to Site VPN connection" with IPSec protocol and now I need to also access through an IPSec client on Windows 10.
      In pfSense I enabled:
      "Enable IPsec Mobile Client Support"
      as shown in the attached image.
      Then I specified a "Pre-Shared Keys" and configured the phase2 (as shown in the attached image).
      In Windows 10 I configured the VPN client but when I try to connect to the VPN server immediately an error message appears:

      "L2tp connection attempt failed.
      the security level cannot negotiate the parameters compatible with the remote computer"

      where am I wrong ?
      Thanks.
      mobile.PNG phase2 mobile.PNG

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Sounds like Windows is not attempting IKEv2 but L2TP instead. I'd look at the client:

        https://docs.netgate.com/pfsense/en/latest/book/ipsec/mobile-ipsec-client-windows.html?windows-ikev2-client-configuration

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • S
          sasa1
          last edited by

          Hi,
          I'm not using the digital certificate.
          Thanks.

          markbroeM 1 Reply Last reply Reply Quote 0
          • markbroeM
            markbroe @sasa1
            last edited by markbroe

            @sasa1

            Sounds like there is a mismatch with the encryption algorithms you have configured on your tunnel.

            Take a look at at the IPSec log (Status / System logs / IPSec) for "received proposals" and "configured proposals" to see which algorithms you client can use and which are configured on the tunnel.

            proposedcongifured.PNG

            You may also have to make adjustments to the encryption and hashing in Phase 2, to ensure that they are supported by your client.

            Examining the log I found the config below, with two supported algorithms for Pase 1, to work with both my Window 10 client and my iPhone - but your mileage may vary :-)

            tunnel.PNG

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Transport mode for mobile IPsec? That would be a first for me.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              markbroeM 1 Reply Last reply Reply Quote 0
              • S
                sasa1
                last edited by

                Hi,
                thanks but for now i have preferred to use openvpn.

                1 Reply Last reply Reply Quote 0
                • markbroeM
                  markbroe @Derelict
                  last edited by

                  @Derelict

                  I'm only just getting into psSense myself, and was following a tutorial, but could not get the setup to work.
                  I was looking for help myself, when I came across this problem that I had just spent time figuring out myself and thought that I would share :-)

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Yeah you almost certainly want tunnel mode there, not transport.

                    It really depends on the mix of intended VPN clients but if I had to use IPsec instead of OpenVPN for some reason I would try to get IKEv2 working first.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.