• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

iOS / IPsec Connection Error

Scheduled Pinned Locked Moved IPsec
5 Posts 2 Posters 807 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rchiocchio
    last edited by Dec 6, 2022, 2:07 PM

    Setting up a brand new Netgate 1100 for a customer's site for use with iOS devices and remote access. I followed the Configuring IPsec IKEv2 Remote Access VPN Clients doc and got everything set up, certs installed on the initial iOS device for testing. Seems like I'm able to get all the way through the connection until the very end where I'm getting an "generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]" error message. Not really sure at this point where the failure is; in the Authentication settings of the VPN on the phone I'm using the username and password set up under VPN / IPsec / Pre-Shared Keys.

    A bit of looking around I found this may be because the IP address I'm connecting from is not configured in the tunnel; I doubt any of my customer's home locations have static IP addresses, so I guess my question is what are my options if that is the case?

    VPNError-001.txt

    ipsec_phase1.png

    ipsec_phase2.png

    N 2 Replies Last reply Dec 6, 2022, 5:10 PM Reply Quote 0
    • N
      NogBadTheBad @rchiocchio
      last edited by Dec 6, 2022, 5:10 PM

      @rchiocchio Look at the My id & Peer id, you've got IP addresses in the FQDN field and Peer Id.

      Change the Peer id to Any.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      R 1 Reply Last reply Dec 6, 2022, 5:29 PM Reply Quote 1
      • N
        NogBadTheBad @rchiocchio
        last edited by NogBadTheBad Dec 6, 2022, 5:18 PM Dec 6, 2022, 5:18 PM

        @rchiocchio I use EAP-RADIUS with the following settings and can connect fine with IOS devices, I also tunnel everything over the VPN:-

        VPN: IPsec: Mobile Clients: Edit Phase 1.png

        I've blanked out the FQDN & Cert name.

        VPN: IPsec: Mobile Clients: Edit Phase 2.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • R
          rchiocchio @NogBadTheBad
          last edited by rchiocchio Dec 6, 2022, 6:25 PM Dec 6, 2022, 5:29 PM

          @nogbadthebad whoops, that was the wrong screenshot. Here's an updated one:

          ipsec_phase1.png

          Looks like changing My Identifier to My IP Address and Peer Identifier to Any did the trick.

          Now I can work on getting the local DNS entries working, since my access to the local subnet works via IP (but need to use the locally defined dns names).

          Thanks! (will mark as resolved once I can confirm the actual devices I'm trying to configure are all set)

          1 Reply Last reply Reply Quote 0
          • R
            rchiocchio
            last edited by rchiocchio Dec 14, 2022, 2:43 PM Dec 14, 2022, 2:03 PM

            An update on this; the above settings still being the same, I cannot get the connected devices to use the firewall/DNS resolver when doing a lookup/attempting to connect to any of the devices on the LAN via hostname. Also attached a screenshot of the DNS Resolver settings in case I'm missing anything. I just get the generic "A server with the specified hostname could not be found" message when trying to connect.

            dnsResolverGeneral.png

            For reference, the Netgate itself is able to ping anything in the DNS Resolver list by name without any issue:

            netgateDNSTest.PNG

            1 Reply Last reply Reply Quote 0
            • R rchiocchio referenced this topic on Dec 14, 2022, 3:07 PM
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              [[user:consent.lead]]
              [[user:consent.not_received]]