<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IOS mobile IPSec connectivity [screenshots]]]></title><description><![CDATA[<p dir="auto">Hi folks,</p>
<p dir="auto">I've read most of the threads on this forum with the keywords "IPSec" and "iOS" in them and I just can't get this setup to work for me. Running 2.0.2-RELEASE.</p>
<p dir="auto">I've taken screenshots of what I think are all of the relavent sections… I'm able to connect from my iOS devices but unable to route anywhere (can't load the web interface for pfSense or google.com).</p>
<p dir="auto">Screenshots to follow...</p>
<p dir="auto">Firewall rule:<br />
<img src="http://f.cl.ly/items/432z1I0i0t2C3o2L1j2S/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">IPSec enabled:<br />
<img src="http://f.cl.ly/items/133K390B471e1E0q3o3h/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">p1 part 1:<br />
<img src="http://f.cl.ly/items/1u0F1W020p3K162a0K2B/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">p1 part 2:<br />
<img src="http://f.cl.ly/items/3o0o0U222v3B05004508/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">p2:<br />
<img src="http://f.cl.ly/items/3I2a143H0c3h1N2g282a/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">SAD (after multiple attempts) – note that even if I reboot racoon to clear these out and only have two entries I get the same results:<br />
<img src="http://f.cl.ly/items/3J2u11143Z0I011i3U11/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">SPD:<br />
<img src="http://f.cl.ly/items/0R3O3B2B2Z003Q181Z0d/Grab.png" alt="" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/52120/ios-mobile-ipsec-connectivity-screenshots</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 05:38:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/52120.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 19 Jan 2013 05:45:44 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Mon, 04 Feb 2013 20:54:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a>:</p>
<blockquote>
<p dir="auto">make sure the client(s) are also set to use NAT-T, and make sure nothing is blocking UDP/4500 between the clients and the firewall</p>
</blockquote>
<p dir="auto">Clients are iOS 6 devices on 3G, so no in-depth settings there. Firewall is open:<br />
https://www.evernote.com/shard/s12/sh/659a1b61-92b4-470e-8d3c-f6c40616ce51/24d11db24ce72f1e9383166dfdcdb1e4/deep/0/Screenshot%202/4/13%204:00%20PM.jpg</p>
]]></description><link>https://forum.netgate.com/post/376910</link><guid isPermaLink="true">https://forum.netgate.com/post/376910</guid><dc:creator><![CDATA[bwoodruff]]></dc:creator><pubDate>Mon, 04 Feb 2013 20:54:22 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Mon, 04 Feb 2013 20:46:06 GMT]]></title><description><![CDATA[<p dir="auto">make sure the client(s) are also set to use NAT-T, and make sure nothing is blocking UDP/4500 between the clients and the firewall</p>
]]></description><link>https://forum.netgate.com/post/376906</link><guid isPermaLink="true">https://forum.netgate.com/post/376906</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 04 Feb 2013 20:46:06 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Mon, 04 Feb 2013 20:31:42 GMT]]></title><description><![CDATA[<p dir="auto">Unfortunately this doesn't work for me. If I set NAT-T to "Force," clients are unable to connect (at all).</p>
]]></description><link>https://forum.netgate.com/post/376899</link><guid isPermaLink="true">https://forum.netgate.com/post/376899</guid><dc:creator><![CDATA[bwoodruff]]></dc:creator><pubDate>Mon, 04 Feb 2013 20:31:42 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Mon, 04 Feb 2013 20:05:43 GMT]]></title><description><![CDATA[<p dir="auto">The Cisco VPN client is one that is only likely to work once, and never again, until you restart racoon. Also by using the Cisco client to connect to a non-Cisco device, you're technically violating the terms of its license agreement.</p>
<p dir="auto">Make sure that you have:<br />
(Phase 1)<br />
Policy Generation: Unique<br />
Proposal Checking: Strict</p>
<p dir="auto">System &gt; Advanced, Miscellaneous tab.<br />
Uncheck "Prefer Old IPsec SA"</p>
]]></description><link>https://forum.netgate.com/post/376881</link><guid isPermaLink="true">https://forum.netgate.com/post/376881</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 04 Feb 2013 20:05:43 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Wed, 30 Jan 2013 09:25:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/spi">@<bdi>spi</bdi></a>:</p>
<blockquote>
<p dir="auto">Also work with Cisco VPN client on PC's</p>
</blockquote>
<p dir="auto">Which version?  I've NEVER got it to work!  Currently using 5.0.07.0410</p>
]]></description><link>https://forum.netgate.com/post/375768</link><guid isPermaLink="true">https://forum.netgate.com/post/375768</guid><dc:creator><![CDATA[jonallport]]></dc:creator><pubDate>Wed, 30 Jan 2013 09:25:24 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Wed, 30 Jan 2013 09:21:52 GMT]]></title><description><![CDATA[<p dir="auto">This is my (working) config - works with iOS 5.x, 6.0.x &amp; 6.1 so far.</p>
<p dir="auto">Some redactions for obvious reasons!</p>
<p dir="auto">PS.  There is a DNS resolution bug in iOS 6.0.x, now resolved in 6.1 that may also have caused  problems: no DNS lookups for .local using VPN over cellular.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/P1.PNG" alt="P1.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/P1.PNG_thumb" alt="P1.PNG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/P2.PNG" alt="P2.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/P2.PNG_thumb" alt="P2.PNG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Ext.PNG" alt="Ext.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Ext.PNG_thumb" alt="Ext.PNG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/User.PNG" alt="User.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/User.PNG_thumb" alt="User.PNG_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Firewall.PNG" alt="Firewall.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Firewall.PNG_thumb" alt="Firewall.PNG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/375765</link><guid isPermaLink="true">https://forum.netgate.com/post/375765</guid><dc:creator><![CDATA[jonallport]]></dc:creator><pubDate>Wed, 30 Jan 2013 09:21:52 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Tue, 29 Jan 2013 16:57:13 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for the suggestion. I made that change, but it had no effect. The clients still connect, but no traffic is passed.</p>
]]></description><link>https://forum.netgate.com/post/375614</link><guid isPermaLink="true">https://forum.netgate.com/post/375614</guid><dc:creator><![CDATA[bwoodruff]]></dc:creator><pubDate>Tue, 29 Jan 2013 16:57:13 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Tue, 29 Jan 2013 16:40:14 GMT]]></title><description><![CDATA[<p dir="auto">Hi bwoodruff</p>
<p dir="auto">my own IOS VPN integration is almost exactly as yours and works from iPads…iphones. OSX os's and so on.<br />
Also work with Cisco VPN client on PC's</p>
<p dir="auto">ive added a diff screenshot in the P1 configuration. When not set as i have it now...IOS devices cant connect.</p>
<p dir="auto">see the attachment</p>
<p dir="auto">![Skærmbillede 2013-01-29 kl. 17.42.44.png](/public/<em>imported_attachments</em>/1/Skærmbillede 2013-01-29 kl. 17.42.44.png)<br />
![Skærmbillede 2013-01-29 kl. 17.42.44.png_thumb](/public/<em>imported_attachments</em>/1/Skærmbillede 2013-01-29 kl. 17.42.44.png_thumb)</p>
]]></description><link>https://forum.netgate.com/post/375609</link><guid isPermaLink="true">https://forum.netgate.com/post/375609</guid><dc:creator><![CDATA[spi]]></dc:creator><pubDate>Tue, 29 Jan 2013 16:40:14 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Sun, 27 Jan 2013 16:19:28 GMT]]></title><description><![CDATA[<p dir="auto">Hi Sparky,</p>
<p dir="auto">Thanks for the suggestions but unfortunately neither work.</p>
<p dir="auto">With NAT-T set to Force, the devices can no longer connect at all. With the sending available routes box checked, traffic routes around the VPN tunnel instead of through it (it goes out over 3G/WiFi).</p>
]]></description><link>https://forum.netgate.com/post/375119</link><guid isPermaLink="true">https://forum.netgate.com/post/375119</guid><dc:creator><![CDATA[bwoodruff]]></dc:creator><pubDate>Sun, 27 Jan 2013 16:19:28 GMT</pubDate></item><item><title><![CDATA[Reply to IOS mobile IPSec connectivity [screenshots] on Sun, 27 Jan 2013 01:17:37 GMT]]></title><description><![CDATA[<p dir="auto">2 things to try, try enable or Force the NAT Traversal under the Advance Options. The other thing which I don't see in your screenshots, there's a tick box somewhere related to sending available routes to the client or something along those lines. Try untick that. With that ticked I was finding that after bringing up the VPN on my iPad, traffic was just being sent straight out of it's wifi interface and not down the tunnel.</p>
]]></description><link>https://forum.netgate.com/post/375045</link><guid isPermaLink="true">https://forum.netgate.com/post/375045</guid><dc:creator><![CDATA[Sparky]]></dc:creator><pubDate>Sun, 27 Jan 2013 01:17:37 GMT</pubDate></item></channel></rss>