Page 1 of 1

iOS9 is not working with IPSec

Posted: Thu Aug 25, 2016 4:31 pm
by moatazelmasry
Hi all,

I'm trying to connect using my iphone to a softether server.
I'm setting up a vpn connection on iphone using the GUI. Setting the vpn type to IPSec.
When starting the vpn connection, I get the error:
"The VPN Server did not respond"
On the server side I'm getting the error:
"There are no acceptable transform proposals from the client for establishing an IKE SA."

Using the exact same configuration on iOS but using L2TP instead is working fine. I guess this is a very specific problem related to the iphone
I have iOS 9.3.4

Here are the server logs:
"
2016-08-25 16:11:26.665 IPsec Client 11 (xx:500 -> xx:500): A new IPsec client is created.
2016-08-25 16:11:26.665 IPsec Client 11 (xx:500 -> xx:500): There are no acceptable transform proposals from the client for establishing an IKE SA.
2016-08-25 16:11:29.950 IPsec Client 12 (xx:500 -> xx:500): There are no acceptable transform proposals from the client for establishing an IKE SA.
2016-08-25 16:11:36.936 IPsec Client 11 (xx:500 -> xx:500): This IPsec Client is deleted.
"

Any ideas what is happening?
Does anyone know for a fact that SoftEther IPSec is working fine on iOS??

Cheers

Re: iOS9 is not working with IPSec

Posted: Mon Aug 29, 2016 10:11 pm
by moatazelmasry
I found the problem.
I was using IPSec on iPhone, while softether supports L2TP over IPSec.
Using L2TP protocol on the ipone solved the problem

Follows question:
Can I get a pure IPSec configuration running on softether? (i.e. without L2TP, for example like in strongswan)

Re: iOS9 is not working with IPSec

Posted: Mon Sep 12, 2016 5:14 am
by thisjun
SoftEether support only L2TP/IPSec.

Re: iOS9 is not working with IPSec

Posted: Sat Feb 29, 2020 5:21 pm
by MyronSz
moatazelmasry wrote:
Mon Aug 29, 2016 10:11 pm
I found the problem.
I was using IPSec on iPhone, while softether supports L2TP over IPSec.
Using L2TP protocol on the ipone solved the problem

Follows question:
Can I get a pure IPSec configuration running on softether? (i.e. without L2TP, for example like in strongswan)
Erm... If you use L2TP without IPSec then, if I understand this right, the tunnel between your iPhone and the VPN server is unencrypted and as such, not secure?