IKEv2/IPSec VPN server to connect Android 12 clients to the network.
IKEv2/IPSec VPN server to connect Android 12 clients to the network.
Dear members / technicians,
On Android 12 the old VPN types: PPTP and L2TP are no longet supported.
Only IKEv2/IPSec PSK, IKEv2/IPSec RSA, and IKEv2/IPSec MSCHAPv2, types are available.
Is there a tutorial, or example available, how to configurate VPN server for this IKEv2/IPSec VPN types?
I'm running a complete Omada network controlled by OC200. I can't get it work for now.
Hope someone can help me any further.
Best regards,
Alex
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Hi Stef,
Unfortunately I didn't get it working. The VPN connection from android 12 (now android 13) works fine, but I still can't access the internet from the VPN network. I actually didn't go any further with the issue either because it wasn't important enough for me. It should be possible to solve it but I didn't succeed.
I am happy with the Omada network. It is very stable and reliable. The only issues I have is the Internet connection from VPN connected clients and the fact that it's not possible to configure my own DynDNS provider.
Regards,
Alex
- Copy Link
- Report Inappropriate Content
@Intrax Hi! using you proposition it works!
I manage to connect without the user - as it's not possible to define a user for IPsec (ER7206, SW: 1.3.0).
However - no internet access as well.
Do you have double NAT in your setup? Once I've seen the information that there is some problem in such setup - this could be it (I am behind double NAT).
Thank you anyway!
- Copy Link
- Report Inappropriate Content
The crucial setting which determines whether it works or not is Remote ID Type:
(IP Address works, Name doesn't work)
I am suggesting NAT as this tutorial:
https://www.tp-link.com/pl/support/faq/3447/
says following:
Even though I am behind NAT it partially works. This is why I blame NAT for no internet access.
I am not able to ping my WAN IP (which is ISP's router) from the VPN tunnel, which suggests no communication.
- Copy Link
- Report Inappropriate Content
anyway I'll stick to OpenVPN as it works fine.
Maybe expect max throughput which is 34 Mb/s (ER7206 v1)
- Copy Link
- Report Inappropriate Content
Hi Fofix,
Thanks for your comment.
I am not using double NAT. My ER605 v1 is connected directly to the internet via an MC220L converter (RJ45 to Fiber).
Tonight I checked my configuration again, but I don't see any wrong settings.
Unfortunately, it is still not possible to access the internet from a VPN connection.
The VPN connection from my Samsung A53 device (Android 13) only stays in the local network.
That's really a pity,
Maybe I should wait for new firmware for the ER605 v1 router that supports SHA2.
Regards,
Alex
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
I got it working following the example from Intrax (post#6). I would like to point out a few things in case it isn't clear enough:
You have to create a vpn user despite the android client does not expect an user. And you have to provide a password when creating the user but the password is not actually used anywhere. You also cannot choose ipsec as the vpn server type, so just leave it blank.
On your android phone you enter the pre-shared key you used when you create the vpn profile (not the vpn user password), and put the vpn user name in the "IPSec identifier" even it explicitly says that it isn't being used.
I am using omada software controller 5.7.4 with a er605 v2
- Copy Link
- Report Inappropriate Content
You're right. That part isn't very clear, thanks for the update.
The only problem that remains is that you can no longer connect to the Internet from the VPN server connection.
That's why I use OpenVPN.
The speed may not be great, but it works well and it is stable.
regards Alex
- Copy Link
- Report Inappropriate Content
Thanks for the tips everyone... For my situation (see below) I had sucess using the Phase1 Proposal set to "SHA-256 - AES256 - DH14" and Phase 2 Proposal set to ESP - SHA-256 - AES256
Android 14
Controller Version: 5.12.9 Model: OC200 1.0 Firmware Version: 1.26.3 Build 20230906 Rel.36269
Router: ER605 v1.0 Firmware: 1.3.0 Build 20230511 Rel.51317
- Copy Link
- Report Inappropriate Content
Information
Helpful: 2
Views: 18655
Replies: 19