1
23.7 Legacy Series / Re: How to configure IPsec for mobile clients new way (via connections)?
« on: September 04, 2023, 11:13:30 am »
Thanks.
I succeed configure new way IPsec using examples from here.
So, configuration is following (see screenshot attachments).
What I learned from logs (and missed early) that is both authentication is required (local + remote). Local I use "Public key" method, certificate is usable here. Remote - using pre-defined PSK with EAP type.
On mobile client side (I use strongSwan for android) is required to add root CA and server certificate to local storage and specify server's cert in connection settings.
This works for me.
I succeed configure new way IPsec using examples from here.
So, configuration is following (see screenshot attachments).
What I learned from logs (and missed early) that is both authentication is required (local + remote). Local I use "Public key" method, certificate is usable here. Remote - using pre-defined PSK with EAP type.
On mobile client side (I use strongSwan for android) is required to add root CA and server certificate to local storage and specify server's cert in connection settings.
This works for me.