Skip to main content
paul_slegg
New Member
October 22, 2015
Solved

IPSEC IOS Help

  • October 22, 2015
  • 3 replies
  • 3594 views

Hi

 

I am struggling with setting up a VPN connection from IOS devices to my internal network (Fortigate firewall 500D)

 

I started by using SSL VPN, but found the IOS app was next to useless, as it doesn't support tunneling and as soon as you close the app, you lose the VPN. 

 

I started looking into IPSEC via the IOS Dialup, but cannot get my head around it. My knowledge of IPSEC was that it requires a source IP and destination IP, however, with the mobile devices constantly on the road, near on impossible to lock down the devices IP. It seems IPSEC IOS doesnt require this, but i am lost to understand how it authenticates the tunnel between the devices? 

 

Any help to get my head around this would be much appreciated. 

 

Thanks

 

Paul

    3 replies

    gschmitt
    gschmittAnswer
    New Member
    October 22, 2015
    paul_slegg
    New Member
    October 22, 2015

    Thanks for the reply. 

     

    The process of the setup i am ok with, it is more understanding how this can work from a security side of things, is their a virtual remote gateway that acts as the source IP?   

    gschmitt
    New Member
    October 22, 2015

    Depends on your service provider. Mobile devices do have an external IP address. That IP address is often shared tho.

    In my country the devices usually connect to a gateway which handles around 10 devices per IP and manages the connection, similar to NAT.

    An IPSec Tunnel set to Dial-Up does not require a static source IP address hence any IP can establish the connection.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.