IPSEC VPN from Android using certificate
Hi,
FortiClient VPN on Android 16 disconnects immediately after a successful IKEv2 certificate authentication against a FortiGate 101F running FortiOS 7.4.12.
FortiGate debug shows:
certificate validation succeeded
signature verification succeeded
authentication succeeded
mode-cfg assigned IPv4 address 10.242.221.100
added IPsec SA
tunnel up event assigned address 10.242.221.100
Â
Immediately after that, the Android client sends:
received informational request
processing delete request (proto 1)
deleting IKE SA
FortiClient Android only shows:
START → STARTED → TUNNELLING → ERROR → DISCONNECTED
Â
No useful error is displayed. Logs show:
authenticationFailure false
connectionFailure false
failureReason null
Â
The same VPN configuration works perfectly from Windows.
DNS changes, send-cert-chain disable, and fragmentation changes did not change the behaviour.
Â
The FortiGate uses a wildcard server certificate. Client certificate authentication is successful.
Has anyone seen Android 16 / FortiClient Android immediately delete the IKE SA after successful certificate auth?Â
Unable to configure it on iPhone too... Doesn't see the certificate in the store.
Â
Thank you in advance for your help because it’s mandatory to migrate to 7.6 too.
