Created on
09-10-2025
10:29 AM
Edited on
09-14-2025
11:08 PM
By
Jean-Philippe_P
Description | This article describes why Android devices are unable to connect using IKEv2 with Username and Password with a Preshared key used as an authentication method. |
Scope | FortiOS, FortiClient Android. |
Solution |
When connecting to an IPsec IKEv2 dial-up VPN using FortiClient on Android, the tunnel fails to establish and returns the following output when running IKE debugs:
diagnose vpn ike log filter name <tunnel name > diagnose deb application ike -1 diagnose deb enable .... ike V=root:0:MAIN_IKEV2_CLI:144510: responder received AUTH msg
Example of misconfigured Phase 1 setup:
edit "MAIN_IKEV2_CLI" set authusrgrp "VPN_USERS"
While the ike debug shows the connection failed due to gateway validation, the connection on FortiGate will show as active. However, the connection on the Android device shows as failed.
Tunnel showing as established on FortiGate:
diagnose vpn tunnel list name MAIN_IKEV2_CLI
In this case, authentication is configured using a pre-shared key combined with Username and Password, which is not compatible with FortiClient on Android when using IKEv2 with EAP.
FortiClient (Android) supports IPsec VPN using either pre-shared key or X.509 certificate-based authentication, but does not support combining PSK with EAP (Username/Password).
If only a pre-shared key is used and EAP is disabled, the tunnel will connect successfully, as Username/Password authentication will not be triggered.
If Username and Password authentication is required, then certificate-based authentication should be used instead, as FortiClient (Android) supports X.509 certificates for IPSEC.
To configure IPsec Dial-up VPN using signature-based authentication, see Dial-up IPsec VPN with certificate authentication.
For further information on authentication methods supported by Android clients, see Creating an IPsec VPN IKEv2 connection. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.