FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Nishtha_Baria
Article Id 350451
Description This article describes how to use the Require 'Group Name' on the VPN client option when constructing an iOS dial-up tunnel to add a peer ID. 
Scope FortiGate.
Solution

The following example showcases a scenario where the option Require 'Group Name' on the VPN client is disabled, the tunnel is created, and there is no option to add peer ID via the CLI. Converting the tunnel to a custom tunnel allows the inclusion of peerID:

 

Nishtha_Baria_0-1729256631994.png

 

Nishtha_Baria_1-1729256631997.png

 

Nishtha_Baria_2-1729256631998.png

 

However, there is a setting that allows adding the peer ID while creating an iOS tunnel without turning it into a custom tunnel.

 

The step to add the peer ID while creating a tunnel is as below:

 

  1. Create the tunnel with the usual settings for iOS, like giving it a name, template type as Remote access, and remote device type as Native-iOS Native.
                                                 
Nishtha_Baria_4-1729256632001.png

 

  1. After pressing Next, there is an option labeled Require 'Group Name' on the VPN client on the next page, with a checkbox next to it.
                                  
Nishtha_Baria_5-1729256632003.png

 

  1. Once the checkbox is selected, the Group Name (peerid) becomes available, along with a text box that lets the user enter the peer.
                                                                                       
Nishtha_Baria_6-1729256632005.png

 

Nishtha_Baria_7-1729256632007.png

 

  1. Once a peerID has been added normally, configure the tunnel as required. After, the peer ID will be displayed on the tunnel configuration.

 

Nishtha_Baria_8-1729256632009.png

 

Before FortiOS version 7.6.3, using an IPv4 address as a Peer ID is not supported for IPsec VPN tunnels.
This feature is available starting from version 7.6.3 but will not be backported to earlier versions.
If upgrading to version 7.6.3 is not possible, it is recommended to configure the remote peer to use either FQDN or KEYID as the ID type.