Created on
05-26-2025
11:07 PM
Edited on
09-19-2025
12:23 AM
By
Jean-Philippe_P
Description | This article describes how to create an IPsec VPN IKEv2 between FortiGate and FortiClient VPN in IOS devices. |
Scope | FortiGate v7.2 and later; FortiClient VPN (including iOS/iPadOS, macOS, etc.). |
Solution |
In IOS native VPN settings, it is not possible to directly configure the IKEv2 encryption/integrity/PRF ciphers.
FortiClient download link: Product Downloads | Fortinet Product Downloads | Support
Related articles: Technical Tip: Apple IOS native VPN using IKEv2 connection for IPsec VPN to FortiGate Technical Tip: iPhone and iPad Dialup User IPsec VPN sample configuration
Select 'Connection' and 'Add Configuration':
Select 'Secure Protocol' as 'IKEV2 VPN' and provide 'Name' as the IPsec Remote VPN name configured on FortiGate. Mention the 'Server Address' as the interface IP of the IPsec VPN and set the same 'pre-shared key'.
In case of remote IPsec VPN, select 'Secure Protocol' as 'SSL VPN'.
Select the phase1 and phase2 ciphers and Lifetime matching with FortiGate settings:
Mention the username at the bottom and save the settings.
Go back to the VPN first page and select 'Connect'. It will ask for the password for the username 'Mac-user'. It is now possible to connect to the Remote IPsec VPN.
Note:
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.