hoping someone can give me any pointers.
Trying for the life of me to set up IoS VPN and am hitting a brick wall.
I believe i am getting through phase 1 & 2 but getting stuck somewhere...
The iphone just times out..
Doing diagnose debug application ike -1
I get...
ike 0:iphonevpn_0:18: mode-cfg type 1 request 0:''
ike 0:iphonevpn_0:18: mode-cfg using allocated IPv4 10.10.10.1
ike 0:iphonevpn_0:18: mode-cfg type 2 request 0:''
ike 0:iphonevpn_0:18: mode-cfg type 3 request 0:''
ike 0:iphonevpn_0:18: mode-cfg type 4 request 0:''
ike 0:iphonevpn_0:18: mode-cfg WINS ignored, no WINS servers configured
ike 0:iphonevpn_0:18: mode-cfg type 5 request 0:''
ike 0:iphonevpn_0:18: mode-cfg type 7 request 41:'436973636F2053797374656D732056504E20436C69656E742031312E322E363A6950686F6E65204F53'
ike 0:iphonevpn_0:18: mode-cfg received APPLICATION_VERSION Cisco Systems VPN Client 11.2.6:iPhone OSp
ike 0:iphonevpn_0:18: mode-cfg type 28672 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28672 requested
ike 0:iphonevpn_0:18: mode-cfg no banner configured, ignoring
ike 0:iphonevpn_0:18: mode-cfg type 28674 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28674 requested
ike 0:iphonevpn_0:18: mode-cfg no domain configured, ignoring
ike 0:iphonevpn_0:18: mode-cfg type 28675 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28675 requested
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28675 not supported, ignoring
ike 0:iphonevpn_0:18: mode-cfg type 28676 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28676 requested
ike 0:iphonevpn_0:18: mode-cfg type 28678 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28678 requested
ike 0:iphonevpn_0:18: mode-cfg type 28679 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28679 requested
ike 0:iphonevpn_0:18: mode-cfg type 28673 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28673 requested
ike 0:iphonevpn_0:18: mode-cfg type 28680 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28680 requested
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28680 not supported, ignoring
ike 0:iphonevpn_0:18: mode-cfg type 28681 request 0:''
ike 0:iphonevpn_0:18: mode-cfg UNITY type 28681 requested
ike 0:iphonevpn_0:18: mode-cfg no backup-gateway configured, ignoring
ike 0:iphonevpn_0:18: mode-cfg type 28683 request 0:''
ike 0:iphonevpn_0:18: mode-cfg attribute type 28683 not supported, ignoring
ike 0:iphonevpn_0:18: mode-cfg assigned (1) IPv4 address 10.10.10.1
ike 0:iphonevpn_0:18: mode-cfg assigned (2) IPv4 netmask 255.255.255.0
ike 0:iphonevpn_0:18: mode-cfg send (3) IPv4 DNS(1) 212.159.6.9
ike 0:iphonevpn_0:18: mode-cfg send (3) IPv4 DNS(2) 212.159.6.10
ike 0:iphonevpn_0:18: PFS is disabled
ike 0:iphonevpn_0:18: mode-cfg send (28676) IPv4 subnet 0.0.0.0/0.0.0.0 port 0 proto 0
ike 0:iphonevpn_0:18: mode-cfg send APPLICATION_VERSION 'FortiWiFi-60E v5.6.3,build1547b1547,171204 (GA)'
ike 0:iphonevpn_0:18: mode-cfg INTERNAL_ADDRESS_EXPIRY ignored, address does not expire
ike 0:iphonevpn_0:18: include-local-lan is disabled
ike 0:iphonevpn_0:18: client save-password is disabled
ike 0:iphonevpn_0:18: enc BD60C4F396D24721326FC960AE3972D008100601E9CCB513000000CD0E00004412639C944011CF608BE6C643A490053CBC87247B10D86FD759F4C9DAEDBD5EA38D8A9EAB0E2C38411BAAA820539ACA8342CAD8071B7A6342F41B223639F561230000006D0200FD91000100040A0A0A0100020004FFFFFF0000030004D49F060900030004D49F060A7004000E00000000000000000000000000000007002F466F727469576946692D3630452076352E362E332C6275696C643135343762313534372C3137313230342028474129
ike 0:iphonevpn_0:18: out BD60C4F396D24721326FC960AE3972D008100601E9CCB513000000DCCC9E1F54E8EC6D2B54BBF71682393830570E6CC1B3041A01B20ED266138B1AB36C4F9A91CD0FCCC3832E854359C7E3F530BB04692B81852A79B089CF653E1B408EFD1BD4DCAF23A2EB5E1993A46092FDF56253CEA3CB8FCC06629AA152C4ED8802FD84ADAD71DE121CAD95F26F1AFFEDA9E4CB9C12B4D26DD1279D82C5E2C5A83D7FF4BFE3530FB78B768A42D3A82DB7E3399ECBE59D1EEB22D8564F364868F52379D913E385EF76177FC1A1C2EB73E33A1A76DACCD7B447E78F0DAB306EE687
ike 0:iphonevpn_0:18: sent IKE msg (cfg_send): 80.229.17.87:4500->213.205.251.249:64916, len=220, id=bd60c4f396d24721/326fc960ae3972d0:e9ccb513
ike 0: comes 213.205.251.249:64916->80.229.17.87:4500,ifindex=32....
ike 0: IKEv1 exchange=Informational id=bd60c4f396d24721/326fc960ae3972d0:cad562fa len=140
ike 0: in BD60C4F396D24721326FC960AE3972D008100501CAD562FA0000008CBDC291595884D34BB1BEF035ECA358EAD460F4BFE6D09F1AA5A92C78FEC030279FA4154B963F16A45EB3777F9C8E3D4D57DE6335C54718EEBE1A55408B8A44678284147C19164BA8248CBDFD7B8EFC2D622B5B879CD06365345E3895A021BB10BA1FA7FEA7ED590BF3AD2A50178EA43E
ike 0:iphonevpn_0:18: dec BD60C4F396D24721326FC960AE3972D008100501CAD562FA0000008C0C0000446F567EADFAE2CF4A4814E4755E3DA239C2CA3666B62E10B73DCA9D09E731AF23C765C0227A82448E55CAD058996E299A5A84CB1F3BC61F2FB608216BDEE132690000001C0000000101100001BD60C4F396D24721326FC960AE3972D000000000000000000000000000000010
ike 0:iphonevpn_0:18: recv ISAKMP SA delete bd60c4f396d24721/326fc960ae3972d0
ike 0:iphonevpn_0: deleting
ike 0:iphonevpn_0: mode-cfg release 10.10.10.1/255.255.255.0
ike 0:iphonevpn_0: delete dynamic
ike 0:iphonevpn_0: reset NAT-T
ike 0:iphonevpn_0: deleted
ike 0:iphonevpn: carrier dow
From my limited understanding of the output.
I am being assigned ip 10.10.10.1 from the range
DNS are shown.
But then no idea and Iphone times out...
Any pointers welcomed!
Thanks
Andrew
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Sorry should of added!!
Fortiwifi 60 E, running v5.6.3 build1547 (GA)
IPhone 6S, running latest 11.x
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.