Hello all,
i'am searching for an alternate vpn/ipsec client for Android that has als an encryption higher the AES128/SHA1.
There are many on the market, can you recommend one that works well with IPSEC?
I already had the native Android client running a few weeks ago. I can't tell you the level of encryption, you can't set anything on the client. I had only been able to get L2TP to work. Unfortunately, surfing via the VPN was not possible via the Fortigate when the VPN was active. Unfortunately, the support team did not find a solution either.
Can anyone recommend a client for me? If possible OpenSource.
Very Thanks and Best Regards
Fireon
Fortigate 60E v7.x (GA)
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Strongswan Android client. It's simple to use and should have sha2 families support. Are you doing IKEv2?
Ken Felix
PCNSE
NSE
StrongSwan
Strongswan Android client. It's simple to use and should have sha2 families support. Are you doing IKEv2?
Ken Felix
PCNSE
NSE
StrongSwan
I installed strongswan this day. It will probably take some work to set it up properly. You might want to post a config example of your VPN.
> Are you doing IKEv2?
Not yet. Because it does not work with the Fortinet Android VPN Client.
Fortigate 60E v7.x (GA)
I put this post together a few years back. It should be very simple to follow
http://socpuppet.blogspot.com/2018/06/fortios-and-eap-identity-vpn.html
I had a client that want to do it awhile back and with enforcing ikev2 so they deployed IKEv2 thru out the org. Another vpn client that's worth it's money that I should mention is NCP.
http://socpuppet.blogspot.com/2018/06/ncp-vpnclient-ikev2-with-fortios-v60.html
They are based in EU but easy folks to work with. The clients and cfg across all OS that they support is easy to manage fwiw.
YMMV but I personally like the strongswan, but if your in an org that do not honor free or opensource NCP. is the bets thing out in the world. With strongswan you have to know it or rely on open forums but if it is doable or your doing it wrong you can get the correct information or help.
NCP
Just toggle from german to english if the page does not load english site assuming you're an english speaker.
https://www.ncp-e.com/en/service-resources/download-vpn-client/
Ken Felix
PCNSE
NSE
StrongSwan
Hello Felix,
and very thanks for the links. I spend time to confgure this on my fortigate and configure also the client on android. I also use a purchased certificate from GlobalSign. If i connect to the fortigate, i get this error in the log on the android client:
giving up after 3 retransmits
etablishing IKE_SA failed: peer not responding
unabel to terminate IKE_SA: ID 34 not found
The ID changes with each connection attempt. What irritates me is that the connection should be established via port 4500. However, the port is closed on the Fortigate. I have tried it with [link]https://www.yougetsignal.com/tools/open-ports/[/link] scanned.
I used the purchased certificate from GlobalSign for the global webserver in the fortigate. And the CA (normaly in all webbrowsers and devices) directly imported in the strongswan client on the phone. Is this right?
Fortigate 60E v7.x (GA)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.