aicrd Posted October 4, 2020 Posted October 4, 2020 I'm trying to setup an iPad to join our Server 2019 Always on VPN for RDP access. We currently use per user tunnels where the user will log into the VPN and not device. These are the settings I've got configured on iOS so far: VPN Type: IKEv2 Server: vpn.domainname.com Remote ID: vpn.domainname.com Local ID: DOMAIN\User User Authentication: Username Username: DOMAIN\User Password: password123 Using these settings just gives me an unknown error when trying to connect. The VPN works just fine on Windows clients. I should also mention we use Always on VPN with PDQ Link.
Norphy Posted October 4, 2020 Posted October 4, 2020 Are you using a radius server to authenticate your VPN users? If so, is it set to accept password authentication or is it set to just accept certificates?
aicrd Posted October 4, 2020 Author Posted October 4, 2020 Looking at the policy in NPS its configured for Microsoft Secured Password (EAP-MSCHAP v2) under authentication methods. I Although oddly when I try to manually add our VPN into Windows (Instead of letting PDQ Link do it) I get an error message stating that the machine certificate couldn't be found. I suspect this means I'm missing something in the configuration?
meakjoe Posted October 5, 2020 Posted October 5, 2020 Depending on how you have set it up, you may also need to import your CA root certificate onto the iPad. When I've set AoVPN up before, you set a Root CA with Powershell for IKEv2 connections so that only devices with the Root CA installed can connect.
aicrd Posted October 5, 2020 Author Posted October 5, 2020 I just imported the root CA as a profile but still getting the same error. Just says "An unexpected error occurred". The message pops up almost instantly as if it hasn't even tried to connect to the server so I'm wondering if its a configuration issue on the device itself. Also, what ports are needed for IKEv2? I only have port 443 accessible as thats what always on vpn uses.
Norphy Posted October 5, 2020 Posted October 5, 2020 I just imported the root CA as a profile but still getting the same error. Just says "An unexpected error occurred". The message pops up almost instantly as if it hasn't even tried to connect to the server so I'm wondering if its a configuration issue on the device itself. Also, what ports are needed for IKEv2? I only have port 443 accessible as thats what always on vpn uses. If you're using 443, it will be an SSTP VPN. IKEv2 will need UDP 4500 and 500.
aicrd Posted October 5, 2020 Author Posted October 5, 2020 Any idea how to configure SSTP on iOS? The only options I have are IKEv2, IPSec and L2TP.
meakjoe Posted October 5, 2020 Posted October 5, 2020 SSTP is Windows only I believe, you'll have to set up your VPN server to accept other auth methods I should think.
aicrd Posted October 5, 2020 Author Posted October 5, 2020 Did some googling and SSTP is supported on iOS via the Cisco AnyConnect client. Just got to figure out how to get that to work with SSTP on Windows Server.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now