Configure Client Devices for Mobile VPN with IKEv2 (2024)

Many client operating systems include a native IKEv2 client. For Android devices, you must download the third-party strongSwan app.

The steps to configure an IKEv2 connection are different for each client operating system. We provide instructions and files to help you configure an IKEv2 VPN connection on devices with these operating systems:

  • Windows
  • macOS
  • iOS
  • Android (strongSwan app)

For information on supported operating system versions, go to the Fireware Release Notes.

Instructions, profiles for macOS and Android, and scripts for Windows are included in a single file that you can download from your Firebox. You can use the profiles and scripts on your devices to automatically configure the IKEv2 VPN client. Or, you can follow the instructions to manually configure the IKEv2 VPN client. If you manually configure a client, you must add the rootca.crt or rootca.pem certificate to your device and follow the instructions in the README file.

To configure pre-logon VPN connections for Windows users, go to How can I create and deploy custom IKEv2 and L2TP VPN profiles for Windows computers? in the WatchGuard Knowledge Base.

WatchGuard provides interoperability instructions to help our customers configure WatchGuard products to work with products created by other organizations. If you need more information or technical support about configuring a non-WatchGuard product, see the documentation and support resources for that product.

To download the instructions, profiles, and scripts, from Fireware Web UI:

  1. (Fireware v12.3 or higher) Select VPN > Mobile VPN > IKEv2 > Client Profile.
    The Client Profile page opens.

Configure Client Devices for Mobile VPN with IKEv2 (2)

  1. (Fireware v12.2.1 or lower) Select VPN > Mobile VPN with IKEv2 .
  2. Click Download. A compressed .TGZ file downloads to your computer.
  3. Extract the .TAR file from the .TGZ file.
  4. Extract the files from the .TAR file. Folders with instructions and scripts, certificates, and a README.txt file show.

Configure Client Devices for Mobile VPN with IKEv2 (3)

  1. For an overview of the client configuration process, open the README.txt file in the root folder.
  2. For instructions and a configuration script specific to your operating system, open the folder for your operating system.

Configure Client Devices for Mobile VPN with IKEv2 (4)

To download the instructions, profiles, and scripts, from Policy Manager:

  1. (Fireware v12.3 or higher) Select VPN > Mobile VPN > Get Started > IKEv2 > Client Profile.
  2. (Fireware v12.2.1 or lower) Select VPN > Mobile VPN >IKEv2 > Client Instructions.
    The Mobile VPNwith IKEv2 Client Instructions dialog box opens.

Configure Client Devices for Mobile VPN with IKEv2 (6)

  1. In the VPN Connection Name text box, type a name that describes this VPNconnection.
  2. Click Download.
  3. On your computer, select a location to save the .TGZ file.
    A dialog box that requests connection information and credentials for your Firebox opens.

Configure Client Devices for Mobile VPN with IKEv2 (7)

  1. Type the IP address of your Firebox.
  2. Type the administrator user name and password for your Firebox.
  3. From the Authentication Server drop-down list, select the authentication server for your Firebox.
  4. Click OK.
    The Fireware Policy Manager dialog box opens.

Configure Client Devices for Mobile VPN with IKEv2 (8)

  1. Extract the .TAR file from the .TGZ file.
  2. Extract the files from the .TAR file. Folders with instructions and scripts, certificates, and a README.txt file show.

Configure Client Devices for Mobile VPN with IKEv2 (9)

  1. For an overview of the client configuration process, open the README.txt file in the root folder.
  2. For instructions and a configuration script specific to your operating system, open the folder for your operating system.

Configure Client Devices for Mobile VPN with IKEv2 (10)

If you manage your Firebox in WatchGuard Cloud, go to Download the Mobile VPN with IKEv2 Client Profile for download instructions.

For online versions of the instructions included in the .TGZ file, go to:

Related Topics

Mobile VPNwith IKEv2

Use the WatchGuard IKEv2 Setup Wizard

Troubleshoot Mobile VPN with IKEv2

Give Us FeedbackGet SupportAll Product DocumentationTechnical Search

© 2024 WatchGuard Technologies, Inc. All rights reserved. WatchGuard and the WatchGuard logo are registered trademarks or trademarks of WatchGuard Technologies in the United States and other countries. Various other trademarks are held by their respective owners.

Configure Client Devices for Mobile VPN with IKEv2 (2024)
Top Articles
Latest Posts
Article information

Author: Manual Maggio

Last Updated:

Views: 6298

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.