Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ipranger
Contributor

Searching for an alternate vpn/ipsec client for Android

Hello all, 

 

i'am searching for an alternate vpn/ipsec client for Android that has als an encryption higher the AES128/SHA1. 

There are many on the market, can you recommend one that works well with IPSEC?

I already had the native Android client running a few weeks ago. I can't tell you the level of encryption, you can't set anything on the client. I had only been able to get L2TP to work. Unfortunately, surfing via the VPN was not possible via the Fortigate when the VPN was active. Unfortunately, the support team did not find a solution either.

 

Can anyone recommend a client for me? If possible OpenSource.

 

Very Thanks and Best Regards

Fireon

Fortigate 60E v7.x (GA)

Fortigate 60E v7.x (GA)
1 Solution
emnoc
Esteemed Contributor III

Strongswan Android client. It's simple to use and should have sha2 families support. Are you doing IKEv2?

 

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
4 REPLIES 4
emnoc
Esteemed Contributor III

Strongswan Android client. It's simple to use and should have sha2 families support. Are you doing IKEv2?

 

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ipranger

I installed strongswan this day. It will probably take some work to set it up properly. You might want to post a config example of your VPN.

 

> Are you doing IKEv2?

Not yet. Because it does not work with the Fortinet Android VPN Client.

Fortigate 60E v7.x (GA)

Fortigate 60E v7.x (GA)
emnoc
Esteemed Contributor III

I put this post together a few years back. It should be very simple to follow 

 

 http://socpuppet.blogspot.com/2018/06/fortios-and-eap-identity-vpn.html

 

I had a client that want to do it awhile back and with enforcing  ikev2  so they deployed IKEv2 thru out the org. Another vpn client that's worth it's money that I should mention is NCP.

 

  http://socpuppet.blogspot.com/2018/06/ncp-vpnclient-ikev2-with-fortios-v60.html

 

They are based in EU but easy folks to work with. The clients and cfg across all OS that they support is easy to manage fwiw.

 

YMMV but I personally like the strongswan, but if your in an org that do not honor free or opensource NCP. is the bets thing out in the world. With strongswan you have to know it or rely on open forums but if it is doable or your doing it wrong you can get the correct information or help.

 

NCP

 

Just toggle from german to english if the page does not load english site assuming you're an english speaker.

 

  https://www.ncp-e.com/en/service-resources/download-vpn-client/

 

 

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ipranger

Hello Felix, 

 

and very thanks for the links. I spend time to confgure this on my fortigate and configure also the client on android. I also use a purchased certificate from GlobalSign. If i connect to the fortigate, i get this error in the log on the android client:

 

giving up after 3 retransmits

etablishing IKE_SA failed: peer not responding

unabel to terminate IKE_SA: ID 34 not found

 

The ID changes with each connection attempt. What irritates me is that the connection should be established via port 4500. However, the port is closed on the Fortigate. I have tried it with [link]https://www.yougetsignal.com/tools/open-ports/[/link] scanned.

 

I used the purchased certificate from GlobalSign for the global webserver in the fortigate. And the CA (normaly in all webbrowsers and devices) directly imported in the strongswan client on the phone. Is this right?

 

Fortigate 60E v7.x (GA)

Fortigate 60E v7.x (GA)
Labels
Top Kudoed Authors