AnsweredHot!Searching for an alternate vpn/ipsec client for Android

Author
ipranger
Gold Member
  • Total Posts : 152
  • Scores: 2
  • Reward points: 0
  • Joined: 2012/11/13 11:49:10
  • Location: Austria/Steiermark
  • Status: offline
2021/05/17 13:01:13 (permalink)
0

Searching for an alternate vpn/ipsec client for Android

Hello all, 
 
i'am searching for an alternate vpn/ipsec client for Android that has als an encryption higher the AES128/SHA1. 
There are many on the market, can you recommend one that works well with IPSEC?
I already had the native Android client running a few weeks ago. I can't tell you the level of encryption, you can't set anything on the client. I had only been able to get L2TP to work. Unfortunately, surfing via the VPN was not possible via the Fortigate when the VPN was active. Unfortunately, the support team did not find a solution either.
 
Can anyone recommend a client for me? If possible OpenSource.
 
Very Thanks and Best Regards
Fireon
post edited by ipranger - 2021/05/17 13:04:34

Fortigate 60E v7.x (GA)
#1
emnoc
Expert Member
  • Total Posts : 6137
  • Scores: 422
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: Searching for an alternate vpn/ipsec client for Android 2021/05/17 13:13:18 (permalink) ☼ Best Answerby ipranger 2021/05/18 10:08:09
0
Strongswan Android client. It's simple to use and should have sha2 families support. Are you doing IKEv2?
 
 
Ken Felix

PCNSE 
NSE 
StrongSwan  
#2
ipranger
Gold Member
  • Total Posts : 152
  • Scores: 2
  • Reward points: 0
  • Joined: 2012/11/13 11:49:10
  • Location: Austria/Steiermark
  • Status: offline
Re: Searching for an alternate vpn/ipsec client for Android 2021/05/18 10:10:44 (permalink)
0
I installed strongswan this day. It will probably take some work to set it up properly. You might want to post a config example of your VPN.
 
> Are you doing IKEv2?
Not yet. Because it does not work with the Fortinet Android VPN Client.

Fortigate 60E v7.x (GA)
#3
emnoc
Expert Member
  • Total Posts : 6137
  • Scores: 422
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: Searching for an alternate vpn/ipsec client for Android 2021/05/18 11:38:28 (permalink)
0
I put this post together a few years back. It should be very simple to follow 
 
 http://socpuppet.blogspot.com/2018/06/fortios-and-eap-identity-vpn.html
 
I had a client that want to do it awhile back and with enforcing  ikev2  so they deployed IKEv2 thru out the org. Another vpn client that's worth it's money that I should mention is NCP.
 
  http://socpuppet.blogspot.com/2018/06/ncp-vpnclient-ikev2-with-fortios-v60.html
 
They are based in EU but easy folks to work with. The clients and cfg across all OS that they support is easy to manage fwiw.
 
YMMV but I personally like the strongswan, but if your in an org that do not honor free or opensource NCP. is the bets thing out in the world. With strongswan you have to know it or rely on open forums but if it is doable or your doing it wrong you can get the correct information or help.
 
NCP
 
Just toggle from german to english if the page does not load english site assuming you're an english speaker.
 
  https://www.ncp-e.com/en/service-resources/download-vpn-client/
 
 
 
Ken Felix
 

PCNSE 
NSE 
StrongSwan  
#4
ipranger
Gold Member
  • Total Posts : 152
  • Scores: 2
  • Reward points: 0
  • Joined: 2012/11/13 11:49:10
  • Location: Austria/Steiermark
  • Status: offline
Re: Searching for an alternate vpn/ipsec client for Android 2021/05/21 13:01:15 (permalink)
0
Hello Felix, 
 
and very thanks for the links. I spend time to confgure this on my fortigate and configure also the client on android. I also use a purchased certificate from GlobalSign. If i connect to the fortigate, i get this error in the log on the android client:
 
giving up after 3 retransmits
etablishing IKE_SA failed: peer not responding
unabel to terminate IKE_SA: ID 34 not found
 
The ID changes with each connection attempt. What irritates me is that the connection should be established via port 4500. However, the port is closed on the Fortigate. I have tried it with https://www.yougetsignal.com/tools/open-ports/ scanned.
 
I used the purchased certificate from GlobalSign for the global webserver in the fortigate. And the CA (normaly in all webbrowsers and devices) directly imported in the strongswan client on the phone. Is this right?
 

Fortigate 60E v7.x (GA)
#5
Jump to:
© 2021 APG vNext Commercial Version 5.5