Project

General

Profile

Actions

Bug #6684

closed
CL MS

Setting IKEv2 Phase 2 in Mobile Config appears to generate invalid Apple Profile

Bug #6684: Setting IKEv2 Phase 2 in Mobile Config appears to generate invalid Apple Profile

Added by Chris Linstruth about 10 years ago. Updated over 6 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
IPsec Profile Wizard
Target version:
-
Start date:
08/07/2016
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

Setting "Phase2 PFS Group - Provide the Phase2 PFS group to clients (overrides all mobile phase2 settings)" in Mobile Clients settings on at least IKEv2 appears to generate an invalid mobileconfig profile using the Apple IPsec Profile factory package (ipsec-profile-exporter).

Culprit is probably:

<key>DiffieHellmanGroup</key>
<integer></integer>

in the child SA config.

Workaround: disable in Mobile Clients config and enable DH group in Phase 2.

JT Updated by Jim Thompson almost 10 years ago Actions #1

  • Assignee set to Matthew Smith

JP Updated by Jim Pingle about 7 years ago Actions #2

  • Category set to IPsec Profile Wizard

VG Updated by Viktor Gurov over 6 years ago Actions #3

tested on pfSense 2.4.5.a.20200120.1342 with ipsec-profile-wizard 0.12

no such issue - you can set DH group in both Phase 2 and "Phase2 PFS Group - Provide the Phase2 PFS group to clients (overrides all mobile phase2 settings)" and get correct DH group numbers in remote-access-ipsec.mobileconfig

JP Updated by Jim Pingle over 6 years ago Actions #4

  • Status changed from New to Resolved
Actions

Also available in: Atom