Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

VPN Configuration Profiles iOS4

Just installed iOS4 on my 3GS. I use configuration profiles (created with iPhone Configuration Utility 2.2) to setup my VPN and WIFI settings for two locations I go back and forth between (aka Home & Work). The WIFI profiles seem to be working fine, signing on to the WIFI network at each location just as they're supposed to; however, the VPN profiles don't seem to be working. I recreated the profiles and reinstalled them on the phone but the VPN toggle never shows up and no configurations are listed under "General > Network > VPN". I have reset the network settings and forcefully rebooted the phone to no avail. iOS4 bug?

iPhone 3GS 32GB, iOS 4

Posted on Jun 21, 2010 10:50 PM

Reply
53 replies

Dec 30, 2010 2:41 PM in response to pauldambra

Hi, for anyone with a draytek router/firewall and ios 4 (i've just tested with my iphone 3gs) I have the exact setting that are needed to establish a pptp or l2tp with ipsec vpn.

1. Under vpn and remote access > remote access control I have all 2 options on :pptp, ipsec & l2tp
2. under ipsec general setup the important thing for l2tp with ipsec to work is: set a pre-shared key, and under ipsec security method only have 3des enabled
3. Under remote dial in user I have a user created with a pwd and only enabled l2tp with ipsec policy set to "must" and everything else left to it's default settings

Then on the iphone I have created a profile on the phone manually for L2TP with the server set to my ip address (a domain name using dyndns hasn't been tested yet), account as the username, password and the password setup in the draytek router and secret same as the pre-shared key set in the router, finally send all traffic set to on.

I will try a domain name and hope this is the problem that needs sorting next on wither the router and or the iphone

Feb 18, 2011 5:38 PM in response to Dh4rm3sh

Unfortunately I couldn't get your suggestion to work Dh4rm3sh, not sure why, I tried a zillion times (i've got a DrayTek 2710vn and iphone 4/ipad iOS 4.2.1).

eventually got it to work, but my similar method involves some black magic and I'm not sure what was the final step which sorted it (also involved using a beta firmware from DrayTek support).

details here: http://forums.whirlpool.net.au/forum-replies.cfm?t=1486587

(i'm using a dynDNS domain also)

good luck to others, pity this isn't as simple as it was pre iOS 4 (when it worked without any fiddling)

scott

Apr 14, 2011 1:26 PM in response to Patrick Cummings

Hello gents,
our admin is almost at the point to give up the iphone 4 (iOs 4.3.1).
VPN connection fails in phase 1.
we tried AES-128 (failed)

Any help/idea would be greatly appreciated!


Apr 14 22:17:04 USER-iPhone configd[26] <Notice>: IPSec connecting to server [COM.PAN.YSE.RVE.R]
Apr 14 22:17:04 USER-iPhone configd[26] <Notice>: IPSec Phase1 starting.
Apr 14 22:17:04 USER-iPhone configd[26] <Notice>: SCNC: start, triggered by Preferences, type IPSec, status 0
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: *** racoon started: pid=3120 started by: 1
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: @(#) racoon / IPsec-tools
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: @(#)This product linked OpenSSL 0.9.7l 28 Sep 2006 ( http://www.openssl.org/)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: Reading configuration from "/etc/racoon/racoon.conf"
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] WARNING: /var/run/racoon/[COM.PAN.YSE.RVE.R].conf:17: "support_mip6" it is obsoleted. use "support_proxy".
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: racoon launched by launchd.
Apr 14 22:17:04 USER-iPhone sandboxd[3121] <Notice>: racoon(3120) deny network-outbound /private/var/tmp/launchd/sock
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: 10.7.172.122[500] used as isakmp port (fd=7)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: 10.7.172.122[4500] used as isakmp port (fd=8)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: 192.168.2.101[500] used as isakmp port (fd=9)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: 192.168.2.101[4500] used as isakmp port (fd=10)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: fe80::129a:ddff:fe27:d1a9%en0[500] used as isakmp port (fd=11)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: fe80::129a:ddff:fe27:d1a9%en0[4500] used as isakmp port (fd=12)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: ::1[500] used as isakmp port (fd=13)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: ::1[4500] used as isakmp port (fd=14)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: 127.0.0.1[500] used as isakmp port (fd=15)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: 127.0.0.1[4500] used as isakmp port (fd=16)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: fe80::1%lo0[500] used as isakmp port (fd=17)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: fe80::1%lo0[4500] used as isakmp port (fd=18)
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: found launchd socket.
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] NOTIFY: accepted connection on vpn control socket.
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: accept a request to establish IKE-SA: [COM.PAN.YSE.RVE.R]
Apr 14 22:17:04 USER-iPhone racoon[3120] <Notice>: IPSec connecting to server [COM.PAN.YSE.RVE.R]
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: initiate new phase 1 negotiation: 192.168.2.101[500]<=>[COM.PAN.YSE.RVE.R][500]
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] INFO: begin Identity Protection mode.
Apr 14 22:17:04 USER-iPhone racoon[3120] <Notice>: IPSec Phase1 started (Initiated by me).
Apr 14 22:17:04 USER-iPhone racoon[3120] <Info>: [3120] ERROR: fatal NO-PROPOSAL-CHOSEN notify messsage, phase1 should be deleted.
Apr 14 22:17:04 USER-iPhone kernel[0] <Debug>: launchd[3120] Builtin profile: racoon (sandbox)
Apr 14 22:17:07 USER-iPhone racoon[3120] <Info>: [3120] ERROR: fatal NO-PROPOSAL-CHOSEN notify messsage, phase1 should be deleted.
Apr 14 22:17:11 USER-iPhone racoon[3120] <Info>: [3120] ERROR: fatal NO-PROPOSAL-CHOSEN notify messsage, phase1 should be deleted.
Apr 14 22:17:13 USER-iPhone racoon[3120] <Info>: [3120] ERROR: fatal NO-PROPOSAL-CHOSEN notify messsage, phase1 should be deleted.
Apr 14 22:17:14 USER-iPhone configd[26] <Notice>: IPSec disconnecting from server [COM.PAN.YSE.RVE.R]
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] WARNING: glob found no matches for path "/var/run/racoon/*.conf"
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] INFO: 10.7.172.122[500] used as isakmp port (fd=7)
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] INFO: 192.168.2.101[500] used as isakmp port (fd=8)
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] INFO: fe80::129a:ddff:fe27:d1a9%en0[500] used as isakmp port (fd=9)
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] INFO: ::1[500] used as isakmp port (fd=10)
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] INFO: 127.0.0.1[500] used as isakmp port (fd=11)
Apr 14 22:17:14 USER-iPhone racoon[3120] <Info>: [3120] INFO: fe80::1%lo0[500] used as isakmp port (fd=12)
Apr 14 22:17:15 USER-iPhone racoon[3120] <Info>: [3120] INFO: racoon shutdown

Aug 9, 2011 7:01 PM in response to Yps

@Yps: I would focus on finding the cause of the "NO-PROPOSAL-CHOSEN" fatal error. In addition to your log output and iOS version, I think you should show your iOS VPN configuration details and your VPN server configuration details (URLs & addresses obscured for security, of course). Knowing the brand, model and firmware version of the router would also help. That full picture is the only way to link cause and effect.

VPN Configuration Profiles iOS4

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.