Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

proxy through vpn-connection

Hi there,

I have a problem using a proxy server trough a vpn connection on the iphone (3GS and 4, iOS 5.0.1).

VPN works fine, but the iphone doesn't use the proxy settings given for the vpn-connection. I tried to set them manually or

via proxy pac, nothing works. There is no problem to use a proxy server via wifi, but for vpn it doesn't work. Can anybody help me please?

iPhone 4, iOS 5.0.1

Posted on Feb 3, 2012 5:20 AM

Reply
18 replies

Feb 25, 2012 7:09 AM in response to davefromdennyloanhead

Actually. Scratch this request. I appear to have got to the bottom of this. The proxy is only used on a split tunnel for domains you decalre as being serviced by the VPN. This is done on the ASA device with the split-dns command. Just list the domains the tunnel will be used for. I had that change made on the AS and it works as expected.


There's a fair explanation of the parameter in the ASA CLI configuration guide.

Feb 26, 2012 12:32 PM in response to Speedy166

One thing to add. Although it's working for me, the first request after the conneciton auto-dials fails. It would appear the DNS is going out on internet proper. However, if I refresh the page it goes via the proxy and all subsequent pages are OK until the tunnel drops and then the same thing happens.


We currently dont have a DNS server allocated and also have a different domain name for the clients than the domain the tunnel is servicing - will see if I can resolve tomorrow, but just for your info at moment.


If you start the tunnel and then access the page - all works 1st time.

Feb 28, 2012 1:03 AM in response to Speedy166

Hmpf....my mistake ( should'nt do such configs when telephone is ringing all the time 😉 ).

It works now. I have a list of domains separated with spaces and all are being used through the tunnel. And you're right, I don't need wildcards, just something like "domainname.com".

Oh yes, and I supply DNS server to the client and even the proxy-server.

Do you also give proxy-server? I'm not sure if the client then first is going out to internet for DNS...

But, just try it with setting the DNS server, but don't forget to add its ip address to the split tunneling 😉

Feb 28, 2012 7:57 AM in response to davefromdennyloanhead

I tried both setups and - actually - both are working 🙂

You can manually set the proxy on the iphone, but then it's importat the ASA is configured not to modify client proxy settings.

Now I've configured the ASA to supply the proxy server ip and port (and here again, also add the proxy server ip to split tunneling).

Need the commands?

Feb 29, 2012 12:34 AM in response to davefromdennyloanhead

Just for me to understand:

If you start the tunnel manually, then everything works fine.

But if the tunnel starts via auto-dial the first try is unsuccessful? Maybe it's just something like a timeout problem, if the tunnel does'nt come up fast enough?

How do you configure auto-dial vpn on the iphone? Do you use the anyconnect client?

I can't find this option in the "normal" ipsec client on the phone...

proxy through vpn-connection

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.