IPSec IKEv2
Advantages of IKEv2
Compared to IKEv1, IKEv2 (Internet Key Exchange version 2) provides a more robust and efficient VPN experience:
Enhanced Security: Supports modern encryption algorithms (AES-GCM) and is more resistant to Denial-of-Service (DoS) attacks.
Faster Connection: Requires fewer message exchanges to establish a secure tunnel, resulting in quicker connection times.
Native OS Compatibility: Fully supported by modern versions of Windows, macOS, iOS, and Android without requiring third-party software.
EnGenius Cloud Configuration
Step1: Enable IKEv2 Settings
Log in to EnGenius Cloud and navigate to Configure > Gateway > Client VPN.
Toggle IPSec to On.
Select IKEv2 as the protocol Type.
Define the VPN Client Subnet and Authentication Type.
Click Apply.

Step 2: Download the CA Certificate
In the Certificate field, click Download.
Save the IKEv2_CA.crt file. This certificate must be installed on all client devices to establish a trust relationship with the gateway.

3. Client Device Configuration
Android Setup
Install Certificate: Transfer IKEv2_CA.crt to the device. Go to Settings > Security > Advanced > Encryption & credentials > Install from storage > CA certificate.




Add VPN:
Type: IKEv2/IPSec MSCHAPv2.
Server Address: Enter the Gateway Hostname.
IPSec Identifier: Enter your VPN Username (This is a mandatory field for Android).
IPSec CA Certificate: Select the installed EnGenius CA.


Note
Android OS “IPSec identifier” should input “Username”
iOS Setup
Install Profile: Open the .crt file and install the profile in Settings > Profile Downloaded.
Trust Certificate: Go to Settings > General > About > Certificate Trust Settings and enable full trust for the EnGenius CA.
Add VPN: Select IKEv2 type, enter the Server and Remote ID (Hostname), and use Username for authentication.




macOS Setup
Trust Certificate: Open IKEv2_CA.crt in Keychain Access and set it to Always Trust.
Network Settings: Create a new VPN interface with type IKEv2. Enter the Server Address and Remote ID. Use Username for authentication.


Note
Configurated as always trust



Windows Setup
Install Certificate: Install the certificate to the Local Machine and place it in the Trusted Root Certification Authorities store.




VPN Connection: Go to VPN Settings > Add a VPN. Select IKEv2 as the VPN type and enter the server details.

Note
the example is Connection name = IKEv2_VPN



Must know
Ensure the Gateway firmware is 1.2.85 or above.
The Remote ID (iOS/macOS) and Server Address must match the Hostname/DDNS shown in the Cloud UI
Last updated
Was this helpful?

