How to make iPhone Cisco VPN client work with ASA with certificate authentication

Posted by Ben Jencks on Server Fault See other posts from Server Fault or by Ben Jencks
Published on 2010-04-22T21:47:58Z Indexed on 2010/04/22 21:53 UTC
Read the original article Hit count: 1164

Filed under:
|
|
|
|

I have an ASA that's providing IPsec VPN services using certificate authentication (no xauth, just the certs). It works perfectly with the Cisco IPsec VPN Client. Now I'm trying to let iPhones connect.

I've installed the CA cert and a client certificate on the iPhone with a profile using iPCU, along with the VPN configuration. Then connecting gives the error "Could not validate the server certificate". Additionally, the ASA logs the error "Received encrypted Oakley Informational packet with invalid payloads".

FWIW, I receive the same invalid payload error when trying to use the Snow Leopard IPsec client to connect.

Has anyone successfully gotten the iPhone IPsec client to work with certificate auth?

© Server Fault or respective owner

Related posts about iphone

Related posts about vpn