Anyone tried to connect GP from iphone/ipad with ClientCert?

Announcements
Attention: The LIVEcommunity is experiencing an interruption with videos in some areas. We apologize for any inconvenience this may cause. Thank you for your patience as we work towards a solution to restore videos.
Reply
Highlighted
L4 Transporter

Anyone tried to connect GP from iphone/ipad with ClientCert?

I'm tring to connect GP from iPhone5 and iPad4.3.3 with Client Cert Auth.

I can't see the establishment of IPSec VPN, however, I could establish VPN from Windows with same client cert.

I want to see the working sample cofiguration.

Could anyone share the information?

My testbed:

-PA-5020 v4.1.1

-GP v1.1.1

-Windows 2003R2 as Client Cert CA

BTW, I know the following document and could not work well.

https://live.paloaltonetworks.com/docs/DOC-1972

Regards,

Emr

Tags (3)
Highlighted
Community Team Member

Re: Anyone tried to connect GP from iphone/ipad with ClientCert?

This has been setup and works with other customers, the following should help:

On the PAN device
1: configure a Global Protect Portal (fairly simple and straight forward, refer to the Global Protect setup doc)
2: configure a Global Protect Gateway (this is where you get into the Xauth feature needed for iOS VPN)
A: server cert, authentication setup is as usual, do not use a client cert
B: enable tunnel mode
C: enable X-auth support (IPSEC will already be enabled, leave this as-is)
D: make up a group name and a group password, leave ‘skip auth on IKE Rekey’ enabled
E: tunnel Gateway: I used the same as my GP Portal
F: client configuration tab of the GP gateway is more or less the same as NetConnect setup parameters so I will not cover them here
G: iOS VPN does not use HIP so do NOT create any HIP profiles
3: make sure you have security policy and NAT policy configured as needed
4: commit

On the iOS device:
General -> Network -> VPN -> Add a VPN Configuration
Select the IPSec tab
Description: choose a name
Server: the IP address or FQDN of your GP Portal
Account: username for VPN access
Password: password for the user in previous step
Use certificate: greyed out on my setup (I am not sure if we can enable this on iOS, need to do research)
Group name: use the same group name you created on the GP Gateway
Secret: the group password from your GP Gateway
Save the config
Connect the VPN
Test connectivity in your web browser on the iOS device.

I hope this helps.

Stay Secure,
Joe
End of line
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!