Configure Client Devices for Mobile VPN with IKEv2

Many client operating systems include a native IKEv2 client. For Android devices, you must download the third-party strongSwan app.

The steps to configure an IKEv2 connection are different for each client operating system. We provide instructions and files to help you configure an IKEv2 VPN connection on devices with these operating systems:

  • Windows
  • macOS
  • iOS
  • Android (strongSwan app)

For information on supported operating system versions, go to the Fireware Release Notes.

Instructions, profiles for macOS and Android, and scripts for Windows are included in a single file that you can download from your Firebox. You can use the profiles and scripts on your devices to automatically configure the IKEv2 VPN client. Or, you can follow the instructions to manually configure the IKEv2 VPN client. If you manually configure a client, you must add the rootca.crt or rootca.pem certificate to your device and follow the instructions in the README file.

To configure pre-logon VPN connections for Windows users, go to How can I create and deploy custom IKEv2 and L2TP VPN profiles for Windows computers? in the WatchGuard Knowledge Base.

WatchGuard provides interoperability instructions to help our customers configure WatchGuard products to work with products created by other organizations. If you need more information or technical support about configuring a non-WatchGuard product, see the documentation and support resources for that product.

If you manage your Firebox in WatchGuard Cloud, go to Download the Mobile VPN with IKEv2 Client Profile for download instructions.

For online versions of the instructions included in the .TGZ file, go to:

Related Topics

Mobile VPN with IKEv2

Use the WatchGuard IKEv2 Setup Wizard

Troubleshoot Mobile VPN with IKEv2