[GH-ISSUE #312] Connection problem #288

Closed
opened 2026-03-02 08:01:07 +03:00 by kerem · 2 comments
Owner

Originally created by @tianrenhyb on GitHub (Oct 18, 2022).
Original GitHub issue: https://github.com/hwdsl2/docker-ipsec-vpn-server/issues/312

Apple phones can connect, Android phones cannot connect.

Originally created by @tianrenhyb on GitHub (Oct 18, 2022). Original GitHub issue: https://github.com/hwdsl2/docker-ipsec-vpn-server/issues/312 Apple phones can connect, Android phones cannot connect.
kerem closed this issue 2026-03-02 08:01:07 +03:00
Author
Owner

@hwdsl2 commented on GitHub (Oct 18, 2022):

@tianrenhyb Please see:
https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/docs/clients.md#android

Android users should instead connect using IKEv2 mode (recommended), which is more secure. Android 12+ only supports IKEv2 mode. The native VPN client in Android uses the less secure modp1024 (DH group 2) for the IPsec/L2TP and IPsec/XAuth ("Cisco IPsec") modes.

If you still want to connect using IPsec/L2TP mode, you must add VPN_ENABLE_MODP1024=yes to your env file, then re-create the Docker container.

<!-- gh-comment-id:1283055549 --> @hwdsl2 commented on GitHub (Oct 18, 2022): @tianrenhyb Please see: https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/docs/clients.md#android Android users should instead connect using [IKEv2 mode](https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/docs/ikev2-howto.md) (recommended), which is more secure. Android 12+ only supports IKEv2 mode. The native VPN client in Android uses the less secure modp1024 (DH group 2) for the IPsec/L2TP and IPsec/XAuth ("Cisco IPsec") modes. If you still want to connect using IPsec/L2TP mode, you must add VPN_ENABLE_MODP1024=yes to [your env file](https://github.com/hwdsl2/docker-ipsec-vpn-server#how-to-use-this-image), then re-create the Docker container.
Author
Owner

@tianrenhyb commented on GitHub (Oct 21, 2022):

Thanks.

------------------ 原始邮件 ------------------
发件人: "hwdsl2/docker-ipsec-vpn-server" @.>;
发送时间: 2022年10月19日(星期三) 上午6:01
@.
>;
@.@.>;
主题: Re: [hwdsl2/docker-ipsec-vpn-server] Connection problem (Issue #312)

@tianrenhyb Please see:
https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/docs/clients.md#android

Android users should instead connect using IKEv2 mode (recommended), which is more secure. Android 12+ only supports IKEv2 mode. The native VPN client in Android uses the less secure modp1024 (DH group 2) for the IPsec/L2TP and IPsec/XAuth ("Cisco IPsec") modes.

If you still want to connect using IPsec/L2TP mode, you must add VPN_ENABLE_MODP1024=yes to your env file, then re-create the Docker container.


Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you were mentioned.Message ID: @.***>

<!-- gh-comment-id:1286319666 --> @tianrenhyb commented on GitHub (Oct 21, 2022): Thanks. ------------------&nbsp;原始邮件&nbsp;------------------ 发件人: "hwdsl2/docker-ipsec-vpn-server" ***@***.***&gt;; 发送时间:&nbsp;2022年10月19日(星期三) 上午6:01 ***@***.***&gt;; ***@***.******@***.***&gt;; 主题:&nbsp;Re: [hwdsl2/docker-ipsec-vpn-server] Connection problem (Issue #312) @tianrenhyb Please see: https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/docs/clients.md#android Android users should instead connect using IKEv2 mode (recommended), which is more secure. Android 12+ only supports IKEv2 mode. The native VPN client in Android uses the less secure modp1024 (DH group 2) for the IPsec/L2TP and IPsec/XAuth ("Cisco IPsec") modes. If you still want to connect using IPsec/L2TP mode, you must add VPN_ENABLE_MODP1024=yes to your env file, then re-create the Docker container. — Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you were mentioned.Message ID: ***@***.***&gt;
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/docker-ipsec-vpn-server#288
No description provided.