• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Help VPN IKEv2 connection problems on Android, IKE_SA failed

thecriser

Lurker
Hello, I have big problem with connecting to my VPN server from 50% of Android devices.

Cannot resolve it 2 weeks with network and android developers

VPN server based on IKEv2 with Charon and Strongswan libs, and it works stable with iPhone devices

But on Android devices it fails with error “IKE_SA failed, peer not responding” after 3 retransmits of sending IKE_SA_INIT requests

I tried to gether information what was tested, and some hypotheses we had:

1) Android app used to connect is problematic:

No, it is most popular Strongswan application for VPN connection, that advised by many respective VPN services

2) Network providers is problematic and cut some traffic:

No, because iPhone device can connect to this VPN through standard settings. iPhone was connected to the same Wi-Fi and was in airplane mode for disable cellular network (I doublechecked that cellular network was disabled)

3) Android devices that was on manual tests is problematic:

No, because when I using not Wi-Fi from my home provider, but using wi-fi from my iPhone hotspot the connection is Successful.

Also another GooglePlay IKEv2 free VPNs is failed to connect

So based on this 3 points I have very strange situation.

Screenshots of android logs will be attached at bottom, with error connection(through wifi) and success connection(through iPhone hotspot)

Also screenshot of VPN server error connection log will be attached

I am android developer, and have network developer in my team, so any additional questions please



Dear developers, please give me some advices what I can do to test and understand what problem we have?

Very need it, because based on this VPN serves android free VPN app will be created
 

Attachments

  • 2022-12-26 15.02.53.jpg
    2022-12-26 15.02.53.jpg
    61.5 KB · Views: 158
  • 2022-12-26 15.04.05.jpg
    2022-12-26 15.04.05.jpg
    149.4 KB · Views: 106
Have you got the correct and up-to-date security certificate installed in your Strongswan for the VPN service?

When I used Strongswan to connect to NordVPN, they insisted I have their certificate installed, otherwise it wouldn't connect.
 
Yes, of course, the certificate was installed and correct, this confirms the fact that it works with the same settings on one device, but not on the other, the certificate is also the same
 
Back
Top Bottom