Starting with ZLD 5.20, USG FLEX and ATP devices support predefined settings for both SecuExtender IPSec and non-SecuExtender IPSec VPN clients. In this article, we will guide you through using the VPN setup wizard for remote access (Quick Setup). We will also demonstrate how to configure StrongSwan on Android using the quick setup script, manually install certificates, and configure StrongSwan to establish a VPN tunnel using IKEv2 with EAP-MSCHAPv2 authentication.
Note:You can also use this if L2TP VPN has been removed on your Android version 12+.
Keep in mind: Once you have configured the VPN using Quick Setup, you can always modify the settings later. For example, you can add or change groups or include additional proposals as needed.
However, be aware that manual changes may impact the operation of devices initially configured using the quick setup script.
If you need to re-enter the Quick Setup script and start from the beginning—such as when downloading the script again—any manual changes you previously made will be overwritten. But don't worry, you can simply apply those manual changes again after running the setup.
Note:The IP addresses in the figure are, for example, only and are not relevant to the article as a whole. They may be different in your case.
Configuring VPN via Quick Setup
Login to your Firewall WEB GUI and go into Quick Setup, and choose Remote Access VPN and then IKEv2 IPSec Client (Zyxel SecuExtender, non-SecuExtender)
Use this if you are using the Zyxel SecuExtender IPSec VPN client or a computer operating system that supports IPSec VPN with IKEv2 (non-SecuExtender VPN client). You can create a Full Tunnel or Split Tunnel VPN rule with Zyxel SecuExtender VPN client. You can only create a Full Tunnel VPN rule with non-SecuExtender VPN client.
Configure the IP Address Pool for the client.
The IP address pool will use a select non-used subnet on the device to avoid setting up the same subnet.The IP address Pool will begin at 192.168.50.1 If the subnet 192.168.50.1 exists in the gateway settings, the IP address pool will automatically change.
Add or create users who will have VPN access. Once users are added, click Next and review all settings to ensure accuracy. You can now either download an automated script to configure the VPN or configure it manually using a certificate.
After successful VPN configuration, you can download and install the script files on Android devices to configure VPN settings automatically.
Note:The VPN settings for Non-SecuExtender IPSec VPN Clients do not support the following features:
Upload Bandwidth Limit
Spilt Tunnel
Two-factor Authentication (Google Authenticator)
Details on configuring a VPN for Windows and Apple devices can be found in the following article:
Please keep in mind: To reduce configuration errors and other potential issues, we recommend using a script for installation. However, you can also manually install and configure the certificate directly on your endpoint device. Detailed instructions for manual certificate installation and VPN configuration can be found in the "Manual Certificate Configuration" section.
Configuring StrongSwan VPN on Android via Quick Setup Script
Download StrongSwan from the Google Play Store
Send the Script to the mobile device via email
Save Script on your mobile Device
Open the StrongSwan App
Click “ADD VPN PROFILE”
Import VPN profile
Select a previously saved script
Fill in the username and password and Save
Click on the created profile
Wait a few seconds for the connection to be established
Configuring StrongSwan VPN on Android by installing a certificate and manually creating a VPN profile
How to download a certificate
Navigate to Configuration -> Object -> Certificate, select the VPN certificate, and press "Download" to download the certificate.
Note: The "Password" field should be left blank as we need to download the crt certificate to use it in the StrongSwan client on Android. If you fill in the password, the certificate format will be pfx; this is not suitable for our case.
If you're having trouble selecting the correct certificate from your list, you can identify the required certificate for a specific VPN by checking the VPN settings.
Configuration - VPN - IPSec VPN - VPN Gateway - Open settings of the VPN of interest
In the “Authentication” section, you will see which certificate is selected for your VPN.
Now, you can attach this certificate to an email you send to the users, explaining how to install it and connect to the VPN.
Manual configuration of StrongSwan VPN on Android (without script)
Download StrongSwan from the Google Play Store
Send the certificate to the mobile device via email
Save the certificate to the mobile device (don't try to install the certificate directly from the mail; just saves it)
Open the StrongSwan App
Click on the three tokens in the right corner and select “CA Certificate.”
Select “Import certificate.”
Select a previously saved certificate and click “Import Certificate.”
Click on the three tokens in the right corner and select “CA Certificate.”
If the certificate is successfully imported, you will see the message “Certificate successfully imported.”
Next, go back to the StrongSwan main menu and click “Add VPN Profile.”
In the VPN profile configuration form that appears, please fill in all required fields:
We and our partners use cookies on our site for delivering personalised content, ads and analyzing website traffic. This provides you with better browsing experience. By clicking ‘agree’ or navigating this site, you agree to the use of cookies described in our cookie policy. You can manage your cookie preferences at any time.
Zyxel periodically provides end-of-life information and migration recommendations to our valued customers.
custom
/hc/theming_assets/01J2ZZZN7PVVR88HREAMFW19F1
The Zyxel Community is an online platform dedicated to networking enthusiasts, IT professionals, and Zyxel product users.
custom
/hc/theming_assets/01J2ZZZNGB20MYAWFSNCPJ8QTF
FAQ
The Zyxel online FAQ, dedicate to the frequently asked questions.
USG FLEX L2TP Android, Nebula License Migration, NAS326 Twonky Media Server
Warranty Expiration Date:
Model Name:
The Serial Number that you provided does not correspond to a Zyxel device. To create a Support or Warranty case, please ensure you enter the correct Serial Number.
If your Serial Number is still not matching with our device records, you can proceed with initiating a web support request by completing the form below, once you have successfully registered or logged in.
Obadete se da govorite s predstavitel na uslugata.
Stremim se da otgovorim na vsichki obazhdaniya v ramkite na 3 minuti
no v natovareni vremena mozhe da ni tryabva malko poveche vreme
We were unable to verify the Support and Warranty status of your device using the provided Serial Number. If you purchased your device in North America, please submit a support request to the US support team here. This portal is exclusively for products and services sold in the EMEA region.
Please attach an invoice of your defective device(s) as proof of purchase.
Dear Zyxel Customer,
We are currently experiencing issues with the Serial Number check, which may result in a timeout. Please try again later. In the meantime, you can sign in or continue using the options below without entering a Serial Number.
Thank you for your understanding.