所以你有了你闪亮酷炫的新iPhone。你沉迷于他们非常酷的网页浏览器。现在你想要能够冲浪到你的内部家庭或企业网络使用VPN ?嵌入式iPhone VPN客户端可以通过Wi-Fi和EDGE网络连接工作。好消息是,思科IOS路由器和ASA设备都支持这一点。事实上,他们一直支持它。下面是一些极客的细节以及如何设置它。iPhone vpn客户端使用L2TP/IPSEC。这是MacOS和Windows XP原生VPN客户端使用的同一种VPN协议。对于那些不熟悉L2TP/IPSEC的人,可以将其看作是使用本机IPSEC的另一种选择。 The Cisco routers and firewalls (ASA) have included support for L2TP/IPSEC for a number of years now. Apple, in its infinite wisdom, has made the iPhone L2TP/IPSEC vpn client almost identical to the one on its MacOS. As a result, Cisco VPN gateways support it. However, the iPhone L2TP/IPSEC vpn client does have some limitations. It is not as full featured as the vpn client that is on the MacOS. Here are the officially supported features from Apple that you’ll need to know when configuring your VPN gateway to handle the iPhone.
- 使用SHA1哈希方法的IKE phase 1-3DES加密。(没有md5支持)
- IPSec phase 2-3DES或AES加密与MD5或SHA哈希方法。
- PPP验证-MSCHAPv2的(官方),但PAP,MS-CHAPv1还曾在测试。
- 预共享密钥(不支持证书)。
显示vpn-sessiondb详细远程过滤协议L2TPOverIPSec要么显示VPN-sessiondb细节远程滤波器协议L2TPOverIPSecOverNAtT
这些show命令只提供已连接的L2TP/IPSEC客户机。第二个show命令显示了使用nat遍历的任何客户机(意味着它们位于某处的PAT设备后面)。有关如何配置苹果iPhone的信息,请点击http://docs.info.apple.com/article.html?artnum=305827或者这里http://docs.info.apple.com/article.html?artnum = 305723。有关如何在IOS VPN路由器上配置L2TP/IPSEC的信息,请参见:http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804dfa69.html任何人都可以有另一个iPhone,我可以“测试”的目的。在此陈述的意见和信息是我的个人意见,而不是我的雇主。