Cisco IPsec VPN setup for Apple devices

Use this section to configure your Cisco VPN server for use with iOS, iPadOS, and macOS, all of which support the Cisco network firewalls Adaptive Security Appliance 5500 Series and Private Internet Exchange. They also support Cisco IOS VPN routers with IOS version 12.4(15)T or later. VPN 3000 Series Concentrators don’t support VPN capabilities.

Authentication methods

iOS, iPadOS, and macOS support the following authentication methods:

Authentication groups

The Cisco Unity protocol uses authentication groups to group users based on a common set of parameters. You should create an authentication group for users. For preshared key and hybrid authentication, the group name must be configured on the device with the group’s shared secret (preshared key) as the group password.

When using certificate authentication, there’s no shared secret. A user’s group is determined from fields in the certificate. The Cisco server settings can be used to map fields in a certificate to user groups.

RSA-Sig must be the highest priority on the ISAKMP (Internet Security Association and Key Management Protocol) priority list.

IPsec settings and descriptions

You can specify these settings to define how IPsec is implemented: