To configure IPsec IKEv2 you must first have the certificate. This must be exported from the router and can be done either through Insight or the local GUI of the router.
To export the Certificate in Insight.
- Access the Insight Cloud Portal.
- Navigate to the Devices tab and the Device settings of the router.
- The router’s settings page will display.
- Click General > Certificate Authority.
- Highlight the certificate you wish to export and click Export Certificate. The certificate will be zipped and will need to be extracted.
- The certificate is now exported and can now be imported into Android. This can be done by emailing the certificate to the user.
To export the Certificate on the local GUI.
- On a computer or mobile device that is connected to your PR60X router's network, access https://www.routerlogin.net. Your browser might display a security message, which you can ignore.
- A login window opens.
- Enter the router user name and password.
- The user name is admin. If you did not change your router's password during setup, enter password. The user name and password are case-sensitive.
- On the router dashboard, select VPN > Certificate.
- Under the Certificate page, select Authorities.
- Highlight the certificate you wish to export and click Export Certificate.
- The certificate is now exported and can now be imported into Android.
To setup through Android.
- Email the Certificate Authority file to an e-mail address that is reachable on the Android device.
- Open the mail add and open the message with the attached Certificate Authority Certificate and download the Certificate Authority Certificate directly to the device.
- Next, download strongSwan VPN Client directly through the Google Play Store.
- Open the strongSwan app and tap the settings icon on the top right.
- Select Certificate Authority Certificates, tap Import Certificate, tap Settings, Certificate Authority, tap Import Certificate.
- Locate the CA Certificate that was downloaded to your device and tap IMPORT CERTIFICATE.
- Next, tap Add VPN Profile.
- Enter the IP address or hostname of the router.
- Select IKEv2 EAP (Username/Password) for the Type.
- Enter the Username and Password.
- Select Select automatically under the Certificate Authority certificate field.
- Tap Advanced Settings and enter the Server identity which needs to match the remote server address of the PR60X or PR460X router.
- Click Save on the top right corner to save the VPN profile.
- To connect in the strongSwan app, tap the configured VPN profile.