All Products
Search
Document Center

VPN Gateway:Client configuration

Last Updated:Jun 21, 2026

After you create an IPsec-VPN server, configure a mobile client to establish a VPN connection to Alibaba Cloud.

Prerequisites

Ensure that the following prerequisites are met:

  • You have created an IPsec-VPN server. See Create and manage an IPsec-VPN server.

  • You have obtained the following information from the VPN Gateway console:

    • The public IP address of the VPN Gateway instance associated with your IPsec-VPN server.

    • The IKE version used by the IPsec-VPN server.

    • The pre-shared key used by the IPsec-VPN server.

iOS mobile client configuration

IPsec-VPN servers support connections from iOS devices only. This topic uses iOS 14 as an example.

  1. On your mobile device, open Settings.

  2. Go to .

  3. On the Add VPN Configuration page, configure the following parameters.

    • Type: Select the VPN type.

      The type must match the IKE version of the IPsec-VPN server.

    • Description: Enter a name for the VPN connection.

    • Server: Enter the public IP address of the VPN Gateway instance.

    • Remote ID: Enter the public IP address of the VPN Gateway instance.

    • Local ID: Enter an identifier for the mobile client. You can leave this field empty.

    • User Authentication: Select None.

    • Use Certificate: Set the toggle to Off.

    • Secret: The key for authenticating the mobile client with the IPsec-VPN server. The key must be identical on both ends.

      Enter the pre-shared key of the IPsec-VPN server.

    • Proxy: Keep the default setting Off.

  4. Tap Done.

  5. On the VPN page, select the VPN configuration that you created and turn on the Status toggle.

    A Connected status indicates that the VPN connection is established.