FAQs - IPsec VPN Client for Android
Can I import configuration files?
Yes, you can directly import configuration files (*.pcf, *.spd, *.wgx, *.ini) from other manufacturers or files (*.ini) exported by the NCP configuration exporter.
You further have the option to import the configuration file "ncpphone.cfg". Please note that this configuration file only contains the VPN profile for the communication medium LAN.
Please copy the file "ncpphone.cfg" to the "\NCP\Import" directory on the internal or external SD card of the Android phone. In Windows Clients this file is usually located in "C:\Program Files (x86)\NCP\Secure Client\". You can now import the configuration data from that file into the Android Client via the "Import / Export" option. If the file is located in the correct directory, the system displays the entry "ncpphone.cfg" and next to it a box which can be checked. Check this box and then press the "Back" button to leave the menu. With that, the configuration data has been imported correctly and a connection can be established.
How do I import a certificate?
Currently support is provided for a certificate stored in a PKCS#12 file located on the Android phone's internal or external SD card in the "\NCP\Import" directory.
Import the certificate into the Android Client using the "Import / Export" option (menu - Import / Export); select either "Import User Certificates" or "Import CA Certificates" dependent on the type of certificate being imported.
Finally, select the certificate as "Certificate" in the Profile settings.
What does the error message: "Ike: NOTIFY : x : RECEIVED : NO_PROPOSAL_CHOSEN : 14" mean?
This error message means that the IPsec Phase 2 encryption settings are incorrect. Currently the Client only supports a limited list of proposals. If the VPN server requires a type of encryption not in that list, this error message will be generated when the Client attempts to establish a connection to the server.
The facility to fully configure the settings will be implemented in the next version of the Client.
In the interim, a workaround is to create the correct configuration ("ncpphone.cfg", see above) on a Windows Client and import that into the Android Client.
Is there an NCP Secure Client for Android versions earlier than V4.0?
Manufacturer dependent restrictions mean that, on Android versions earlier than V4.0, the NCP VPN Client can not be sourced from the Android Market and then installed in the normal way. To circumvent this problem, NCP has developed an NCP Secure Client that requires either a "rooted" device or a specially adapted Android kernel. NCP only supplies this product to hardware manufacturers or system integrators or for major projects.
If you are interested in this particular development, please contact firstname.lastname@example.org
Where do I store the Cisco parameters "Group Password" and "Group ID"?
Save the "Group Password" parameter as the "Pre-shared Key" in the NCP Android Client. Also, with connections to Cisco servers, "Exchange Mode" is then usually set to "Aggressive Mode".
Save the "Group ID" parameter as the "IKE ID", and then set the "IKE ID Type" to "Free string used to identify groups".
How does the configurable connection mode of the Premium Client work?
The VPN tunnel always starts automatically without interaction with the user. If connection setup fails, the client tries to establish a connection every 20 seconds. In order to permanently disconnect the tunnel, the user should select a different profile, which has been configured for the manual connection mode. Please note that after cold booting the device, the user has to manually initiate the first VPN connection setup.
NCP's Secure VPN Client Premium automatically reconnects a VPN tunnel (auto-reconnect: default setting) if a connection has been interrupted or the communication medium has been changed (3G/WiFi). Under certain circumstances, however, for example with bad 3G reception, it might happen that the VPN reconnect fails and the connection remains disconnected. Users who wish a permanent VPN connection can counter this by setting the communication mode to "always". With that setting an established VPN connection will only be permanently disconnected if the user selects a different VPN profile.
Why does NCP's Secure VPN Client not work on my Android 4.x system?
NCP's Secure VPN Client requires a VPN-API, which has to be installed on the Android 4.x operating system. If the system displays an error message after installation of the client, please contact the manufacturer of your device or install the latest systems software or Android version; you will find both on the manufacturer's support websites.