Can anybody recommend a simple, automated setup for a Personal VPN profile [0] for iOS? Something like the @TinfoilSecurity generator [1] would be great. @buyvpnservice does it but I prefer to use my own cloud host.
[0]: https://developer.apple.com/documentation/networkextension/personal_vpn … .
[1]: https://www.tinfoilsecurity.com/vpn/new
-
-
Why not just use algo? It speaks ipsec
2 replies 0 retweets 0 likes -
@AlgoVPN is what I'd prefer to use, but it's not clear that the recommended@WireGuardVPN app generates an enterprise profile or a personal profile. It also lacks automagic scripts for setup on cloud providers, and info on disabling logs. /cc@trailofbits@dguido1 reply 0 retweets 0 likes -
We generate a QR code used for automated setup with the WireGuard app. Is that what you meant by personal or enterprise profile? Algo has built-in support for about a dozen cloud providers once you give it an API key. What are you looking for in terms of automation?
1 reply 0 retweets 0 likes -
I think
@ebeip90 meant the .mobileconfig to use the native personal VPN UI, fwiw1 reply 0 retweets 0 likes -
I don’t think WireGuard can be configured that way? If it can, then I’ll add it. AFAIK the mobileconfig can only set built-in Apple configs, like IPSEC. https://developer.apple.com/business/documentation/Configuration-Profile-Reference.pdf …
1 reply 0 retweets 0 likes -
You should be able to add an IPSEC config that routes to localhost (with an app that dishes data out to the "real" VPN), no?
2 replies 0 retweets 0 likes -
What benefit does that provide that outweighs the added complexity?
1 reply 0 retweets 0 likes -
You can have one Enterprise and one Personal VPN profile active *simultaneously* on iOS. The enterprise gets first shot depending on the destination, otherwise it goes to Personal. This means I don't have to switch between work and personal VPNs all the time.
1 reply 0 retweets 0 likes -
TL;DR iOS 13 allows you to have two active VPN connections as long as lone of them is a "personal" profile and the other is classic enterprise profile.
1 reply 0 retweets 0 likes
That’s neat! Won’t the Algo-generated IPSEC mobileconfig work for this use case? You won’t have to setup the convoluted packet shoveling to use WireGuard.
-
-
Possibly, I'll look into it tonight and see how it goes
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.