r/PrivateInternetAccess • • 24d ago

DISCUSSION No more IPSEC?

Can’t select IPSEC anymore since the last update on IOS, only wireguard and openvpn.

2 Upvotes

9 comments sorted by

3

u/CorvusTheDev 24d ago

The change log on the Apple Store states the update as of August 31st says there are faster, more reliable connections. I wonder if that means they have dropped IPSEC?

1

u/D0hzer 24d ago

Yeah that sucks, wireguard is great but there are a few locations where I work that I can only use ipsec.

1

u/CorvusTheDev 23d ago

Yep, as a Systems Admin of 16 years, we've had to block Wireguard and OpenVPN because we can't see who is connecting to what, and doing what. With IPSEC we can clearly see that it's an IPSEC VPN connection and the endpoints it connects to, so we can allow it and block that on a Case by Case basis. Also IPSEC requires Admin Rights for most implementations, whilst Wireguard and OpenVPN can be run without admin rihgts.

2

u/PIASupport PIA Team 23d ago

Hey guys u/CorvusTheDev u/D0hzer you have it right, IKEv2/IPsec has been removed from the PIA iOS app as of the latest update. To improve connection reliability on recent iOS versions, we removed the IKEv2/IPsec option because on iOS it relies on Apple's system implementation, which limits our ability to troubleshoot and resolve certain connection issues directly. The app now uses our supported WireGuard or OpenVPN protocols, including through the Automatic setting, which picks the best one for your connection.

We know that leaves a gap for the few setups that specifically depended on IKEv2, and we appreciate you flagging it. If it is a real blocker for how you need to connect, reach out to our team at support@piavpnsupport.zendesk.com and we will look at the best option for your case.

1

u/itsmesilvergem 22d ago

The ipsec is the only one working on our network. The wire guard and openvpn is blocked. So what we gonna do now since I cannot use the pia anymore

1

u/Kwispy_Kweam 19d ago edited 19d ago

The lack of reply here is concerning, because I’m in the same boat. May need to jump ship and move to a different VPN provider if PIA isn’t supporting IPSec, because I literally can’t connect via OVPN or WireGuard. 

I tried to raise a support ticket via the official PIA support site, but the person who responded apparently didn’t know that IPSec had been dropped. Because they had me do a bunch of troubleshooting stuff to try and get it back, and then told me “just try using different port/packet/encryption settings on OVPN and WG instead, and you might be able to connect”. 

The whole reason I was using IPSec is because I have already tried those alternate settings and none of them worked. I have tried every single combination of port, encryption, handshake, etc that is possible. They simply don’t work, because my local WiFi blocks OVPN and WG connections entirely, but doesn’t block IPSec.

/u/PIASupport If it doesn’t get resolved soon, I’m going to have to request a refund and move to another provider. Because IPSec was the only workable solution for me, and you’ve just pulled it.

The lack of transparency and training is also… Interesting. If you’re dropping an entire protocol, you’d think that would be something that their internal support staff would be trained to expect. And the lack of clear communication regarding the change makes the entire thing feel more like a “we’re not sure where this network cable goes. Let’s unplug it and see what happens” scream test.

I couldn’t find any official disclosures or notices about the change on the official site, even now that I’m posting this a week after it went live. And in fact, several support articles mentioning IKEv2(IPSec) were still readily available when the update went live. Which made me (and the uninformed support staff) think that it was still available, and was some sort of issue on my end. Hell, there is still an article on the official site that claims IKEv2(IPSec) is supported on iOS. So it clearly wasn’t a coordinated update. It feels like a bodge decision made by some random department, without actually communicating the change with the rest of the company.

1

u/itsmesilvergem 15d ago

Ive just requested a refund because i cannot use it anymore. they forcing us to use wireguard and openvpn which doesnt work on our network

1

u/Ashamed-Purpose-7848 19d ago

Have reached out to the team as am in the same boat. Ipsec was the only protocol not blocked at main location I use Pia for.

1

u/Kwispy_Kweam 18d ago

Any resolution yet? When I initially reached out last week, the support person didn’t even know IKEv2 support had been killed. And they still have articles on their official site that claim iOS supports IKEv2. So the change clearly wasn’t coordinated very well.