You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Defguard Mobile on iOS 27 Beta 5 does not send traffic to gateway / TestFlight access requested
Hi,
I'm currently experiencing an issue with the Defguard Mobile client on an iPhone running iOS 27 Beta 5.
The Defguard client does not appear to send any WireGuard traffic to the Defguard Gateway at all.
The public Defguard Mobile TestFlight beta is currently not accepting new testers, so I am unable to verify whether the latest iOS build containing the recent iOS / KeepAlive / BoringTun changes already fixes the issue.
Would it be possible to get access to the current TestFlight beta?
Environment
Defguard Core: 2.0.3 stable
Client: Defguard Mobile for iOS
Device: iPhone
iOS: 27 Beta 5
Defguard Gateway: working with other clients
Windows Defguard client: working
Linux Defguard client: working
macOS Defguard client: working, including macOS 27 Beta 4/5
Official WireGuard iOS app: working on the same iPhone against another WireGuard endpoint
Problem
The iPhone can be enrolled successfully in Defguard.
When I try to connect the VPN using the Defguard Mobile client:
no working VPN tunnel is established
no traffic passes through the tunnel
the device remains shown as Never connected in the Defguard Admin UI
no WireGuard packets from the iPhone can be observed on the Defguard Gateway
Gateway packet capture
I performed a packet capture directly on the Defguard Gateway while initiating the connection from the iPhone.
There is no incoming WireGuard traffic from the iPhone at all during the connection attempt.
This seems to indicate that the problem occurs on the iOS client side before or while the initial WireGuard handshake is generated/sent.
Comparison with other Defguard clients
The same Defguard installation and Gateway work correctly with:
Windows
Linux
macOS
Therefore, the Core/Gateway configuration itself appears to be working.
Comparison with official WireGuard on the same iPhone
The official WireGuard iOS application works correctly on exactly the same iPhone when connecting to another WireGuard endpoint.
So basic WireGuard/UDP functionality on iOS 27 Beta 5 appears to work.
This makes me suspect an issue specific to the Defguard iOS VPN extension or its WireGuard/BoringTun implementation.
Possible relation to recent iOS fixes
I noticed several recent iOS-related changes in the Defguard Mobile repository, including:
iOS split-DNS fixes
new iOS builds
an iOS KeepAlive fix
BoringTun-related changes
I would therefore like to test the newest available iOS build before investigating the issue further.
Unfortunately, the public TestFlight invitation currently returns:
This beta isn't accepting any new testers right now.
TestFlight access
Could you please provide access to the current Defguard Mobile iOS TestFlight beta?
I would be happy to test the latest build specifically against this issue and report whether the current iOS changes resolve it.
I can also provide additional diagnostics if useful, including:
Defguard Mobile debug logs
Defguard Gateway logs
tcpdump captures
iOS diagnostics
comparison tests with the official WireGuard client
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Defguard Mobile on iOS 27 Beta 5 does not send traffic to gateway / TestFlight access requested
Hi,
I'm currently experiencing an issue with the Defguard Mobile client on an iPhone running iOS 27 Beta 5.
The Defguard client does not appear to send any WireGuard traffic to the Defguard Gateway at all.
The public Defguard Mobile TestFlight beta is currently not accepting new testers, so I am unable to verify whether the latest iOS build containing the recent iOS / KeepAlive / BoringTun changes already fixes the issue.
Would it be possible to get access to the current TestFlight beta?
Environment
Problem
The iPhone can be enrolled successfully in Defguard.
When I try to connect the VPN using the Defguard Mobile client:
Never connectedin the Defguard Admin UIGateway packet capture
I performed a packet capture directly on the Defguard Gateway while initiating the connection from the iPhone.
There is no incoming WireGuard traffic from the iPhone at all during the connection attempt.
This seems to indicate that the problem occurs on the iOS client side before or while the initial WireGuard handshake is generated/sent.
Comparison with other Defguard clients
The same Defguard installation and Gateway work correctly with:
Therefore, the Core/Gateway configuration itself appears to be working.
Comparison with official WireGuard on the same iPhone
The official WireGuard iOS application works correctly on exactly the same iPhone when connecting to another WireGuard endpoint.
So basic WireGuard/UDP functionality on iOS 27 Beta 5 appears to work.
This makes me suspect an issue specific to the Defguard iOS VPN extension or its WireGuard/BoringTun implementation.
Possible relation to recent iOS fixes
I noticed several recent iOS-related changes in the Defguard Mobile repository, including:
I would therefore like to test the newest available iOS build before investigating the issue further.
Unfortunately, the public TestFlight invitation currently returns:
TestFlight access
Could you please provide access to the current Defguard Mobile iOS TestFlight beta?
I would be happy to test the latest build specifically against this issue and report whether the current iOS changes resolve it.
I can also provide additional diagnostics if useful, including:
tcpdumpcapturesThanks!
All reactions