一般手机不能很好支持ssl vpn 和EAP认证, 客户需要部署L2TP OVER IPSEC
配置:
interface Virtual-Template1
ppp authentication-mode chap
ip address 172.16.19.1 255.255.255.0
firewall zone untrust
set priority 5
add interface Dialer0
add interface Virtual-Template1
l2tp enable
l2tp-group 1
tunnel password cipher admin@123 //关闭tunnel认证 undo tunnel authentication
tunnel name LNS
allow l2tp virtual