{"id":27971,"date":"2025-05-09T14:36:26","date_gmt":"2025-05-09T12:36:26","guid":{"rendered":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/?p=27971"},"modified":"2025-09-22T09:39:43","modified_gmt":"2025-09-22T07:39:43","slug":"howto-watchguard-ipsec-mobile-vpn-client-by-ncp-jetzt-auch-mit-ikev2-support","status":"publish","type":"post","link":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2025\/05\/howto-watchguard-ipsec-mobile-vpn-client-by-ncp-jetzt-auch-mit-ikev2-support\/","title":{"rendered":"HOWTO: WatchGuard IPSec Mobile VPN Client by NCP \u2013 Jetzt auch mit IKEv2 Support"},"content":{"rendered":"<p>WatchGuard Firewalls erm\u00f6glichen verschiedene Optionen f\u00fcr den mobilen VPN-Zugriff. Der SSLVPN auf OpenVPN-Basis ist besonders benutzerfreundlich und erfordert keine zus\u00e4tzlichen Lizenzen \u2013 er ist daher wahrscheinlich die am h\u00e4ufigsten genutzte L\u00f6sung. IKEv2 ist bereits in Windows integriert und bietet eine sp\u00fcrbar bessere Performance als SSLVPN \u2013 entsprechend gewinnt es zunehmend an Bedeutung.<\/p>\n<p>WatchGuard bietet f\u00fcr das Protokoll IKEv1\/IPSEC Mobile-VPN (Legacy) schon seit langem einen Premium-Client (by NCP) zum Kauf an (<a href=\"https:\/\/www.boc.de\/mobile-security.html\" target=\"_blank\" rel=\"noopener\">WatchGuard IPSec Client bei uns im Shop<\/a>). Seit dem 7. November 2024 kann der kostenpflichtige Client nun auch \u00fcber das moderne IKEv2-Protokoll kommunizieren. Der NCP-Client bietet im Vergleich zur integrierten Windows-VPN-L\u00f6sung eine Vielzahl an Vorteilen. Ob sich der Aufpreis lohnt, h\u00e4ngt vom individuellen Anwendungsfall ab. Eine kostenlose 30-Tage Trial-Version kann unverbindlich getestet werden. Sprechen Sie uns dazu gerne an.<\/p>\n<p>In diesem Blog-Artikel geht es darum, wie Sie mit dem WatchGuard IPSec Mobile VPN Client (NCP) eine sichere, leistungsstarke und flexible IKEv2-VPN-Verbindung f\u00fcr mobile Arbeitspl\u00e4tze einrichten k\u00f6nnen \u2013 inklusive Start-Before-Logon und Netzwerk-Isolation.<\/p>\n<p><!--more--><\/p>\n<h2>Vorteile des WatchGuard IPSec Client<\/h2>\n<ul>\n<li><strong>Integrierter Failover:<\/strong> Mehrere Ziel-IPs\/FQDNs konfigurierbar (z.B. Failover \u00fcber zweiten ISP)<\/li>\n<li><strong>Zuverl\u00e4ssige Verbindung:<\/strong> Unempfindlich gegen\u00fcber Carrier-grade NAT, kleine MTU-Sizes, \u2026 sehr gutes Fehlerlog<\/li>\n<li><strong>Integrierte Endpoint-Firewall:<\/strong> Beispielsweise f\u00fcr Home-Office-Notebooks, welche in unbekannten Netzwerken isoliert werden sollen\u00a0 -&gt; VPN wird erzwungen und benachbarte IPs blockiert<\/li>\n<li><strong>Start-Before-Logon:<\/strong> Der VPN-Tunnel kann vor dem Windows-Logon aufgebaut werden und bietet somit keine Einschr\u00e4nkungen f\u00fcr Skripte, GPO, Netzlaufwerke, \u2026<\/li>\n<li><strong>VPN-Bypass:<\/strong> Applikationen k\u00f6nnen gezielt am VPN vorbeigeleitet werden (z.B. bei zeitkritischem Traffic wie VoIP, Video-Konferenzen, \u2026)<\/li>\n<\/ul>\n<h2>Praxis-Beispiel: IKEv2-VPN inkl. VPN-Enforcement und Start-Before-Logon<\/h2>\n<h3>1. Test-Umgebung<\/h3>\n<ul>\n<li>WatchGuard Firebox T45-CW (Firmware 12.11.1 U1 -&gt; min. 12.11.1 ben\u00f6tigt)<\/li>\n<li>IKEv2 wurde auf der Firebox bereits konfiguriert (Bsp.: <a href=\"https:\/\/www.boc.de\/watchguard-info-portal\/2019\/04\/howto-mobile-ikev2-vpn-client-anbindung-mit-windows-10-boardmitteln\/\" target=\"_blank\" rel=\"noopener\">HOWTO: Mobile IKEv2 VPN \u2013 Client-Anbindung mit Windows 10 Boardmitteln<\/a>)<\/li>\n<li>WatchGuard IPSec Mobile VPN Client for Windows (Version 15.19)<\/li>\n<li>Windows 11 Professional 24H2<\/li>\n<\/ul>\n<h3>2. Ziel<\/h3>\n<p>IKEv2-Anbindung inkl. VPN-Enforcement f\u00fcr unsichere Netzwerke. Der NCP-Client soll in \u00f6ffentlichen Netzen das Notebook komplett abschotten. Eine Internetkommunikation darf erst nach VPN-Einwahl m\u00f6glich sein. Zus\u00e4tzlich wird durch Start-Before-Logon sichergestellt, dass der sichere Tunnel bereits vor Windowsanmeldung ge\u00f6ffnet wird (hilfreich bei Logon-Skripte, GPO,\u2026).<\/p>\n<h3>3. Umsetzung<\/h3>\n<ol>\n<li>Laden Sie den aktuellen VPN-Client von der WatchGuard Website herunter: <a href=\"https:\/\/software.watchguard.com\" target=\"_blank\" rel=\"noopener\">https:\/\/software.watchguard.com<\/a> -&gt; Firebox ausw\u00e4hlen (Bsp. T45-CW) -&gt; Client herunterladen:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-28023 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support1.png\" alt=\"Download WatchGuard IPSec Mobile VPN Client\" width=\"996\" height=\"450\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support1.png 996w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support1-300x136.png 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support1-768x347.png 768w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support1-800x361.png 800w\" sizes=\"(max-width: 996px) 100vw, 996px\" \/><\/li>\n<li>Installieren Sie den NCP-Client als Trial oder ggf. mit Ihrer vorhandenen Lizenz<\/li>\n<li>Verbinden Sie sich \u00fcber den Firebox System Manager mit Ihrer Firewall, \u00f6ffnen Sie den Policy Manager und laden Sie das IKEv2-Profil herunter:<br \/>\n<div class=\"su-image-carousel  su-image-carousel-has-spacing su-image-carousel-has-lightbox su-image-carousel-has-outline su-image-carousel-adaptive su-image-carousel-slides-style-minimal su-image-carousel-controls-style-dark su-image-carousel-align-none\" style=\"max-width:623px\" data-flickity-options='{\"groupCells\":true,\"cellSelector\":\".su-image-carousel-item\",\"adaptiveHeight\":true,\"cellAlign\":\"left\",\"prevNextButtons\":true,\"pageDots\":true,\"autoPlay\":false,\"imagesLoaded\":true,\"contain\":false,\"selectedAttraction\":0.15,\"friction\":1}' id=\"su_image_carousel_69d9f3356e4e0\"><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support2.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"731\" height=\"472\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support2.png\" class=\"\" alt=\"Mobile VPN - Get Started\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support2.png 731w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support2-300x194.png 300w\" sizes=\"(max-width: 731px) 100vw, 731px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support3.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"349\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support3.png\" class=\"\" alt=\"Mobile VPN with IKEv2 Client Instructions\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support3.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support3-300x138.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><\/div><script id=\"su_image_carousel_69d9f3356e4e0_script\">if(window.SUImageCarousel){setTimeout(function() {window.SUImageCarousel.initGallery(document.getElementById(\"su_image_carousel_69d9f3356e4e0\"))}, 0);}var su_image_carousel_69d9f3356e4e0_script=document.getElementById(\"su_image_carousel_69d9f3356e4e0_script\");if(su_image_carousel_69d9f3356e4e0_script){su_image_carousel_69d9f3356e4e0_script.parentNode.removeChild(su_image_carousel_69d9f3356e4e0_script);}<\/script><\/li>\n<li>Entpacken Sie das Profil auf Ihrem VPN-Test-Client (.tgz kann mit 7-Zip, WinRAR,\u2026 ge\u00f6ffnet werden). Im Unterordner \u201eWatchGuard IPSec Mobile VPN\u201c finden Sie folgende Dateien:\n<ol>\n<li>README.txt -&gt; Installationsanleitung<\/li>\n<li>WG IKEv2.pem -&gt; Zertifikat des IKEv2 Servers (der Name der .pem kann abweichen)<\/li>\n<li>WG IKEv2.ini -&gt; Profil f\u00fcr NCP Client (der Name der .ini kann abweichen)<strong><br \/>\nACHTUNG:<\/strong> Im Default wird eine &#8220;Konfigurationssperre&#8221; gesetzt. Den Benutzernamen und das Passwort findet man im ini-File:<\/p>\n<p><em>[CONFLOCKS]<\/em><br \/>\n<em>user=admin<\/em><br \/>\n<em>password=readonly<\/em><\/p>\n<p>Die Credentials k\u00f6nnen vor dem Import im ini-File oder nachtr\u00e4glich \u00fcber die GUI des Clients angepasst werden.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-28028 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support4.png\" alt=\"IKEv2-Profil Dateien\" width=\"756\" height=\"262\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support4.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support4-300x104.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><\/li>\n<\/ol>\n<\/li>\n<li>Kopieren Sie die *.pem Datei in den Ordner \u201eC:\\ProgramData\\WatchGuard\\Mobile VPN\\cacerts\u201c<\/li>\n<li>\u00d6ffnen Sie den VPN-Client \u00fcber das Desktop-Icon und legen Sie ein Profil an:<br \/>\n<div class=\"su-image-carousel  su-image-carousel-has-spacing su-image-carousel-has-lightbox su-image-carousel-has-outline su-image-carousel-adaptive su-image-carousel-slides-style-minimal su-image-carousel-controls-style-dark su-image-carousel-align-none\" style=\"max-width:623px\" data-flickity-options='{\"groupCells\":true,\"cellSelector\":\".su-image-carousel-item\",\"adaptiveHeight\":true,\"cellAlign\":\"left\",\"prevNextButtons\":true,\"pageDots\":true,\"autoPlay\":false,\"imagesLoaded\":true,\"contain\":false,\"selectedAttraction\":0.15,\"friction\":1}' id=\"su_image_carousel_69d9f3356f12a\"><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"511\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5.png\" class=\"\" alt=\"IKEv2-Profil anlegen\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5.png 623w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-300x246.png 300w\" sizes=\"(max-width: 623px) 100vw, 623px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-1.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"511\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-1.png\" class=\"\" alt=\"IKEv2-Profil anlegen Assistent\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-1.png 623w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-1-300x246.png 300w\" sizes=\"(max-width: 623px) 100vw, 623px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-2.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"483\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-2.png\" class=\"\" alt=\"IKEv2-Profil anlegen Assistent2\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-2.png 625w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-2-300x232.png 300w\" sizes=\"(max-width: 625px) 100vw, 625px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-3.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"622\" height=\"484\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-3.png\" class=\"\" alt=\"IKEv2-Profil anlegen Assistent3\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-3.png 622w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-3-300x233.png 300w\" sizes=\"(max-width: 622px) 100vw, 622px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-4.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"622\" height=\"483\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-4.png\" class=\"\" alt=\"IKEv2-Profil anlegen Assistent4\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-4.png 622w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support5-4-300x233.png 300w\" sizes=\"(max-width: 622px) 100vw, 622px\" \/><span><\/span><\/a><\/div><\/div><\/div><script id=\"su_image_carousel_69d9f3356f12a_script\">if(window.SUImageCarousel){setTimeout(function() {window.SUImageCarousel.initGallery(document.getElementById(\"su_image_carousel_69d9f3356f12a\"))}, 0);}var su_image_carousel_69d9f3356f12a_script=document.getElementById(\"su_image_carousel_69d9f3356f12a_script\");if(su_image_carousel_69d9f3356f12a_script){su_image_carousel_69d9f3356f12a_script.parentNode.removeChild(su_image_carousel_69d9f3356f12a_script);}<\/script><\/li>\n<li>Testen Sie den VPN-Zugriff:<br \/>\n<div style=\"width: 416px;\" class=\"wp-video\"><!--[if lt IE 9]><script>document.createElement('video');<\/script><![endif]-->\n<video class=\"wp-video-shortcode\" id=\"video-27971-1\" width=\"416\" height=\"470\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/mp4\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support6.mp4?_=1\" \/><a href=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support6.mp4\">https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support6.mp4<\/a><\/video><\/div><\/li>\n<\/ol>\n<h3>4. Fine-Tuning, Optimierung<\/h3>\n<ol>\n<li><strong>VPN-Bypass<\/strong><br \/>\nSie k\u00f6nnen einzelne Anwendungen oder Domains am VPN-Tunnel vorbeischleusen (z. B. MS-Teams, VoIP-Dienste, TeamViewer,\u2026). Anbei ein Beispiel f\u00fcr den Firefox (macht keinen Sinn, aber l\u00e4sst sich leicht veranschaulichen! &#x1f609;):<br \/>\n<div class=\"su-image-carousel  su-image-carousel-has-spacing su-image-carousel-has-lightbox su-image-carousel-has-outline su-image-carousel-adaptive su-image-carousel-slides-style-minimal su-image-carousel-controls-style-dark su-image-carousel-align-none\" style=\"max-width:600px\" data-flickity-options='{\"groupCells\":true,\"cellSelector\":\".su-image-carousel-item\",\"adaptiveHeight\":true,\"cellAlign\":\"left\",\"prevNextButtons\":true,\"pageDots\":true,\"autoPlay\":false,\"imagesLoaded\":true,\"contain\":false,\"selectedAttraction\":0.15,\"friction\":1}' id=\"su_image_carousel_69d9f3356fe09\"><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support7-1.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"412\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support7-1.png\" class=\"\" alt=\"VPN-Bypass Beispiel\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support7-1.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support7-1-300x163.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support8.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"412\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support8.png\" class=\"\" alt=\"VPN-Bypass-Liste\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support8.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support8-300x163.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support9-1.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"412\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support9-1.png\" class=\"\" alt=\"VPN-Bypass Konfiguration\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support9-1.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/05\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support9-1-300x163.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support10.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"683\" height=\"420\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support10.png\" class=\"\" alt=\"\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support10.png 683w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support10-300x184.png 300w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support11.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"483\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support11.png\" class=\"\" alt=\"VPN-Bypass Profil-Einstellungen\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support11.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support11-300x192.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><\/div><script id=\"su_image_carousel_69d9f3356fe09_script\">if(window.SUImageCarousel){setTimeout(function() {window.SUImageCarousel.initGallery(document.getElementById(\"su_image_carousel_69d9f3356fe09\"))}, 0);}var su_image_carousel_69d9f3356fe09_script=document.getElementById(\"su_image_carousel_69d9f3356fe09_script\");if(su_image_carousel_69d9f3356fe09_script){su_image_carousel_69d9f3356fe09_script.parentNode.removeChild(su_image_carousel_69d9f3356fe09_script);}<\/script>\nTest:<br \/>\nDer Edge-Browser kommuniziert \u00fcber den VPN-Tunnel zur Firebox, aber der Firefox-Browser direkt \u00fcber den vorgel. Router ohne VPN:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-28044 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support12.png\" alt=\"\" width=\"756\" height=\"562\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support12.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support12-300x223.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><\/li>\n<li><strong>Start-Before-Logon<br \/>\n<\/strong>Mit Start-Before-Logon k\u00f6nnen Sie sicherstellen, dass die Verbindung zur Dom\u00e4ne (via VPN) noch vor der Benutzereinwahl stattfindet. \u00dcber diesen Weg gibt es keine Probleme mit Logon-Skripten, Gruppenrichtlinien oder Netzlaufwerken:<br \/>\n<div class=\"su-image-carousel  su-image-carousel-has-spacing su-image-carousel-has-lightbox su-image-carousel-has-outline su-image-carousel-adaptive su-image-carousel-slides-style-minimal su-image-carousel-controls-style-dark su-image-carousel-align-none\" style=\"max-width:600px\" data-flickity-options='{\"groupCells\":true,\"cellSelector\":\".su-image-carousel-item\",\"adaptiveHeight\":true,\"cellAlign\":\"left\",\"prevNextButtons\":true,\"pageDots\":true,\"autoPlay\":false,\"imagesLoaded\":true,\"contain\":false,\"selectedAttraction\":0.15,\"friction\":1}' id=\"su_image_carousel_69d9f335707bd\"><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support13.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"467\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support13.png\" class=\"\" alt=\"Start-Before-Logon Verbindungsoptionen\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support13.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support13-300x185.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><div class=\"su-image-carousel-item\"><div class=\"su-image-carousel-item-content\"><a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support14.png\" data-caption=\"\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"456\" src=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support14.png\" class=\"\" alt=\"Start-Before-Logon Logon-Optionen\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support14.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support14-300x181.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><span><\/span><\/a><\/div><\/div><\/div><script id=\"su_image_carousel_69d9f335707bd_script\">if(window.SUImageCarousel){setTimeout(function() {window.SUImageCarousel.initGallery(document.getElementById(\"su_image_carousel_69d9f335707bd\"))}, 0);}var su_image_carousel_69d9f335707bd_script=document.getElementById(\"su_image_carousel_69d9f335707bd_script\");if(su_image_carousel_69d9f335707bd_script){su_image_carousel_69d9f335707bd_script.parentNode.removeChild(su_image_carousel_69d9f335707bd_script);}<\/script>\nTest:<br \/>\n<div style=\"width: 756px;\" class=\"wp-video\"><video class=\"wp-video-shortcode\" id=\"video-27971-2\" width=\"756\" height=\"456\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/mp4\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/video\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support15.mp4?_=2\" \/><a href=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/video\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support15.mp4\">https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/video\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support15.mp4<\/a><\/video><\/div><\/li>\n<li><strong>VPN-Enforcement \/ eigene Firewall<br \/>\n<\/strong>F\u00fcr mich ist der gr\u00f6\u00dfte Vorteil die integrierte Firewall, welche den Client in unbekannten Netzen komplett isolieren kann und somit die Verwendung des VPN-Tunnels erzwingt. Klicken Sie hierzu im NCP VPN Client im Men\u00fc Konfiguration -&gt; Firewall:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-28047 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support16.png\" alt=\"Firewall-Einstellungen\" width=\"412\" height=\"395\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support16.png 412w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support16-300x288.png 300w\" sizes=\"(max-width: 412px) 100vw, 412px\" \/><br \/>\nAktivieren Sie die Firewall und definieren Sie die relevanten Policies. Die Policies sollten nach Ihren Bed\u00fcrfnissen erstellt und getestet sein. In meinem Fall ist au\u00dferhalb des VPNs oder eines \u201eTrusted\u201c Networks jeglicher Traffic gesperrt (kein Surfen, Mail, &#8230;). F\u00fcr Anwendungen wie WatchGuard EPDR empfehle ich Ausnahmen.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-28052 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support17.png\" alt=\"Firewall-Einstellungen \u00dcbersicht\" width=\"756\" height=\"452\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support17.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support17-300x179.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><br \/>\nDefinieren Sie Ihre Netzwerke, welche als \u201eTrusted\u201c erkannt werden sollen:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-28053 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support18.png\" alt=\"Firewall-Einstellungen Trusted Networks\" width=\"756\" height=\"552\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support18.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support18-300x219.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><br \/>\nAu\u00dferdem empfehle ich die Firewall permanent zu aktivieren, auch wenn der VPN-Client geschlossen wird:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-28054 alignnone\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support19.png\" alt=\"Firewall-Einstellungen always on\" width=\"756\" height=\"552\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support19.png 756w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2025\/04\/howto-watchgaurd-ipsec-mobile-vpn-client-by-ncp-ikev2-support19-300x219.png 300w\" sizes=\"(max-width: 756px) 100vw, 756px\" \/><\/li>\n<\/ol>\n<h3>5. Fazit<\/h3>\n<p>Auch wenn der NCP-Client kostenpflichtig ist, bietet er deutliche Sicherheitsvorteile und eine flexible Konfiguration \u2013 besonders f\u00fcr anspruchsvolle Netzwerkanforderungen im Home-Office oder Au\u00dfendienst. Ein Blick in die 30-Tage Trial-Version empfehle ich jedem Administrator. Zus\u00e4tzlich sollten Sicherheitsmechanismen wie Multifaktor-Authentifizierung (Bsp. <a href=\"https:\/\/www.boc.de\/authpoint\" target=\"_blank\" rel=\"noopener\">https:\/\/www.boc.de\/authpoint<\/a>) und\/oder Network Access Enforcement (<a href=\"https:\/\/www.boc.de\/nae\" target=\"_blank\" rel=\"noopener\">https:\/\/www.boc.de\/nae<\/a>) nicht au\u00dfer Acht gelassen werden.<\/p>\n<p>Sie m\u00f6chten den NCP-Client in Ihrem Unternehmen testen oder ben\u00f6tigen Unterst\u00fctzung bei der Konfiguration? Kontaktieren Sie uns gerne \u2013 wir helfen weiter.<\/p>\n<h3>Weiterf\u00fchrende Links<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-us\/Content\/en-US\/Fireware\/mvpn\/client\/mvpn-ipsec_client_about_c.html\" target=\"_blank\" rel=\"noopener\">Informationen \u00fcber den IPSec Mobile Client by NCP<\/a> (Help Center)<\/li>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-us\/Content\/en-US\/Fireware\/mvpn\/ikev2\/mvpn_ikev2_mobile_vpn_client.html\" target=\"_blank\" rel=\"noopener\">IKEv2 in Verbindung mit dem WatchGuard IPSec Mobile VPN Client (inkl. Silent-Installation)<\/a> (Help Center)<\/li>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-us\/Content\/en-US\/Fireware\/mvpn\/client\/desktop_firewall_enable_c.html\" target=\"_blank\" rel=\"noopener\">WatchGuard IPSec Mobile VPN Client \u2013 Desktop Firewall aktivieren<\/a> (Help Center)<\/li>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-us\/Content\/en-US\/Fireware\/mvpn\/client\/mvpn-ipsec_see_log_msgs_c.html\" target=\"_blank\" rel=\"noopener\">Log-Informationen einsehen<\/a> (Help Center)<\/li>\n<li><a href=\"https:\/\/www.boc.de\/watchguard-info-portal\/2025\/08\/howto-ncp-silent-installation-rollout-via-gpo-mvls\/\" target=\"_blank\" rel=\"noopener\">HOWTO: NCP Silent-Installation \/ Rollout via GPO \/ MVLS<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>WatchGuard Firewalls erm\u00f6glichen verschiedene Optionen f\u00fcr den mobilen VPN-Zugriff. Der SSLVPN auf OpenVPN-Basis ist besonders benutzerfreundlich und erfordert keine zus\u00e4tzlichen Lizenzen \u2013 er ist daher wahrscheinlich die am h\u00e4ufigsten genutzte L\u00f6sung. IKEv2 ist bereits in Windows integriert und bietet eine sp\u00fcrbar bessere Performance als SSLVPN \u2013 entsprechend gewinnt es zunehmend an Bedeutung. WatchGuard bietet f\u00fcr das Protokoll IKEv1\/IPSEC Mobile-VPN (Legacy) schon seit langem einen Premium-Client &hellip; <a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2025\/05\/howto-watchguard-ipsec-mobile-vpn-client-by-ncp-jetzt-auch-mit-ikev2-support\/\" class=\"more-link\">Weiterlesen <span class=\"screen-reader-text\">HOWTO: WatchGuard IPSec Mobile VPN Client by NCP \u2013 Jetzt auch mit IKEv2 Support<\/span> <span class=\"meta-nav\">&raquo;<\/span><\/a><\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[362],"tags":[1043,638,468,12,793,971,1257,1103,594,273,1263,975,446],"class_list":["post-27971","post","type-post","status-publish","format-standard","hentry","category-howto","tag-firewall","tag-homeoffice","tag-ikev2","tag-ipsec","tag-mobile-vpn","tag-ncp","tag-road-warrior","tag-silent","tag-start-before-logon","tag-vpn","tag-vpn-bypass","tag-vpn-enforcement","tag-windows"],"_links":{"self":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/27971"}],"collection":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/comments?post=27971"}],"version-history":[{"count":41,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/27971\/revisions"}],"predecessor-version":[{"id":29118,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/27971\/revisions\/29118"}],"wp:attachment":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/media?parent=27971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/categories?post=27971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/tags?post=27971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}