VPN enhancements in iOS 13 and macOS Catalina
Starting with iOS 13, IPsec supports HMAC-SHA-256 with IKEv1 VPN.
To make sure that your iOS 13 and macOS Catalina clients can connect to your IKEv1 VPN server, configure the server to truncate the output of the SHA-256 hash to 128 bits. Truncating to a smaller number of bits might cause the server to drop data that VPN clients transmit.
To make sure that your iOS 13 and macOS Catalina clients can use IKEv1 or L2TP, don't use a double-quote character in the value of any of the keys in a VPN configuration profile. Using a double-quote character for these VPN types can prevent the client from connecting, starting with iOS 13.6 and macOS 10.15.6.