Palo configuration for IPhone native ipsec (appears to be cisco client) vpn

I am attempting to setup the native iphone vpn client ipsec app to connect to a PA-455 . Following the below article I cannot get a connection. A little background is that I have a globalprotect portal open with a single IP from my ISP. Due to having a single IP there is a nat forward for that portal. Globalprotect works fine. Looking at traffic I see traffic arriving from the iphone on port 500 though I am unable to get a connection. Doing some research it is unclear if this functionality works with the iphone and properly documented. Curious if someone can provide insight that has this configure.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAlICAW

EDIT: for clarity, this is NOT concerning using the globalprotect app but the native iphone vpn client

global protect needs a license to connect to apple/android.

All i can say is that it used to work, haven’t done it for a while so, considering quality of recent software versions, i am not sure if that matters.

Do you have “Enable X-Auth Support” checked?

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAlICAW&lang=en_US%E2%80%A9

native iphone vpn client NOT GP

yes along with a group name and password