<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 10pt;
font-family:Tahoma
}
--></style>
</head>
<body class='hmmessage'><div dir='ltr'>
Hi Julian,<br><br>Thanks for the reply. I changed the default eap type to mschapv2 but the problem persists. Do you<br>mind to post your strongswan.conf and ipsec.conf so I can make sure it's not a strongswan but a <br>freeradius problem? Thank you.<br><br><div>> Date: Fri, 28 Oct 2011 17:10:36 +0200<br>> From: julian.poschmann@rwth-aachen.de<br>> To: users@lists.strongswan.org<br>> Subject: Re: [strongSwan] Strongswan+RADIUS secret code problem?<br>> <br>> -----BEGIN PGP SIGNED MESSAGE-----<br>> Hash: SHA1<br>> <br>> Hi,<br>> <br>> I have similar setup, here two caveeats I had:<br>> <br>> 1) Windows 7 was not happy with the eap-type the radius server<br>> suggested and quit with error 13801. I had to set "default_eap_type =<br>> mschapv2" in eap.conf. I think Windows 7 only supports eap-mschapv2<br>> for it's ikev2 client. Maybe there is a more elegant way than changing<br>> the default eap type. I haven't looked further into it.<br>> <br>> 2) There have been license issue with openssl in freedradius under<br>> debian/ubuntu resulting in the repo version being compiled with very<br>> limited functionality. Although it shouldn't have an impact on<br>> eap-mschapv2 (I think), maybe it's worth a try compiling freefradius<br>> yourself.<br>> <br>> Regards,<br>> Julian<br>> <br>> Am 28.10.2011 06:37, schrieb T Z:<br>> > Hi all,<br>> > <br>> > I'm using Strongswan 4.5.2 (from Debian squeeze-backports) and <br>> > Freeradius 2.1.0 (from Debian stable) to construct an IKEv2 VPN for<br>> > my clients. It seems that Strongswan is connected with Freeradius,<br>> > but client connection just fails. Testing with Windows 7 IKEv2<br>> > client, it prompts "Error 13801: IKE authentication credentials are<br>> > unacceptable."<br>> <br>> - -- <br>> Julian Poschmann<br>> Josefstr. 126<br>> 52080 Aachen-Eilendorf<br>> <br>> Telefon: +49 170 3295135<br>> E-Mail: julian.poschmannn@rwth-aachen.de<br>> PGP-ID: 0x7D51DD8B<br>> -----BEGIN PGP SIGNATURE-----<br>> Version: GnuPG v2.0.17 (MingW32)<br>> <br>> iEYEARECAAYFAk6qxewACgkQJmSm8H1R3YtLhwCfWyuSXztlTxVFRfOMhLYgW4cz<br>> sjgAn31r+lBORw7Z3P38ZWNn2gtFtoAh<br>> =Vytf<br>> -----END PGP SIGNATURE-----<br>> <br>> _______________________________________________<br>> Users mailing list<br>> Users@lists.strongswan.org<br>> https://lists.strongswan.org/mailman/listinfo/users<br></div> </div></body>
</html>