[strongSwan] strongswan network manager client using eap-radius
claude.tompers at restena.lu
Thu Jun 3 10:16:04 CEST 2010
You assumed right. :)
Ok I'll try to get it running with a proper ipsec.conf configuration without the network-manager plugin.
thanks very much for your help
On Thursday 03 June 2010 10:08:48 Martin Willi wrote:
> > 16[IKE] EAP method EAP_MSCHAPV2 succeeded, no MSK established
> > 14[IKE] verification of AUTH payload without EAP MSK failed
> Then I'd assume you are using FreeRADIUS :-).
> It does not include the MSK in MSCHAPv2 if used over EAP. IKEv2 however
> requires the MSK to calculate the AUTH payload.
> In its current form, you can't use FreeRADIUS for your setup, my
> apologies. One could extend FreeRADIUS to copy over the MPPE keys, but
> writing such a patch is not something I can do in a few minutes.
Ingénieur réseau et système
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche
6, rue Richard Coudenhove-Kalergi
Tel: +352 424409 1
Fax: +352 422473
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 198 bytes
Desc: This is a digitally signed message part.
More information about the Users