[strongSwan] Combining authentication types

Fred curious_freddy at gmsl.co.uk
Fri Jun 26 15:07:20 CEST 2015


On 26/06/2015 13:51, Noel Kuntze wrote:
> Use eap-dynamic[1][2] then.
>
> [1] https://wiki.strongswan.org/projects/strongswan/wiki/Eap-dynamic
> [2] https://www.strongswan.org/uml/testresults/ikev2/rw-eap-dynamic/index.html

Thanks Noel.

Am I right in thinking this is only required when the differing property 
is only the EAP method?

And would this have worked fine in a different scenario where all the 
connections didn't use EAP.. but had some other distinguishing property? 
For e.g. if only coming from a specific IP or something? Is there a 
diagram or otherwise that explains the logic that StrongSwan follows in 
trying to select the correct conn section to use? and what connection 
settings can be used as selectors?

Fred


More information about the Users mailing list