[strongSwan] MacOS 10.12 Sierra IKEv2 user/password auth

Pete Ashdown pashdown at xmission.com
Sun Oct 9 18:59:34 CEST 2016


On 10/9/16 10:49 AM, Andreas Steffen wrote:
> Hi Pete,
>
> there in no AUTH payload in the IKE_AUTH request. This means that
> the Mac wants to do EAP-based username/password authentication but
> your strongSwan server is not configured for EAP (e.g. EAP-MD5,
> EAP-MSCHAPv2 or EAP-GTC). 
Do I need something additional here?

conn win7
     leftcert=vpnHostCert.der
     leftsendcert=always
     leftauth=pubkey
     leftsubnet=0.0.0.0/0
     right=%any
     rightauth=eap-gtc
     rightsourceip=10.10.10.16/26
     rightsendcert=never
     eap_identity=%any
     keyexchange=ikev2
     auto=add



More information about the Users mailing list