Hi Yudi, > Is there a way to fine tune this behavior, ie, If the remote peer is > trying to authenticate via EAP-MSCHAPV2 the server should pick the right > method (eap-mschapv2) not the first one in the list. You need to use the eap-dynamic plugin [1]. Regards, Tobias [1] https://wiki.strongswan.org/projects/strongswan/wiki/eap-dynamic