[strongSwan] Multi rounds

Christian Salway christian.salway at naimuri.com
Tue Jul 10 15:42:40 CEST 2018


Thanks for the explanation, Tobias.

I looking at using Duo for the MFA now.  Don't think it's possible with strongSwan and {radius, AD} and native OSX, Win VPN's to have MFA.


Kind regards,

Christian Salway
IT Consultant - Naimuri

T: +44 7463 331432
E: christian.salway at naimuri.com
A: Naimuri Ltd, Capstan House, Manchester M50 2UW

> On 10 Jul 2018, at 09:40, Tobias Brunner <tobias at strongswan.org> wrote:
> 
> Hi Christian,
> 
>> You say on [1] that "The native iOS and OS X clients are known to work
>> fine with multiple authentication rounds.", yet I have the server
>> configured with multiple rounds using xauth but OSX is only requesting EAP
> 
> XAuth is only for IKEv1
> EAP is only for IKEv2 (unless the xauth-eap plugin is used)
> 
> So if you use IKEv2 you can ignore that whole XAuth section (including
> the multiple rounds subsection) in the description of the eap-radius plugin.
> 
> Regards,
> Tobias

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20180710/e4ae12c7/attachment-0001.html>


More information about the Users mailing list