[strongSwan] Client to site and freeradius

Клеусов Владимир Сергеевич Kleusov.Vladimir at wildberries.ru
Tue Jun 23 19:04:15 CEST 2020


Hi
I configure strongswan for vpn clients.Authentication via freeradius. Freeradius eap method is ttls/pap. Is it possible to configure strongswan with this configuration ?If so why ?

If in /etc/ipsec.conf etc/ipsec.conf
conn IKEv2-MSCHAPv2-Apple
also="IPSec-IKEv2"
rightauth=eap-radius
leftid=vpn.domain.com<http://vpn.domain.com>

Then the authentication error and the logs of the radius
login incorrect (EAP: no mutually acceptable types)

Connecting from mac os. Any ides )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20200623/7b9a1514/attachment.html>


More information about the Users mailing list