[strongSwan] Client to site and freeradius

Tobias Brunner tobias at strongswan.org
Wed Jun 24 11:34:46 CEST 2020


Hi,

> Is it possible to configure
> strongswan with this configuration ?If so why ? 

Yes, strongSwan is not directly involved in the authentication if you
use the eap-radius plugin.  The EAP messages are exchanged between
client and RADIUS server, strongSwan only forwards them.  So any EAP
method can be used as long as client and RADIUS server can both agree on
one.

> Then the authentication error and the logs of the radius 
> login incorrect (EAP: no mutually acceptable types)

Apparently, the client doesn't support the EAP method the RADIUS server
proposes.

Regards,
Tobias


More information about the Users mailing list