Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Which VPN Authentification?

    Scheduled Pinned Locked Moved IPsec
    5 Posts 2 Posters 706 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alitai
      last edited by

      Hello Together

      I looking which Authentication Methods i should use for an IPsec VPN Connection.

      Is there a Option for PEAP-TLS or PEAP-MSCHAPV2?
      I'm a little bit confused because of this: https://doc.pfsense.org/index.php/Using_EAP_and_PEAP_with_FreeRADIUS
      This must be only for WLAN?

      For me it looks like EAP-RADIUS is only possible with: EAP-MSCHAPV2 and EAP-TLS

      What (else) is possible? Sorry i'm try to find the perspective.

      Hope for a plausible Answer.

      Many Thanks

      Best Regards
      Alitai

      1 Reply Last reply Reply Quote 0
      • A
        Alitai
        last edited by

        Hello

        I'm a step further.

        Config done and works (Android and IOS):
        https://doc.pfsense.org/index.php/IKEv2_with_EAP-TLS

        Is it now possible to use a Freeradius Server with this config or does it only work with Mschapv2?

        And the other Question i have: Is PEAP Supported for a VPN Connection in pfsense? It looks it's not.

        Many Thanks

        Regards
        Alitai

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Those things are not mutually exclusive. See: https://doc.pfsense.org/index.php/IKEv2_with_EAP-RADIUS

          Steve

          1 Reply Last reply Reply Quote 0
          • A
            Alitai
            last edited by

            Thanks for your Answer.  :)

            I don't understand it 100% but i found this:
            https://doc.pfsense.org/index.php/Mobile_VPN_Client_Availability

            It shows that my Configuration only works without Radius.
            Hope this is still up to date…

            Anyways, i'm happy that it works.

            Thanks
            Regards
            Alitai

            1 Reply Last reply Reply Quote 0
            • A
              Alitai
              last edited by

              Hello

              Got it to work. :)

              EAP-Radius means that the VPN Server will send the Authentification to the FreeRadius Server (That was not clear for me).

              So i can use now EAP-TLS and EAP-MSCHAPV2 with Freeradius at the same Time.

              Thanks

              Regards
              Alitai

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.