No EAP-MSChapv2 or other option but RSA and PSK even no Xauth
-
This post is deleted! -
The extra authentication options only appear for a mobile Phase 1 entry. There can only be one of those.
-
This post is deleted! -
You can have any number of site-to-site IPsec VPNs. But only one for remote access/mobile clients.
-
This post is deleted! -
No.
-
This post is deleted! -
They can all use IKEv2 with EAP-MSCHAPv2. For iOS, use the Apple profile tool to configure a profile that matches your settings, then apply that profile to the device.
There are numerous threads covering the details.
-
This post is deleted! -
Ah, sorry. Well with Windows it can be made to work, though you have to apply routes by hand. With Android, using the strongSwan android app you can connect to anything you can configure in pfSense.
-
Again, there are numerous threads around the forum already covering this in detail.