Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IKEv2 with EAP-MSCHAPv2 changing from IP to DNS name

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 294 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jan-peter.klijn
      last edited by

      I have an IKEv2 with EAP-MSCHAPv2 VPN up and running OK; my clients are connected to the IP-address of my firewall.
      I want to change this setup from IP-based to hostname based and am puzzled what the way to do this is.

      I have created a new certificate with an additional entry for my IPaddress and set the common name to my DNS hostname.
      What is the correct order to change this and minimize downtime?

      • Install new certificate on clients
      • Change certificate at VPN connection
      • change connections at client to connect using hostname instead of IP

      While changing this, will clients be able to connect using either IP or DNS or does the "My identifier" at the IPsec entry allways have to be the same as the entry that is entered at the (Windows 10) client.

      thank you very much

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        You shouldn't need to touch the cert on the clients. They would only have the CA, not the server cert.

        All you need to do is change the server cert and then change where the clients connect.

        And for the record, the cert should have the hostname and IP address in the SAN list. But if you put the hostname in the CN, pfSense automatically adds a SAN for that as well, so it should be fine.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.