IKEv2 VPN with AD authentication problem
Hello,
I've set up an IKEv2 VPN and with local user on FLEX200, this connects fine from Secuextender. Now I want to integrate with AD, so created a user on domain controller with read rights on the security group
AAA Server Active directory setup done, configuration validation with user says OK
Created Authentication method (testauth) and added the AD Profile
Created ext-group-user in Object (TEST_AD-Users), filled in Group Identifier with right security group from AD and entered a test username: OK so far
Changed my IKEv2 Gateway EAP:
- AAA Method: testauth
- Allowed User: TEST_AD-USers
Now I try to connect in tunnel from Secuextender, but I get an EAP authentication failed error
Filled username in as: username also tried username@domain.local and username@domain.
What could be wrong?
Accepted Solution
-
Hi @nielsscheldeman ,
Greeting Forum.
Please kindly check if you have enable MSCHAPv2 at AD settings.
If the settings are fine. Please share configuration files and packets betwee AD/Firewall by private message
Thank you
0
All Replies
-
I am not sure, but reading your log entry, it looks like the authentication process is expecting an Active Directory user name, not Active Directory group name.
I could easily be mistaken. Maybe it is something as simple as making sure that only lowercase name is used, not mixed uppercase/lowercase.
0 -
Yes I use the exact same username as configured on the AD, only lowercase.
0 -
Hi @nielsscheldeman ,
Greeting Forum.
Please kindly check if you have enable MSCHAPv2 at AD settings.
If the settings are fine. Please share configuration files and packets betwee AD/Firewall by private message
Thank you
0 -
Thanks! That was what I forgot to fill in.
1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight