USG FLEX 500 VPN Server EAP-MSChapv2 vs EAP-TLS/PEAP on Radius

custom01
custom01 Posts: 4  Freshman Member
First Comment

Hello,

i've got some trouble setting up remote user connection with certificate instead of user/password, and i don't find much documentation about this on Zyxel networks.

I've setup VPN gateway & tunnel for remote user connection with radius authentification EAP-MSChapv2 successfully, but when i'm trying to change Windows Built-in VPN configuration to use EAP-TLS / PEAP instead of EAP-MSChapv2, connection is never establishing and timed out.

Is it a Zyxel product limitation ? I see on firewall GUI that only MSChapv2 is supported, but i'm wondering if it's also for AAA Radius auth or only USG built-in auth. I saw few doc on AP and 802.11x using EAP-TLS with NXC, but not for USG FLEX itself. (non H version)

The thing is when i switch to EAP-TLS / PEAP the auth is forwarded to my radius server, and Access-Accept is anwsered, like MSChap, but connection never establishing.

On client log i've got an 1931 error, and USG Log doesn't displaying Auth Fail message.

Picture when i'm using EAP-MSChapv2 vs PEAP/EAP-TLS VPN profiles :

On first &second picture, the radius server sent an Access-Accept packet, but USG don't display [AUTH] Recv:[AUTH] when EAP-TLS / PEAP are used.

Thanks for your replies, and every information that could be usefull.

Best Regards.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,571  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @custom01

    Could you please help check your client's log? Based on the EAP-TLS process, this seems to indicate that the negotiation between the client and the Radius server is stuck.

    Zyxel Melen


  • custom01
    custom01 Posts: 4  Freshman Member
    First Comment
    edited December 19

    Hello,

    RasClient log event when i'm using MSChapv2 vs EAP-TLS configuration on Windows client :

    20221
    20222
    20223
    20224
    20291
    20225 -> conn Established

    20221
    20222
    20223
    20224
    20291
    20227 -> error 1931

    In my original post, the firewall seems to not forwarding EAP Success to client, which waiting to start handshake, the radius server is sending Access-Accept in both case.

    Could you please confirm that

    [AUTH] Recv: AUTH

    is related to firewall receiving Access-Accept packet from Radius, else it will be Auth Fail ?

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,571  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @custom01,

    This is more likely an issue on the client and Radius server. I have searched for some posts related to "IPSec VPN error 1931" on Microsoft and I think you can take this post a look:

    Windows VPN doesn't connect, error 1931. Wireshark shows no connection - Microsoft Community

    Zyxel Melen


Security Highlight