OPNsense Forum

English Forums => Virtual private networks => Topic started by: globoximator on October 02, 2023, 09:33:15 AM

Title: IPSEC EAP-RADIUD PAP und privacyidea
Post by: globoximator on October 02, 2023, 09:33:15 AM
Hello everyone,

I'm currently in the process of configuring IPSEC for Roadwarrior with Active Directory authentication via Radius.

I have between the AD and the opnsense privacyidea as radiius server. I would like to use this for totp. I have configured IPSEC Roadwarrior with EAP-RADIUS.

Now the question is does EAP-RADIUS PAP? When authenticating with domain user and TOTP, the password must be sent to the Radius via PAP. With mschapv2 a challenge response is used and the TOTP part cannot be separated from the password.

When I test the user with totp on opnsense under Access/Tester, the authentication works without any problems.

Has anyone done this before or can give me information?
Title: Re: IPSEC EAP-RADIUD PAP und privacyidea
Post by: mimugmail on October 02, 2023, 11:40:08 AM
EAP itself requires CHAP, this wont work
Title: Re: IPSEC EAP-RADIUD PAP und privacyidea
Post by: globoximator on October 05, 2023, 05:35:29 PM
Thanks. I already suspected that.

Is there an alternative with IPSEC, Radius and TOTP?

How about PSK + Xauth and do Radius on mobile Clients Backend?
Title: Re: IPSEC EAP-RADIUD PAP und privacyidea
Post by: mimugmail on October 05, 2023, 06:02:56 PM
I would go for OpenVPN instead of IPsec