OPNsense Forum

English Forums => General Discussion => Topic started by: kapara on September 01, 2019, 11:46:59 pm

Title: IPSEC user auth with local user and 2FA
Post by: kapara on September 01, 2019, 11:46:59 pm
Is it possible to create local access users with 2FA for mobile vpn access? 
Title: Re: IPSEC user auth with local user and 2FA
Post by: mimugmail on September 02, 2019, 05:54:55 am
No, only with OpenVPN
Title: Re: IPSEC user auth with local user and 2FA
Post by: franco on September 03, 2019, 09:38:38 am
Huh, why not? It uses the same authentication system.


Cheers,
Franco
Title: Re: IPSEC user auth with local user and 2FA
Post by: mimugmail on September 03, 2019, 10:22:48 am
- EAP-MSCHAP requires the usage of eap keys -> no 2FA
- EAP-RADIUS would work, but FreeRadius plugin only work wir local users and has no hook for 2FA server
Title: Re: IPSEC user auth with local user and 2FA
Post by: kapara on September 04, 2019, 12:53:38 am
I created a new server Local + Time based one time password (Not Preshared Keys) with EAP-MSCHAP and specified that database in Mobile clients but it did not work.  Only the preshared keys seem to work.

Really too bad this does not work as it makes the 2fa only good for securing firewall management and not vpn though the documentation states it can be used with IPSEC.

There is no instruction however on how to get this working.  If this is possible It would be great to know how to make it work.
Title: Re: IPSEC user auth with local user and 2FA
Post by: mimugmail on September 04, 2019, 07:16:59 am
Maybe with old IKEv1 and cisco-like groups, never tested it. With OpenVPN no big deal
Title: Re: IPSEC user auth with local user and 2FA
Post by: kapara on September 05, 2019, 08:50:19 pm
Franco,

Any feedback as to this?
Title: Re: IPSEC user auth with local user and 2FA
Post by: mimugmail on September 05, 2019, 08:55:58 pm
There *might* be a chance that it works with legacy IKEv1, just give it a try, with IKEv2 no chance
Title: Re: IPSEC user auth with local user and 2FA
Post by: kapara on September 05, 2019, 09:19:24 pm
The problem is I am using Native windows.  I don't think IKEv1 works with native windows.