Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-06 Thread Michael Lam
e wrote: > > On Fri, Apr 05, 2019 at 01:45:19PM +0000, Michael Lam said unto me: >> >> Are you able to have 2 clients connected at the same time? When I tried >> that (I am using mschap) whenever the 2nd client connects the 1st one's >> traffic will not go through

Re: Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2019-04-05 Thread Michael Lam
Are you able to have 2 clients connected at the same time? When I tried that (I am using mschap) whenever the 2nd client connects the 1st one's traffic will not go through anymore (it stays connected but no traffic can go through). I raised this a month ago but seems to have no response. Still tr

Re: iked road warrior setup with multiple clients connecting

2019-03-16 Thread Michael Lam
Hi, Just want to give a pump here to see if anyone get this resolved. Rgds, Michael > On 1 Mar 2019, at 8:24 PM, Michael Lam wrote: > > > >> On 1 Mar 2019, at 6:42 AM, Stuart Henderson wrote: >> >> On 2019-02-28, Michael Lam wrote: >>> Just want to

Re: iked road warrior setup with multiple clients connecting

2019-03-01 Thread Michael Lam
> On 1 Mar 2019, at 6:42 AM, Stuart Henderson wrote: > > On 2019-02-28, Michael Lam wrote: >> Just want to highlight that there is a FAQ document checked in that >> provides some samples of iked configurations for road-warrior setup. >> >> I am using almo

Re: iked road warrior setup with multiple clients connecting

2019-02-28 Thread Michael Lam
client from working. Hope this helps with others until it is fixed. > On 26 Feb 2019, at 10:51 PM, Michael Lam wrote: > > > >> On 26 Feb 2019, at 5:11 AM, William Ahern wrote: >> >> On Mon, Feb 25, 2019 at 03:44:10PM +, Michael Lam wrote: >>> Hi,

Re: iked road warrior setup with multiple clients connecting

2019-02-26 Thread Michael Lam
> On 26 Feb 2019, at 5:11 AM, William Ahern wrote: > > On Mon, Feb 25, 2019 at 03:44:10PM +, Michael Lam wrote: >> Hi, >> >> I have a very straight forward setup use case that I want to use my >> OpenBSD router as a VPN gateway, which will accept IKEv2

Re: iked road warrior setup with multiple clients connecting

2019-02-26 Thread Michael Lam
> On 26 Feb 2019, at 5:11 AM, William Ahern wrote: > > On Mon, Feb 25, 2019 at 03:44:10PM +, Michael Lam wrote: >> Hi, >> >> I have a very straight forward setup use case that I want to use my >> OpenBSD router as a VPN gateway, which will accept IKEv2

iked road warrior setup with multiple clients connecting

2019-02-25 Thread Michael Lam
Hi, I have a very straight forward setup use case that I want to use my OpenBSD router as a VPN gateway, which will accept IKEv2 road warrior connections from the Internet and route all traffics through my router. I am using a ms-chapv2 authentication and a letsencrypt certificate, which I can su

Re: iked with Windows 10 MS-ChapV2

2018-01-07 Thread Michael Lam
think it has something to do with how Windows offers the proposal or peerid. On Mon, 8 Jan 2018 at 6:13 AM, Patrick Wildt wrote: > On Wed, Jan 03, 2018 at 03:11:01AM +0000, Michael Lam wrote: > > Hi all, > > > > Does anyone have experience with using iked with a Windows 10

iked with Windows 10 MS-ChapV2

2018-01-02 Thread Michael Lam
Hi all, Does anyone have experience with using iked with a Windows 10 and EAP mschap-v2 authentication in a road warrior setup? I tried but it doesn’t work. It always return error saying no local certificate found. On a side note - Windows seems to report it’s IP address as peerid. On the OpenBS