-
Notifications
You must be signed in to change notification settings - Fork 192
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vpn/ipsec: Add additional information to swanctl roadwarrior docs #639
Comments
Thanks I didn't know this command existed. Want to offer a PR to add it to the document? |
Hi, @Monviech Option for Windows native client(Tested on Win11 22631.4460) However, for some reason Windows does not cooperate with a CHILD_SA rekeying attempt issued from server nicely(#), causing the connection likely to disconnect during the second or third rekey attempt.
Option for iOS/iPadOS native client(Tested on iOS 18) Option for Samsung (Android) native client(Tested on Samsung OneUI 6.1.1)
To fix this, we just need to set the "Remote Identifier" of EAP to the hostname of our server(#), in this case, is |
Thanks for these tests and additional information, I will include it in the tutorial as additional remarks. Note to myself: ios18.1: https://forum.opnsense.org/index.php?topic=43766.0;topicseen |
Important notices
Before you add a new report, we ask you kindly to acknowledge the following:
Is your feature request related to a problem? Please describe.
On Windows, when split-tunnel is enabled, each time connected to VPN, the route has to be manually added by using the command provided by the document.
docs/source/manual/how-tos/ipsec-swanctl-rw-ikev2-eap-mschapv2.rst
Line 656 in a71715b
https://docs.opnsense.org/manual/how-tos/ipsec-swanctl-rw-ikev2-eap-mschapv2.html#client-configuration
Describe the solution you like
Windows can automate the process with the PowerShell command
Add-VpnConnectionRoute
, with no elevated privilege required. In this example with the document, the command will be:Once connected, the configured route will add to the routing table automatically, and also delete if disconnected.
The text was updated successfully, but these errors were encountered: