Hot!IKE v2 + one P1 + EAP between two Fortigates

Author
Agent 1994
Silver Member
  • Total Posts : 61
  • Scores: 7
  • Reward points: 0
  • Joined: 2016/08/03 09:15:51
  • Location: Rosario, Santa Fe, Argentina
  • Status: offline
2018/07/11 10:12:39 (permalink)
0

IKE v2 + one P1 + EAP between two Fortigates

Hello Forum,
 
 I'm currently trying to do something similar to this recpipe: https://cookbook.fortinet.com/hub-and-spoke-vpn-using-quick-mode-selectors/, but using IKE v2. TL;DR: Many remote sites using the same phase 1 settings, using the same PSK and local id but XAuth for identifying the remote sites.
 
 With IKE v2 we don't have XAuth, but we do have EAP. However, I couldn't find any equivalent for authusr and authpasswd in EAP... and yes, I have RTFM .
 
 Any hints? Or should I go back to IKE v1?
 
Thanks in advance,
#1
emnoc
Expert Member
  • Total Posts : 4890
  • Scores: 300
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: IKE v2 + one P1 + EAP between two Fortigates 2018/07/11 12:56:57 (permalink)
5 (1)
Here's you go, I just posted new blogs on IKEv2 a few weeks back. You read these for more how to and issues IKEv2.
 
http://socpuppet.blogspot.com/2018/06/fortios-and-eap-identity-vpn.html
http://socpuppet.blogspot.com/2018/06/ncp-vpnclient-ikev2-with-fortios-v60.html
http://socpuppet.blogspot.com/2018/07/ikev2notifytsunacceptable.html
 
It should be very clear on how you would  go about it with EAP.

PCNSE6,PCNSE7, ACE, CCNP,FCNSP,FCESP,Linux+,CEH,ECSA,SCSA,SCNA,CISCA email/web
#2
Agent 1994
Silver Member
  • Total Posts : 61
  • Scores: 7
  • Reward points: 0
  • Joined: 2016/08/03 09:15:51
  • Location: Rosario, Santa Fe, Argentina
  • Status: offline
Re: IKE v2 + one P1 + EAP between two Fortigates 2018/07/12 11:13:06 (permalink)
0
Thanks for your reply, I'll take a look and get back here to post the results.
 
PS: Nice blog, I already bookmarked it.
#3
emnoc
Expert Member
  • Total Posts : 4890
  • Scores: 300
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: IKE v2 + one P1 + EAP between two Fortigates 2018/07/12 16:51:31 (permalink)
0
Be careful of  send  EAP identities  and you should be okay.
 

PCNSE6,PCNSE7, ACE, CCNP,FCNSP,FCESP,Linux+,CEH,ECSA,SCSA,SCNA,CISCA email/web
#4
Jump to:
© 2018 APG vNext Commercial Version 5.5