Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
iamirreza13
New Contributor II

Configuring IPSec IKEv2 tunnel for dial up connection

Hi


I'm trying to setup IKEv2 tunnels for my remote access users. on IKEv1 i could assign tunnels to a user groups but when i change it to IKEv2, I can't find anywhere to assign the tunnel to a group. I'm using LDAP for user Authentication. how am i supposed to handle this?

Regards

.
.
1 Solution
ebilcari

This limitation is explained on these articles:

Technical Tip: IKEv2 tunnel fails when LDAP based usergroup is used for EAP

Troubleshooting Tip: Using IKEv2 for a dial-up IPsec tunnel with a RADIUS server and Local user

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
sjoshi
Staff
Staff

Hi,

Can you share the snap where you are exactly not able to assign the group.

Share both working and non working snap for ikev1 and ikev2

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
iamirreza13
New Contributor II

Hi, thanks for the reply
this is the IKEv1 setting but when i change the version to IKEv2, this section disappears cause IKEv2 doesn't work with XAUTH, but no option for EAP appears either. i think it's only configurable via CLI, but i guess you can only use the EAP with RADIUS server and you can't do it with LDAP. Do you have any insight or solution about configuring this with LDAP?

ikev1.png

.
.
iamirreza13

I've tried and did the configs via CLA and it works but only for local users and i assume RADIUS users, but it did not work with LDAP users. any suggestions?

.
.
ebilcari

This limitation is explained on these articles:

Technical Tip: IKEv2 tunnel fails when LDAP based usergroup is used for EAP

Troubleshooting Tip: Using IKEv2 for a dial-up IPsec tunnel with a RADIUS server and Local user

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors