Community discussions

MikroTik App
 
dbeyzade
just joined
Topic Author
Posts: 23
Joined: Sat Jan 06, 2018 11:11 am

IKEv2 PEAP - MS Always on VPN

Sat Jan 06, 2018 11:15 am

Hi everyone,

I have configured the new MS Always on VPN technology that uses RADIUS, Active Directory Certificate Services and Windows RRAS:

https://docs.microsoft.com/en-us/window ... y-overview

Apparently it is possible to use an alternative VPN server than Windows Server RRAS, I was hoping to user our Mikrotik router instead.

The VPN uses IKEv2 with a user certificate issued from Active Directory Certificate Services, this is presented to the RADIUS server via PEAP authentication.

Does the Mikrotik suppoert IKEv2 with radius PEAP authentication?

You can read more about how to set this up using only the windows components here:

https://4sysops.com/archives/always-on- ... indows-10/

Apparently this is the new MS "standard" for corportate VPN, so would be sure good to get this working on the Mikrotik.

If anyone has any thoughts or ideas I would sure be grateful to hear them!

Thanks

Daniel
 
cameorol
just joined
Posts: 1
Joined: Wed Feb 06, 2019 4:56 pm

Re: IKEv2 PEAP - MS Always on VPN

Wed Feb 06, 2019 4:58 pm

Hi, did you ever get this set up?
I am looking at this now and would love to be able to get it working with our Mikrotik router
 
User avatar
ivn
just joined
Posts: 16
Joined: Sun Mar 11, 2018 3:37 pm

Re: IKEv2 PEAP - MS Always on VPN

Fri Jul 12, 2019 4:50 pm

Guys, any news regarding this topic?
 
Widmo
just joined
Posts: 8
Joined: Thu Sep 14, 2017 2:02 am

Re: IKEv2 PEAP - MS Always on VPN

Wed Aug 21, 2019 1:05 am

Bump :)
 
User avatar
ivn
just joined
Posts: 16
Joined: Sun Mar 11, 2018 3:37 pm

Re: IKEv2 PEAP - MS Always on VPN

Mon Jan 06, 2020 6:10 pm

I can tell that Always On VPN works fine with Mikrotik's ikev2 eap radius.
I used this guide to configure Windows Servers https://4sysops.com/archives/always-on- ... indows-10/
Except RRAS part.
Also I use trusted certificated from Comodo for Mikrotik's ikev2 instead of AD CS.
You just need to configure ikev2 server on Mikrotik and use Windows NPS as Radius server for Mikrotik.

Just one drawback for me that Mikrotik does not support SSTP certificate authentication. We could use it with AOVPN too, because AOVPN supports sstp fallback in case of ikev2 cannot connect.
 
rootwilliamson
just joined
Posts: 3
Joined: Thu Nov 07, 2019 10:02 am

Re: IKEv2 PEAP - MS Always on VPN

Tue Jan 07, 2020 12:18 pm

I have been using Mikrotik router since 2019 and always connect vpn on my pc with ikev2. I have never seen any issue regarding connectivity or else and I use this ikev2 guide [REDACTED]