Page 1 of 1

IKEv2 PEAP - MS Always on VPN

Posted: Sat Jan 06, 2018 11:15 am
by dbeyzade
Hi everyone,

I have configured the new MS Always on VPN technology that uses RADIUS, Active Directory Certificate Services and Windows RRAS:

https://docs.microsoft.com/en-us/window ... y-overview

Apparently it is possible to use an alternative VPN server than Windows Server RRAS, I was hoping to user our Mikrotik router instead.

The VPN uses IKEv2 with a user certificate issued from Active Directory Certificate Services, this is presented to the RADIUS server via PEAP authentication.

Does the Mikrotik suppoert IKEv2 with radius PEAP authentication?

You can read more about how to set this up using only the windows components here:

https://4sysops.com/archives/always-on- ... indows-10/

Apparently this is the new MS "standard" for corportate VPN, so would be sure good to get this working on the Mikrotik.

If anyone has any thoughts or ideas I would sure be grateful to hear them!

Thanks

Daniel

Re: IKEv2 PEAP - MS Always on VPN

Posted: Wed Feb 06, 2019 4:58 pm
by cameorol
Hi, did you ever get this set up?
I am looking at this now and would love to be able to get it working with our Mikrotik router

Re: IKEv2 PEAP - MS Always on VPN

Posted: Fri Jul 12, 2019 4:50 pm
by ivn
Guys, any news regarding this topic?

Re: IKEv2 PEAP - MS Always on VPN

Posted: Wed Aug 21, 2019 1:05 am
by Widmo
Bump :)

Re: IKEv2 PEAP - MS Always on VPN

Posted: Mon Jan 06, 2020 6:10 pm
by ivn
I can tell that Always On VPN works fine with Mikrotik's ikev2 eap radius.
I used this guide to configure Windows Servers https://4sysops.com/archives/always-on- ... indows-10/
Except RRAS part.
Also I use trusted certificated from Comodo for Mikrotik's ikev2 instead of AD CS.
You just need to configure ikev2 server on Mikrotik and use Windows NPS as Radius server for Mikrotik.

Just one drawback for me that Mikrotik does not support SSTP certificate authentication. We could use it with AOVPN too, because AOVPN supports sstp fallback in case of ikev2 cannot connect.

Re: IKEv2 PEAP - MS Always on VPN

Posted: Tue Jan 07, 2020 12:18 pm
by rootwilliamson
I have been using Mikrotik router since 2019 and always connect vpn on my pc with ikev2. I have never seen any issue regarding connectivity or else and I use this ikev2 guide [REDACTED]