09-08-2018 10:43 PM - edited 02-21-2020 08:12 AM
I have an ASA5506 configured as an IKEv2 remote access VPN using certificate authentication, and am trying to work around the horrendously broken IKEv2 client on an iPhone 8. At the moment, it only supports using certificates with EAP-TLS; plain cert auth is broken, and has been for quite some time (Apple seems not to care). So, in order to use the IKEv2 client on the iPhone, your VPN server must support EAP-TLS. I have set up many Linux-based Strongswan servers that support this no problem, but I am having trouble finding out how to do this on an ASA. I am using CLI to configure, not Defense Center.
Is this supported? I hope so, as I would really not like to have to set up an entire EAP/RADIUS server just to handle this one stupid device.
Solved! Go to Solution.
09-10-2018 01:24 AM
09-09-2018 06:30 AM
09-09-2018 11:00 PM - edited 09-09-2018 11:00 PM
Can FirePOWER Defense Center provide these services? Or can they be provided via an external RADIUS server (Windows NPS, etc?
I do not have an ISE, and don't particularly want to invest that much in one.
09-10-2018 01:24 AM
09-10-2018 09:20 PM
Thank you!
09-10-2018 11:21 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide