Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello all, I'm trying to set up my ISR4321 running IOS XE 17.03.05 as a FlexVPN-server for Remote Access (RA) with various clients (Windows 10, Apple's iOS, Android, no AnyConnect), based on ikev2, without using client-side certificates. My current p...
Alright. So, if I understand correctly, "query-identity" is to be set, which queries the identity of the client. However, Windows replies with its IP-address and this is not a valid identity, so the authentication fails. When "query-identity" is not ...
I'm trying to make this config work on my ISR4321 running IOS XE 17.03.05. Should be relatively new in terms of supported features, hence my wish to move to a IKEv2 VPN-server-config.Plan B would be to move to ASA but I was hoping to make it work on ...
Thank you. A bit less vague now.Following your advice, I started from scratch. Imported the p12-certificate which I created using the tutorial I linked earlier, and applied various bits and pieces to my config: aaa new-model
!
!
aaa authentication lo...
Yes, things got messy with trying out various configurations. Indeed it would be good to start from scratch.I have to say that I'm still somewhat vague on the certificate-side of things. As MHM replied, I only need a certificate on the router-side. H...