01-25-2016 01:19 AM
Hello,
I need help with configuring IKEv2 remote VPN on Cisco ASA 5505 (ASA version 9.2.4). Is it possible on this version to connect from native Microsoft Windows client (and any other standard-based IKEv2) or only from Cisco Anyconnect client?
Thank you.
01-25-2016 03:15 AM
Never tried it with anything else than AnyConnect, but at least the release notes state that the compatibility with third party clients started with 9.3(2) which is not available for the legacy ASAs:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa93/release/notes/asarn93.html#53205
01-25-2016 08:15 AM
It is supported for the ASA version => 9.3.2,But you have to keep the following in mind:
Neither the IKEv2 VPN client in Windows 7 nor on Windows 8 support pre-shared-keys for authentication purposes.
The clients supports authentication using machine store certificate(not user cert store) or the EAP with methods that use either EAP-MSCHAPv2 or with the certificate it uses user store certificates EAP-TLS.
one of the examples for the same (EAP-MSCHAPv2) this example shows ISE being used as the RADIUS though i have tested it working with Free-Radius as well:
http://www.cisco.com/c/en/us/support/docs/security-vpn/webvpn-ssl-vpn/119208-config-asa-00.html
I hope it will help
Regards
Jagmeet
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide