Skip to content

IPsec: Setup Ixolate for IKEv2 EAP-TLS

EAP-TLS via IKEv2 is based on client certificate authentication. Be sure to install the client certificate on your enduser device.

Updated View as Markdown

EAP-TLS via IKEv2 is based on client certificate authentication. Be sure to install the client certificate on your enduser device.

Step 1 - Create Certificates

For EAP-TLS with IKEv2 you need to create a Root CA and a server certificate for your Firewall.

For more information read Setup Self-Signed Certificate Chains

Step 2 - Mobile Clients

First we will need to setup the mobile clients network and authentication source. Go to VPN › IPsec › Mobile Clients

For our example we will use the following settings:

IKE Extensions

Enable checked check to enable mobile clients
User Authentication Local Database For the example we use the Local Database
Group Authentication none Leave on none
Virtual Address Pool 10.10.0.0/24 Enter the IP range for the remote clients

You can select other options, but we will leave them all unchecked for this example.

Save your settings and select Create Phase1 when it appears. Then enter the Mobile Client Phase 1 setting.

Step 3 - Phase 1 Mobile Clients

Phase 1 General information

Connection method default default is ‘Start on traffic’
Key Exchange version V2 only V2 is supported for EAP-TLS
Internet Protocol IPv4
Interface WAN choose the interface connected to the internet
Description MobileIPsec freely chosen description

Phase 1 proposal (Authentication)

Authentication method EAP-TLS This is the method we want here
My identifier Distinguished Name Set the FQDN you used within certificate
My Certificate Certificate Choose the certificate from dropdown list

Phase 1 proposal (Algorithms)

Encryption algorithm AES For our example we will use AES/256 bits
Hash algorithm SHA1, SHA256 SHA1 and SHA256 for compatibility
DH key group 1024, 2048 bit 1024 and 2048 bit for compatibility
Lifetime 28800 sec lifetime before renegotiation

Advanced Options are fine by default.

Save your settings.

Step 3 - Phase 2 Mobile Clients

Press the button + in front of the phase 1 entry to add a new phase 2.

General information

Mode Tunnel IPv4 Select Tunnel mode
Description MobileIPsecP2 Freely chosen description

Local Network

Local Network LAN subnet Route the local LAN subnet

Phase 2 proposal (SA/Key Exchange)

Protocol ESP Choose ESP for encryption
Encryption algorithms AES / 256 For this example we use AES 256
Hash algorithms SHA1, SHA256 Same as before, mix SHA1 and SHA256
PFS Key group off Most mobile systems do not support PFS in Phase2
Lifetime 3600 sec

Save your settings and Enable IPsec, Select:

Step 4 - Add IPsec Users

Go to System › Trust › Certificates and create a new client certificate. Just click Add, choose your CA and probably increase the lifetime. Everything else besides the CN can be left default. Give a Common Name and Save. Download the newly created certificate as PKCS12 and export it to your end user device.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close