Community discussions

MikroTik App
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Routerboard and MS EAP-MSCHAP v2

Wed Dec 09, 2015 7:48 pm

Can routerboard authenticate pptp client with eap-mschap v2? I need to use it with Windows 2012 R2 and client need to be authenticated with his windows credentials. It works with mschap v2 (windows login and password is typed manually bu user) but if I create connection with eap-mschap v2 I've got 628 error while connecting.
I'll be grateful for any response.
 
Zorro
Long time Member
Long time Member
Posts: 675
Joined: Wed Apr 16, 2014 2:43 pm

Re: Routerboard and MS EAP-MSCHAP v2

Thu Dec 10, 2015 6:48 am

EAP/PEAP-xx-CHAP x ? do you deployed RADIUS/DIAMETER server for that ?
no need to use windows or windows server solely for that. you can use number of network appliances(containers)for, including free ones.
if so- dump config of it here.
628 generally is auth issue, AFAIK.
you can temporally use plaintext auth as advised by MS to troubleshoot/locate root of problems
https://social.technet.microsoft.com/fo ... -error-628
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Re: Routerboard and MS EAP-MSCHAP v2

Thu Dec 10, 2015 9:12 am

Radius on routerboard, vpn authentication by radius. Windows 2012 R2 domain, acting as radius client.
I need Windows to authenticate by domain credentials.
Connection is created by CMAK so it's not possible to change parameters after installing. I've created 2 versions of connection: one with MS-CHAP2 (user enters credentials manually) and second with EAP-MSCHAP2 (actually logged user's credentials are used for authentication).
First one works excellent (but if user will change Windows password, he has to change vpn password too) and second shows error 628.
If I'll have no choice, I'll use version one in my network. But I'm still going to get my network environment user(idiot) friendly :)
 
Zorro
Long time Member
Long time Member
Posts: 675
Joined: Wed Apr 16, 2014 2:43 pm

Re: Routerboard and MS EAP-MSCHAP v2

Thu Dec 10, 2015 4:19 pm

tweak MS-CHAPv2 defaults(there was Several options in windows. some Newer options - simply not supported by ROS, yet, sadly), just avoid plaintext/opened/PAP challenge/"auth" ;)

Who is online

Users browsing this forum: Google [Bot] and 22 guests