StrongSwan - windows double password prompt Announcing the arrival of Valued Associate #679:...

Was the pager message from Nick Fury to Captain Marvel unnecessary?

How to ask rejected full-time candidates to apply to teach individual courses?

Why did Bronn offer to be Tyrion Lannister's champion in trial by combat?

What does 丫 mean? 丫是什么意思?

Why not use the yoke to control yaw, as well as pitch and roll?

Plotting a Maclaurin series

How to infer difference of population proportion between two groups when proportion is small?

First paper to introduce the "principal-agent problem"

malloc in main() or malloc in another function: allocating memory for a struct and its members

Did John Wesley plagiarize Matthew Henry...?

How to name indistinguishable henchmen in a screenplay?

Diophantine equation 3^a+1=3^b+5^c

Improvising over quartal voicings

How can I prevent/balance waiting and turtling as a response to cooldown mechanics

What is the proper term for etching or digging of wall to hide conduit of cables

Does the Rock Gnome trait Artificer's Lore apply when you aren't proficient in History?

Does the main washing effect of soap come from foam?

Is the time—manner—place ordering of adverbials an oversimplification?

Short story about astronauts fertilizing soil with their own bodies

How to achieve cat-like agility?

How do I find my Spellcasting Ability for my D&D character?

Why do C and C++ allow the expression (int) + 4*5?

Does the universe have a fixed centre of mass?

Pointing to problems without suggesting solutions



StrongSwan - windows double password prompt



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Strongswan clients access rightsstrongswan: entirely virtual subnetEAP password prompt in strongSwanWindows 7/8 Strongswan IKEv2 Wrong GatewayTrying to replicate a working IPSec/L2TP config from OpenSWAN to StrongSWANAccounting IPSec connections with RSA authenticationStrongswan VPN: no matching peer config foundStrongswan ubuntu client setup?Strongswan clients access rightsStrongswan: Connecting PSK & EAP at a timeStrongswan + FreeRADIUS and Windows 10 clients without internet access





.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ height:90px;width:728px;box-sizing:border-box;
}







0















I had a requirement to use unique virtual IP pool per peer config (identity). The clients would connect using Windows default VPN client and each client when connected should get the virtual IP address from a different pool. Multiple clients can use the same credentials, so they will get virtual IP address from the pool configured with the peer config. But clients using different credentials will get IP from different virtual pools.



For windows, matching peer config (connection) based on identity doesn't work, so I followed the approach given at the below link (refer answer)



Strongswan clients access rights



Though the solution works fine, but the challenge is that using rightgroups configuration results in an extra password prompt on Windows (using default VPN client). I think it happens because of the dummy connection switch that happens due to the rightgrougs with identity=%any (eap-init).



Is there a way to solve the dual password prompt issue?









share







New contributor




kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.



























    0















    I had a requirement to use unique virtual IP pool per peer config (identity). The clients would connect using Windows default VPN client and each client when connected should get the virtual IP address from a different pool. Multiple clients can use the same credentials, so they will get virtual IP address from the pool configured with the peer config. But clients using different credentials will get IP from different virtual pools.



    For windows, matching peer config (connection) based on identity doesn't work, so I followed the approach given at the below link (refer answer)



    Strongswan clients access rights



    Though the solution works fine, but the challenge is that using rightgroups configuration results in an extra password prompt on Windows (using default VPN client). I think it happens because of the dummy connection switch that happens due to the rightgrougs with identity=%any (eap-init).



    Is there a way to solve the dual password prompt issue?









    share







    New contributor




    kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
    Check out our Code of Conduct.























      0












      0








      0








      I had a requirement to use unique virtual IP pool per peer config (identity). The clients would connect using Windows default VPN client and each client when connected should get the virtual IP address from a different pool. Multiple clients can use the same credentials, so they will get virtual IP address from the pool configured with the peer config. But clients using different credentials will get IP from different virtual pools.



      For windows, matching peer config (connection) based on identity doesn't work, so I followed the approach given at the below link (refer answer)



      Strongswan clients access rights



      Though the solution works fine, but the challenge is that using rightgroups configuration results in an extra password prompt on Windows (using default VPN client). I think it happens because of the dummy connection switch that happens due to the rightgrougs with identity=%any (eap-init).



      Is there a way to solve the dual password prompt issue?









      share







      New contributor




      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.












      I had a requirement to use unique virtual IP pool per peer config (identity). The clients would connect using Windows default VPN client and each client when connected should get the virtual IP address from a different pool. Multiple clients can use the same credentials, so they will get virtual IP address from the pool configured with the peer config. But clients using different credentials will get IP from different virtual pools.



      For windows, matching peer config (connection) based on identity doesn't work, so I followed the approach given at the below link (refer answer)



      Strongswan clients access rights



      Though the solution works fine, but the challenge is that using rightgroups configuration results in an extra password prompt on Windows (using default VPN client). I think it happens because of the dummy connection switch that happens due to the rightgrougs with identity=%any (eap-init).



      Is there a way to solve the dual password prompt issue?







      strongswan





      share







      New contributor




      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.










      share







      New contributor




      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.








      share



      share






      New contributor




      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      asked 3 mins ago









      kapskaps

      11




      11




      New contributor




      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.





      New contributor





      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






      kaps is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






















          0






          active

          oldest

          votes












          Your Answer








          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "2"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });






          kaps is a new contributor. Be nice, and check out our Code of Conduct.










          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f964012%2fstrongswan-windows-double-password-prompt%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes








          kaps is a new contributor. Be nice, and check out our Code of Conduct.










          draft saved

          draft discarded


















          kaps is a new contributor. Be nice, and check out our Code of Conduct.













          kaps is a new contributor. Be nice, and check out our Code of Conduct.












          kaps is a new contributor. Be nice, and check out our Code of Conduct.
















          Thanks for contributing an answer to Server Fault!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f964012%2fstrongswan-windows-double-password-prompt%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          As a Security Precaution, the user account has been locked The Next CEO of Stack OverflowMS...

          Список ссавців Італії Природоохоронні статуси | Список |...

          Українські прізвища Зміст Історичні відомості |...