strongSwan KVM Tests / ikev2 / rw-radius-accounting

Test ikev2/rw-radius-accounting

Description

The roadwarrior carol sets up a connection to gateway moon. At the outset the gateway authenticates itself to the client by sending an IKEv2 RSA signature accompanied by a certificate. carol then uses the Extensible Authentication Protocol in association with an MD5 challenge and response protocol (EAP-MD5) to authenticate against the gateway moon. In addition to her IKEv2 identity carol@strongswan.org, roadwarrior carol uses the EAP identity carol.

Since RADIUS accounting is enabled in strongswan.conf, gateway moon sends user name, connection time and data volume information to the RADIUS server alice.

alice carol moon

moon

 

carol

 

alice

tcpdump