added ikev2/rw-radius-accounting scenario

This commit is contained in:
Andreas Steffen
2012-02-06 12:52:48 +01:00
parent 32dc2b0243
commit 9755910d7f
18 changed files with 406 additions and 0 deletions
@@ -0,0 +1,14 @@
The roadwarrior <b>carol</b> sets up a connection to gateway <b>moon</b>.
At the outset the gateway authenticates itself to the client by sending
an IKEv2 <b>RSA signature</b> accompanied by a certificate.
<b>carol</b> then uses the <i>Extensible Authentication Protocol</i>
in association with an <i>MD5</i> challenge and response protocol
(<b>EAP-MD5</b>) to authenticate against the gateway <b>moon</b>.
In addition to her IKEv2 identity <b>[email protected]</b>, roadwarrior
<b>carol</b> uses the EAP identity <b>carol</b>.
The user password is kept in <b>ipsec.secrets</b> on the client <b>carol</b>
and the gateway forwards all EAP messages to the RADIUS server <b>alice</b>.
<p/>
Since RADIUS accounting is enabled in <b>strongswan.conf</b>, gateway <b>moon</b>
sends user name, connection time and data volume information to the
RADIUS server <b>alice</b>.