Getting started
The SNS 5.1 version includes support for IKEv2 tunnels with certificate-based authentication based on the EAP-TLS protocol used in particular by the native Microsoft Windows VPN client.
Requirements
- The user accounts used for the IPsec VPN must be stored in an LDAP directory defined on the SNS firewall (internal directory in this document). The process of creating an LDAP directory (internal or external) is described in the Directories configuration section in the SNS User Guide.
- An email address must be defined for each user present in the directory in order to identify them when establishing an IPsec tunnel. Indeed, this email address will be compared to the one in the certificate presented by the user.
Limitations
The EAP-TLS authentication method:
- Can only be used in mobile policies,
- Not compatible with Restricted Broadcast (DR) mode.
Definitions and terminology
EAP-TLS (Extensible Authentication Protocol – TLS): TLS-based authentication protocol defined by RFC5216. It allows peers to authenticate each other by certificate. This method is called “Smartcard or other certificate (EAP-TLS)” in Microsoft Windows.
| Date | Description |
|---|---|
| July 30, 2026 | New document |