How to configure Windows IKEv2 VPN client automatically use your Windows logon credentials with a WatchGuard Firebox and RADIUS

When the Windows IKEv2 VPN client uses automatic logon, it sends credentials as DOMAIN\username. The Firebox matches the DOMAIN part with the RADIUS server name. If the names don’t match (for example, lowercase or different spelling), authentication fails. Windows VPN Client Configuration Firebox Configuration

Configure Microsoft NPS to authenticate on‑prem AD users for Firebox IKEv2 mobile VPN

IKEv2 with MS‑CHAPv2 cannot authenticate directly against LDAP, so a RADIUS server is required. The simplest option is Microsoft NPS, which is included with Windows Server. (FreeRADIUS works too, but this guide focuses on NPS.) Install NPS on a Windows Server You can install NPS on any Windows Server, including a Domain Controller. Server ManagerManage…

Guide how to configure a Linux machine to do SSLVPN and IKEv2 mobilevpn to a WatchGuard Firebox device.

SSLVPN (OpenVPN) – Easiest & works on most distros. WatchGuard SSLVPN is just OpenVPN under the hood, so Linux support is excellent. Step 1 — Download the SSLVPN .ovpn file from the Firebox Step 2 — Import the client.ovpn file into NetworkManager All other settings come from the .ovpn file and normally require no changes.…

Close