Community discussions

MikroTik App
alphalt
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 94
加入: Sat Aug 01, 2009 1:53 pm
Location:Denmark

SSTP VPN with Win7 'verify client certificate'

Mon Apr 02, 2012 9:29 am

Hi,

I've tried to search for solution, but didn't find that much. I have Mikrotik as SSTP server and Windows 7 computer as client. It's impossible to make SSTP VPN tunnel with Windows 7 machine if option 'verify client certificate' is turned on on Mikrotik's server. So is there any solution for this ? I use custom generated certificates. If I connect two Mikrotiks (one server, other client) then everything work just fine even with option 'verify client certificate' enabled.
Top
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 6964
加入: Wed Feb 07, 2007 12:45 pm
Location:Latvia
Contact:

Re: SSTP VPN with Win7 'verify client certificate'

Mon Apr 02, 2012 3:24 pm

That is correct, "verify-client-certificate" is Mikrotik feature. If you are connecting Windows machines then disable it.
Top
alphalt
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 94
加入: Sat Aug 01, 2009 1:53 pm
Location:Denmark

Re: SSTP VPN with Win7 'verify client certificate'

Mon Apr 02, 2012 3:30 pm

Ok, thanks for the info.
Top
Fraction
Frequent Visitor
Frequent Visitor
Posts: 84
加入: Wed Jan 16, 2013 9:42 pm
Location:芬兰赫尔辛基

Re: SSTP VPN with Win7 'verify client certificate'

Tue Feb 19, 2013 11:46 pm

Is there any plans/possibilities to implement that feature usable with Windows-clients also?
Would make huge improvement to sstp's security and that way make it much better alternative to OpenVPN (which you don't want to development anymore).
Top
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 6964
加入: Wed Feb 07, 2007 12:45 pm
Location:Latvia
Contact:

Re: SSTP VPN with Win7 'verify client certificate'

Wed Feb 20, 2013 10:16 am

Wrong place to ask.. Contact Microsoft and ask them if such feature will be implemented.
Top
Fraction
Frequent Visitor
Frequent Visitor
Posts: 84
加入: Wed Jan 16, 2013 9:42 pm
Location:芬兰赫尔辛基

Re: SSTP VPN with Win7 'verify client certificate'

Wed Feb 20, 2013 10:47 am

Wrong place to ask.. Contact Microsoft and ask them if such feature will be implemented.

That was that "is there any possibilities" -section of my question.:)

Anyway, EAP authentication with certificates is supported by Microsoft SSTP-solution.
Top
Fraction
Frequent Visitor
Frequent Visitor
Posts: 84
加入: Wed Jan 16, 2013 9:42 pm
Location:芬兰赫尔辛基

Re: SSTP VPN with Win7 'verify client certificate'

Wed May 29, 2013 10:36 pm

Any new ideas concerning this?

I'm still saying that Microsoft is not the problem and Windows SSTP-client is already supporting client-side certificates.
sstp1.png
sstp2.png

Have you done any investigations about that?

Also, Wiki says that Windows client supports only RC4 encryption, this is not true either. My Windows7 is working well with "force-aes" enabled in ROS6.
You do not have the required permissions to view the files attached to this post.
Top
coylh
Member Candidate
Member Candidate
Posts: 159
加入: Tue Jul 12, 2011 12:11 am

Re: SSTP VPN with Win7 'verify client certificate'

Thu Aug 06, 2015 1:32 am

Sounds like its a certificate version issue:https://social.technet.microsoft.com/Fo ... networking
Top
kujo
Member Candidate
Member Candidate
Posts: 169
加入: Sat Jun 18, 2016 10:17 am
Location:Ukraine
Contact:

Re: SSTP VPN with Win7 'verify client certificate'

Fri Dec 08, 2017 2:21 pm

Wrong place to ask.. Contact Microsoft and ask them if such feature will be implemented.
Hi! Can you confirm, that verify-client-certificate is a mikrotik only feature And windows EAP is not a way for make SSTP VPN to mikrotik with cetrificate/tokens?
Top
mpreissner
Member
Member
Posts: 357
加入: Tue Mar 11, 2014 11:16 pm
Location:Columbia, MD

Re: SSTP VPN with Win7 'verify client certificate'

Sat Dec 09, 2017 4:02 am

When you're using EAP, you're not authenticating to the RouterOS system, you're authenticating to a Microsoft NPS server. MikroTik doesn't currently support any EAP methods for their VPN implementations. MikroTik only knows how to pass PAP, CHAP, MSCHAPv1, and MSCHAPv2 to RADIUS in their PPP module, but interestingly, they do support EAP methods on wireless. The functionality exists in the code, it's just that the PPP module doesn't appear to have any linkages to the EAP code.
Top
kujo
Member Candidate
Member Candidate
Posts: 169
加入: Sat Jun 18, 2016 10:17 am
Location:Ukraine
Contact:

Re: SSTP VPN with Win7 'verify client certificate'

Sat Dec 09, 2017 1:35 pm

Ok! Than only way to use IPsec and eap radius?


Yours respectfully!
Top
james59
刚刚加入了
Posts: 1
加入: Mon Dec 18, 2017 12:40 pm

I want to be CEH certified

Thu Dec 28, 2017 9:58 am

I want to be CEH certified, but i dont know how to do it ( as i m beginner ).So if somebody could help me out how else can i study and get CEH? Please help me out, i shall b really thankful to you for replying.
Top

Who is online

Users browsing this forum:Ahrefs [Bot],anh7codon,Google [Bot],kraal,sindy,xanioand 66 guests

Baidu
map