|
From: James C. <jam...@hp...> - 2005-05-10 03:46:06
|
On Mon, May 09, 2005 at 11:13:09PM +0100, Tim Sawyer wrote: > I've made more progress but now it's failing CHAP authentication. Yes, the log shows the following sequence; - server proposes EAP authentication, - client counter-proposes CHAP MD5 authentication, - server accepts CHAP MD5 authentication, - server initiates CHAP MD5 authentication. CHAP MD5 is not the right authentication type to use; the only working authentication type we've seen is MSCHAP V2. Add "refuse-chap" to your options and try again. It is MSCHAP-V2 that you need, but as a client you cannot require it, you can only refuse everything else. Do not try require-mschap-v2, because this will ask the server to authenticate to the client; and most servers don't do that. -- James Cameron http://quozl.netrek.org/ HP Open Source, Volunteer http://opensource.hp.com/ PPTP Client Project, Release Engineer http://pptpclient.sourceforge.net/ |