ADEO Imaging OÜ
The cloud spirit...

VPN Access (IKEv2 with EAP MSCHAPv2 authorization)

Overview.


  • Compatible with Windows, Android, and iOS
  • Authentication via certificate and login/password
  • Very high speed
  • Unlimited traffic
  • Supports simultaneous connections on multiple devices
  • only 9.99 USD per month
  • (subscription can be cancelled at any time)

    VPN location:

    After subscribing, you will be able to download the certificates and receive your login and password.

    WINDOWS-CLIENT SETUP

    To set up the VPN client on Windows, you need to perform two main steps:
       1. Install client certificates on Windows.
       2. Create and configure an IKEv2 VPN connection with Extended Authentication Protocol (EAP) EAP-MSCHAP v2.

    1. Installing certificates on Windows computers.

    Unpack the previously downloaded ZIP archive into a separate folder. Certificates should be installed in the "Local Computer" store. To do this, simply run the file "install-cert-win.bat" (administrator account required). As a result, the client certificate "vpnclient@ec2-...amazonaws.com" will be installed to "Local Computer"->"Personal"->"Certificates" store, and the certificate "ADEO VPN root CA" will be installed to "Local Computer"->"Trusted Root Certification Authorities" store, as shown in the picture "cert-console.jpg". You can check this using the MMC console (double-click the file "cert-console.msc").

    2. Creating and configuring the IKEv2 VPN connection with Extended Authentication Protocol (EAP) EAP-MSCHAP v2.

    The VPN connection must be created using standard Windows tools. The VPN connection should include:
  • Server address: public IP address of the instance on AWS
  • VPN Type: IKEv2
  • Extended Authentication Protocol (EAP): EAP-MSCHAP v2
  • Credentials (username and password): see users on the Web Panel.

  • ANDROID-CLIENT SETUP

    To set up the VPN client on Android, you need to perform two main steps:
       1. Install client certificates on your Android device.
       2. Install and configure the "strongSwan VPN Client" application from Google Play.

    1. Installing certificates on Android device.

    Upload the file "client-cert.p12" to your Android device and tap on it. Install the certificates using the password "vpn".

    2. Installing and configuring the "strongSwan VPN Client" application.

    Download and install the "strongSwan VPN Client" application from Google Play. Then, create a new profile.

    The profile for the "strongSwan VPN Client" should include:
  • Server address: public IP address of the instance on AWS
  • VPN Type: IKEv2 Certificate + EAP (login and password)
  • User Certificate: select a certificate that you installed
  • CA Certificate: select automatically

  • If you decide to use the standard Android VPN client instead of the "strongSwan VPN Client", then the settings should include:
  • Server address: public IP address of the instance on AWS
  • Type: IKEv2/IPSec MSCHAPv2
  • Certificate: select a certificate that you installed