Short answer: StrongSwan IKEv2 road-warriors (iOS, macOS, Windows) speak EAP-MSCHAPv2. OpenLDAP can only simple-bind (PAP). Those are not the same protocol, so StrongSwan cannot authenticate an LDAP password by itself. FreeRADIUS sits in the middle: it reads the user’s ntPassword from LDAP and finishes MS-CHAP. That is the supported…
