cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
640
Views
0
Helpful
4
Replies

HWIC-AP + PEAP + RADIUS

allenelson
Level 1
Level 1

I've configured a 2811 ISR with an HWIC-AP-G-A for LEAP w/ RADIUS authentication. I am searching for documentation for configuring PEAP but am having a hard time finding what I am looking for.

Could anyone point me in the right direction, and tell me if it is possible to accomplish all on the router? I made a root cert through IIS tools and am not quite sure how to go about uploading it and associating it with AAA/RADIUS. Thanks in advance.

4 Replies 4

dancampb
Level 7
Level 7

As long as you are using an external Radius server all you need to do is make sure you have "authentication open eap..." under your SSID config. LEAP only uses the "authentication network-eap..." statement but PEAP and other EAP methods use the open statement.

If you are trying to use the local Radius server you will be limited to LEAP and EAP-FAST.

Yes everything is local but i don't understand why that would limit the use of certificates.

It's a 2811 ISR router with an HWIC-AP module in it for wireless.

What about EAP-TTLS using PKI? Would that be possible on the ISR?

Ok. I was unaware that you could only use LEAP or EAPFAST on a local authenticator.

That being said.. Anyone have suggestions for documentation on EAPFAST? I used the Cisco default configuration which is printed in 2-3 manuals for it on a local authenticator and cannot get it to work. Word for word step by step.. I'm just trying to see what my options are on an ISR with everything built in and don't want to use an external server. Thanks in advance.

bump.

Review Cisco Networking products for a $25 gift card