cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
440
Views
0
Helpful
2
Replies

PEAP MSCHAP V2 - Machine authentication not working

colmgrier
Level 1
Level 1

I have successfully got users to connect to the WLAN using PEAP-mschapv2 (no CA certificate on laptop) but I cannot get machine authentication to work.

At the moment I can get all users with diallin tab ticked to connect to the WLAN from a domain member laptop and a non member laptop. I would like to implement machine authentication so that only domain laptops will allow users to connect to the WLAN using PEAP-mschapv2.

Objective:

Allow domain user (dialin tab ticked) connected to the Wlan using a domain laptop or pc.

Please advise.

2 Replies 2

amritpatek
Level 6
Level 6

For the configuration setting for for PEAP (EAP-MSCHAP v2) Authentication follow the configuration guide http://www.cisco.com/en/US/docs/wireless/technology/peap/technical/reference/PEAP_D.html#wp1008130

For all laptop and tablet clients to authenticate using the machine credential, you need to input the below registration keys on Client/Supplicant,

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EAPOL\Parameters\General\Global]

• SupplicantMode =dword:00000003

• AuthMode =dword:00000002

Krishan

Convergis

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card