cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
347
Views
4
Helpful
2
Replies

PEAP MS CHAPv2

jorge.s
Level 1
Level 1

Hi,

we have the following implementation:

Cisco Access Points mainly 1200 series, Cisco ACS v.3.3, and MS Active Directory.

I've

2 Replies 2

irisrios
Level 6
Level 6

Clients joining ssid wlpaltenpeap will authenticate to 170.64.216.164 primarily and fail over option is 170.64.216.166 in case if primary doesnt respond. aaa group server radius rad_eap statement implies the list of servers under the group rad_eap.aaa authentication login eap_methods group rad_eap statement implies that SSID configured with eap_methods authenticate against the server listed under rad_eap as a part of login process. Regarding the question of certificates Client side certificates are not needed. But the server's certifcates( Self generated certificates) should be present in the Trusted Root CA list of client.

What do you mean by "Trusted Root CA list of client."

?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card