01-17-2007 10:00 AM - edited 03-10-2019 02:55 PM
I am using Microsoft IAS for my 2950's and 3550's. So far I can only get it to work using PAP. The options available are CHAP, MS-CHAP, MS-CHAP2, PEAP, and MD5. Are any of these supported by cisco because PAP is not secure.
01-17-2007 12:56 PM
Huh? Sounds like you're using radius which has little to do with the other protocols mentioned. Elaborate on your setup/issue.
01-17-2007 01:15 PM
Check out the link below. I am using Microsoft Internet Authentication Servicec (IAS) to connect to a 3550 through telenet. I need to do this so that users can be authenticated through active directory. If you look half way down the document those are the protocols offered and only PAP seems to work. I am wondering why on an unencrypted protocol is used and if it is the same on a firewall too.
01-17-2007 02:24 PM
Ahhh OK. I remember that it has to be unencrypted, but don't remember why off the top of my head. I'll see if I can dig up the info.
01-18-2007 03:55 AM
Hi,
Telnet authentication only supports PAP.
As far as encryption is concerned since you are using Radius the user password is encrypted between the device and IAS in the Radius packet. So we need not worry as long as the secret key is not known to anybody.
Regards,
Vivek
01-19-2007 09:08 AM
How about using ssh? Also can I use https instead of http?
My whole purpose in this is to have username and passwords system wide to audit who is logging on, when they are logging on, and what they are doing on our cisco equipment and do it securely.
01-19-2007 01:03 PM
Yes you can.
01-19-2007 02:04 PM
You can use SSH and RADIUS? Can you give an example.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide