cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
594
Views
0
Helpful
7
Replies

IOS authentication methods

wrwiii122
Level 1
Level 1

I am using Microsoft IAS for my 2950's and 3550's. So far I can only get it to work using PAP. The options available are CHAP, MS-CHAP, MS-CHAP2, PEAP, and MD5. Are any of these supported by cisco because PAP is not secure.

7 Replies 7

Collin Clark
VIP Alumni
VIP Alumni

Huh? Sounds like you're using radius which has little to do with the other protocols mentioned. Elaborate on your setup/issue.

Check out the link below. I am using Microsoft Internet Authentication Servicec (IAS) to connect to a 3550 through telenet. I need to do this so that users can be authenticated through active directory. If you look half way down the document those are the protocols offered and only PAP seems to work. I am wondering why on an unencrypted protocol is used and if it is the same on a firewall too.

http://www.xs4all.nl/~hermanb/cisco-ias.htm

Ahhh OK. I remember that it has to be unencrypted, but don't remember why off the top of my head. I'll see if I can dig up the info.

Hi,

Telnet authentication only supports PAP.

As far as encryption is concerned since you are using Radius the user password is encrypted between the device and IAS in the Radius packet. So we need not worry as long as the secret key is not known to anybody.

Regards,

Vivek

How about using ssh? Also can I use https instead of http?

My whole purpose in this is to have username and passwords system wide to audit who is logging on, when they are logging on, and what they are doing on our cisco equipment and do it securely.

Yes you can.

You can use SSH and RADIUS? Can you give an example.