Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Universal Workgroup Bridge mode with PEAP

Hello!

  We have a piece of equipment that is using a Cisco 1602 as a uWGB to connect to client's network. This equipment is used at many different tenants and works great... except under one scenario we have found. When using MS-PEAP, there has been at least one client that configures the RADIUS server to offer back a "Smart Card or other Certificate" in addition to "Secured password (EAP-MSCHAP v2)". Please note, I am referring to the configuration under "Microsoft: Protected EAP (PEAP)". if the FIRST method in this list is "Smart Card or other certificate", then the 1602 can't connect. If I change the order so that "Secured password (EAP-MSCHAP v2)" is first, it work GREAT! Note that the AP is configured to use EAP-MSCHAPv2 (username/password)

So just to be clear, both of these EAP types are of the PEAP family... PEAP-EAP-MSCHAP2 and PEAP-EAP-TLS. We CAN have as many EAP Types as we would like in the screen above this. IE: We can have PEAP, TLS, etc. in ANY order, and it work great. But if we adjust the order WITHIN PEAP, it makes it so the 1602 can't connect. Here is the screen I am referring to:

MSPEAP.png

In this configuration, it will NOT connect. but if I move "Secured password (EAP-MSCHAP v2)" up, it works perfect.

I guess what I am trying to figure out is if there is anyway on the access point side to work past this. I have spent a lot of time on this, and have discovered nothing that helps. We are using 15.2(2)JA2. It would be nice to not have to depend on the client to set this order properly.

Thank you!

Bill Bushong

  • Getting Started with Wireless
Everyone's tags (5)
2 REPLIES

Universal Workgroup Bridge mode with PEAP

Hello William,

What I know is that WGB does not support PEAP and cisco BU had no plans to add a support to it. (my knowledge is 2+ years old).

Let me check if I can find a doc for you.

Regards,

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

Universal Workgroup Bridge mode with PEAP

My info seem very old. Here is a doc that states the PEAP is now supported on WGB with newer IOS versions on the AP:

http://www.cisco.com/en/US/products/ps12723/products_configuration_example09186a0080becd3c.shtml

So, why you try to configure the PEAP client on the end device? try to conigure it on the uWGB and check if that works.

HTH

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"
603
Views
0
Helpful
2
Replies
This widget could not be displayed.