Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PEAP MS CHAPv2

Hi,

we have the following implementation:

Cisco Access Points mainly 1200 series, Cisco ACS v.3.3, and MS Active Directory.

I've

2 REPLIES
Silver

Re: PEAP MS CHAPv2

Clients joining ssid wlpaltenpeap will authenticate to 170.64.216.164 primarily and fail over option is 170.64.216.166 in case if primary doesnt respond. aaa group server radius rad_eap statement implies the list of servers under the group rad_eap.aaa authentication login eap_methods group rad_eap statement implies that SSID configured with eap_methods authenticate against the server listed under rad_eap as a part of login process. Regarding the question of certificates Client side certificates are not needed. But the server's certifcates( Self generated certificates) should be present in the Trusted Root CA list of client.

New Member

Re: PEAP MS CHAPv2

What do you mean by "Trusted Root CA list of client."

?

129
Views
4
Helpful
2
Replies