<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP /MSCHAP V2 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608833#M191063</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott, i am with you i installed a Cert on our ACS and that bit is fine, what i dont get is does the windows supplicant need a cert installed on the client machine ??cuz the tick for validate certificate is of no use, as the clients can connect with or without it &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Jan 2007 23:04:48 GMT</pubDate>
    <dc:creator>satish_chowdhary</dc:creator>
    <dc:date>2007-01-15T23:04:48Z</dc:date>
    <item>
      <title>PEAP /MSCHAP V2</title>
      <link>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608830#M191060</link>
      <description>&lt;P&gt;Hi All, i have  PEAP with MSCHAPV2 setup, my windows supplicant can authenticate to ACS with our without the Validate certificate tick enabled. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read that certificates are optional with PEAP and mandatory in EAP-TLS &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can some pl confirm the above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in adv&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 20:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608830#M191060</guid>
      <dc:creator>satish_chowdhary</dc:creator>
      <dc:date>2021-07-03T20:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP /MSCHAP V2</title>
      <link>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608831#M191061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a good doc that confirms this (Look at Chart#1);&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS server certificate required: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco LEAP - No&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Cisco EAP-FAST- No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft PEAP/MS-CHAPv2- Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PEAP (EAP-GTC)- Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft EAP-TLS- Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client certificate required:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco LEAP - No&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Cisco EAP-FAST- No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft PEAP/MS-CHAPv2- No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PEAP (EAP-GTC)- No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft EAP-TLS- Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From this good doc;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/wireless/ps430/prod_configuration_guide09186a008046dc81.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/wireless/ps430/prod_configuration_guide09186a008046dc81.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to rate helpful posts.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jan 2007 14:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608831#M191061</guid>
      <dc:creator>Rob Huffman</dc:creator>
      <dc:date>2007-01-11T14:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP /MSCHAP V2</title>
      <link>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608832#M191062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not entirely correct.  PEAP does require a certificate, but on the server side only.  The clients do not require a cert.  In EAP-TLS, however, the client does need to verify the server cert.  You can GOOGLE your question or try Microsoft's TechNet.  There is a good article on setting up PEAP from scratch with Win2k3 server, look on TechNet for it.  Also, look at the chart found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.oreillynet.com/pub/a/wireless/2002/10/17/peap.html" target="_blank"&gt;http://www.oreillynet.com/pub/a/wireless/2002/10/17/peap.html&lt;/A&gt; - &lt;/P&gt;&lt;P&gt;you will come across the part where you create a server-side cert.  You will then be taken through the client config that shows validation of the cert is not required.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 19:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608832#M191062</guid>
      <dc:creator>Scott Pickles</dc:creator>
      <dc:date>2007-01-15T19:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP /MSCHAP V2</title>
      <link>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608833#M191063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott, i am with you i installed a Cert on our ACS and that bit is fine, what i dont get is does the windows supplicant need a cert installed on the client machine ??cuz the tick for validate certificate is of no use, as the clients can connect with or without it &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 23:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608833#M191063</guid>
      <dc:creator>satish_chowdhary</dc:creator>
      <dc:date>2007-01-15T23:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP /MSCHAP V2</title>
      <link>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608834#M191064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Satish -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct in that the certificate is not needed on the client.  Just uncheck the "Validate Server..." part.  As for it still not working without validating server, have you checked your RADIUS/IAS logs?  Are you seeing any logged attempts?  In addition, is your AP set up as a RADIUS client under IAS with correct shared secret?  You also need to configure your SSID with the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Open with EAP&lt;/P&gt;&lt;P&gt;Network with No Addition&lt;/P&gt;&lt;P&gt;Encryption Mandatory WPA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, under the encryption manager, for Cipher select TKIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be sure and also define a default EAP server, which is your RADIUS/IAS server.  Make certain your shared secret keys are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can obtain the following document which walks you through a lot of this stuff on a Win2K3 Server at the following address:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0f7fa9a2-e113-415b-b2a9-b6a3d64c48f5&amp;amp;DisplayLang=en" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=0f7fa9a2-e113-415b-b2a9-b6a3d64c48f5&amp;amp;DisplayLang=en&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 19:02:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-mschap-v2/m-p/608834#M191064</guid>
      <dc:creator>Scott Pickles</dc:creator>
      <dc:date>2007-01-19T19:02:46Z</dc:date>
    </item>
  </channel>
</rss>

