12-28-2007 12:47 PM - edited 03-03-2019 08:04 PM
Hi, I have got a Cisco 877w working in VPN mode on a DSL line I have to my Head Office. I have configured the wireless as well on WPA/TKIP and and I can wirelessly connect to my Head office via wireless.
Now I want to secure things down more if possible. Can PEAP be used by this 877w (or a 1800 series) router to a Windows IAS RADIUS server which is in the head office?
That way I can manage access via Active Directory for these small remote offices. I guess though it's not good for this authentication to travel over the VPN?
I read a few old articles that LEAP can only be done, if PEAP can be done though my next question would be how?
I see that the RADIUS Host would need to be added like:
radius-server host 1.2.3.4 auth-port 1812 key rad1
Although I see IAS authenticates on ports 1812,1645 and accounting on 1813,1646.
Attached is my current config.
01-03-2008 12:21 PM
Only peap can be done as 1800 series will not support peap.for autentcaition you can use leap.
01-03-2008 01:10 PM
Are you saying peap can or cannot be on the 1800 or 877 series? Only leap?
01-05-2008 01:20 PM
Yes, they support a broad variety of 802.1x EAP types, including PEAP.
NS
01-06-2008 11:53 AM
Thanks NS, I'm trying to configure my 877w to authenticate its users via a windows IAS radius server, would you have an example on how I can do this? I understand the windows side and that is ready its just the cli config part?
01-07-2008 08:37 PM
Just look at the IOS config pieces, ignore the web configs.
NS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide