blow is the configuration from cisco guide:aaa group server radius eap-serverserver 192.168.2.1!aaa authentication login eap-list group eap-server!crypto pki trustpoint trustpoint1enrollment url http://192.168.3.1:80revocation-check crl!crypto ikev2 ...