cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5708
Views
13
Helpful
19
Comments
Surendra BG
Cisco Employee
Cisco Employee

11929421.mp4
Video Player is loading.
Current Time 0:00
Duration 0:00
Loaded: 0%
Stream Type LIVE
Remaining Time 0:00
 
1x
    • Chapters
    • descriptions off, selected
    • captions off, selected
      (view in My Videos)

      PEAP MSCHAP V2 using WLC and ACS configuration example

       

      In this video we are going to configure the WLC for PEAP MSCHAPV2 Username / Password authentication using Cisco ACS and WLC.

       

      Hope this video was helpful and please feel free to drop in a comment and I will be more than happy to assist you!

       

      Regards

      Surendra

      19 Comments
      stefan.angerer
      Level 1
      Level 1

      I'm pretty sure it's even recommended not to install it on a DC !

      But it definitely doesn't need to be there.

      Good luck!

      Sundeep Dsouza
      Level 1
      Level 1

      Thanks a ton Stefan, appreciate your help.

      Regards

      grabonlee
      Level 4
      Level 4

      Stefan

      Auto enrollment is not only for EAP TLS. With PEAP, the clients also receive certificates and you set a group policy for clients to automatically receive a new Cert once the old one is due to expire. Also no matter which server hosts the CA, the PDC or whatever server hosts the container of machine credentials and user credentials must have a copy of the Cert to establish the trust relationship.

      stefan.angerer
      Level 1
      Level 1

      Sorry for maybe being a bit inaccurate.

      PEAP itself comes in many flavors, one of them is PEAP-MSCHAPv2 - using that there is no need for client certificates. But you could also use EAP-TLS as inner authentication in a PEAP tunnel, and then of course you need client certificates as well.

      Again, since this video is about PEAP-MSCHAPv2, there is no need to have a certificate for all your clients; but you should tell your clients about your root and mabye even your intermediate CA so they can trust your RADIUS server's cert.

      regards

      Stefan

      Getting Started

      Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

      French webcast-routing