cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
604
Views
0
Helpful
2
Replies

PEAP MSCHAP V2 - Machine authentication not working

colmgrier
Level 1
Level 1

I have successfully got users to connect to the WLAN using PEAP-mschapv2 (no CA certificate on laptop) but I cannot get machine authentication to work.

At the moment I can get all users with diallin tab ticked to connect to the WLAN from a domain member laptop and a non member laptop. I would like to implement machine authentication so that only domain laptops will allow users to connect to the WLAN using PEAP-mschapv2.

Objective:

Allow domain user (dialin tab ticked) connected to the Wlan using a domain laptop or pc.

Please advise.

2 Replies 2

amritpatek
Level 6
Level 6

For the configuration setting for for PEAP (EAP-MSCHAP v2) Authentication follow the configuration guide http://www.cisco.com/en/US/docs/wireless/technology/peap/technical/reference/PEAP_D.html#wp1008130

For all laptop and tablet clients to authenticate using the machine credential, you need to input the below registration keys on Client/Supplicant,

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EAPOL\Parameters\General\Global]

• SupplicantMode =dword:00000003

• AuthMode =dword:00000002

Krishan

Convergis

Review Cisco Networking for a $25 gift card