Cloudpath Administrative Console  |     Logout

PEAP Configuration
Return to Main Menu
Name:
Authentication Method
Description:
Controls the method of authentication used within the inner tunnel for PEAP.
Notes:
PEAP establishes an outer tunnel using only the server's certificate. This is analogous to how HTTPS encryption works. Once the outer tunnel is established, information is exchanged to allow an inner tunnel based on the server certificate and a temporary client certificate to be established. Within this inner tunnel, PEAP will perform authentication. Authentication can occur through certificates (TLS) or through a username/password mechanism (MSCHAPv2).
Values:
Secured Password (EAP-MSCHAPv2)
  Authentication occurs inside the inner tunnel using a username and hashed password based on MSCHAPv2.
Smart Card or Other Certificate
  Authentication occurs inside the inner tunnel using client & server certificates, similar to the EAP type TLS.
SecureW2
  Authentication occurs inside the inner tunnel using a username and password mechanism. This option is only available if SecureW2 is installed.
Default Value:
Smart Card or Other Certificate
Recommended Setting:
Secured Password (EAP-MSCHAPv2) is the most common and is the main reason for choosing the EAP type PEAP.
Cloudpath Help :
Cloudpath can detect the status of the authentication method within the PEAP configuration.

Supported settings include:
Secured password (EAP-MSCHAPV2) - Default. When selected, PEAP-MSCHAPv2 will be used. This is the most common PEAP configuration.
Smart card or certificate - When selected, PEAP-TLS will be used.

Cloudpath is able to auto remediate this setting.
By default, Windows XP will set this to 'Secured Password (EAP-MSCHAPV2)' for a new SSID.