Network Authentication
TPG User Manual
72
7.4
How to Configure PEAP
Benefits and
Purpose
PEAP (Protected Extensible Authentication Protocol) validates the
identity of devices or users before they gain access to network
resources. You can configure the TPG for the PEAP network authen-
tication. This makes sure that the TPG gets access to protected net-
works.
Basic Functions
In the case of PEAP (compare EAP-TTLS; see
Ö
70), an encrypted
TLS (Transport Layer Security) channel is established between the
TPG and the RADIUS server. Only the RADIUS server authenticates
itself using a certificate that was signed by a CA.
The TLS channel is then used to establish another connection that
can be protected by means of additional EAP authentication
methods (e.g. MSCHAPv2).
The advantage of this procedure is that only the RADIUS server
needs a certificate. Therefore no PKI is needed. PEAP uses the advan-
tages of TLS and supports various authentication methods, including
user passwords and one-time passwords.
Requirements
;
The TPG is defined as user (with user name and password) on a
RADIUS server.
What do you want
to do?
’Enabling PEAP via the TPG Homepage’
Ö
72
’Enabling PEAP via the InterCon-NetTool’
Ö
73
Enabling PEAP via the TPG Homepage
Proceed as follows:
1. Start the TPG Homepage.
2. Select
Configuration – Protection
.
3. Select
Authentication
.
4. Select
EAP-PEAP
from the
Authentication
list.
5. Enter the user name and the password that are used for the
configuration of the TPG on the RADIUS server.