AWK-5232
Web Console Configuration
3-18
The AWK-5232 provides some non-cryptographic EAP methods including PAP, CHAP, MS-CHAP, and
MS-CHAP-V2. These EAP methods are not recommended for direct use on wireless networks. However, they
may be useful as inner authentication methods with TTLS or PEAP.
Because the inner and outer authentications can use distinct user names in TTLS and PEAP, you can use an
anonymous user name for the outer authentication, while the true user name is shown only through the
encrypted channel. Remember, not all client software supports anonymous altercation. Confirm this with the
network administrator before you enable identity hiding in TTLS and PEAP.
TTL Inner Authentication
Setting
Description
Factory Default
PAP
Password Authentication Protocol is used
MS-CHAP-V2
CHAP
Challenge Handshake Authentication Protocol is used
MS-CHAP
Microsoft CHAP is used
MS-CHAP-V2
Microsoft CHAP version 2 is used
Anonymous
Setting
Description
Factory Default
Max. 31 characters
A distinct name used for outer authentication
None
User name & Password
Setting
Description
Factory Default
User name and password used in inner authentication
None
PEAP
There are a few differences in the inner authentication procedures for TTLS and PEAP. TTLS uses the encrypted
channel to exchange attribute-value pairs (AVPs), while PEAP uses the encrypted channel to start a second EAP
exchange inside of the tunnel. The AWK-5232 provides MS-CHAP-V2 merely as an EAP method for inner
authentication.