Overview
Two of the advantages of using Cloudpath PEAP with AD are:
- It removes the requirement to deploy NPS as a RADIUS server in front of AD for 802.1X EAP-PEAP credential-based authentication.
- It provides a consolidated approach to migrating users from EAP-PEAP to EAP-TLS .
With this type of authentication, you can set up any number of active directories to which your Cloudpath system can communicate. You then configure the Cloudpath onboard RADIUS server to support PEAP. You can also configure an unlimited number of policies, but only one policy will be assigned to a user, depending on which criteria that you specify matches a given user trying to connect to Cloudpath. For each policy, you assign a RADIUS attribute group that can contain many attributes including VLAN ID.
The basic steps to follow to use PEAP with the Cloudpath onboard RADIUS server are:
- Set up your active directory servers.
- Creating An Authorization Server: This section covers the requirements to set up at least one authorization server.
- Adding an Active Directory Authentication Server: This section describes how to add a server to the PEAP configuration within the RADIUS Server portion of the Cloudpath UI.
- Adding Policies to RADIUS Server Configuration: This section describes how to add policies to the PEAP configuration within the RADIUS Server portion of the Cloudpath UI.
- Checking a User Record: This section shows you how to view information about users who have been enrolled or attempted to enroll into the Cloudpath system using this PEAP authentication process.