Hi.
I tried to auth using chap method for Test aaa server on SZ.
But SZ used only pap mothod for Test aaa server.
Doesn't this test mothod apply yet on SZ?
Regards.
I tested it recently, and it was possible to test with chap in versions sz 6.1.2 and 7.0.0.
It was not possible with chap for a long time, but it was recently patched.
Hello Jeronimo.
You can run Chap or Pap to test AAA on SZ.
Services & profiles -> Authentication -> Proxy (SZ authentication)
Select the AAA server and then click in 'Test AAA', it will open a window where you can select Pap or Chap.
If you are not seeing this option, please share the version and model of your SZ.
Hi,Bruno.
I also know I can select PAP or ChAP in TEST AAA.
But wherever I tried PAP or CHAP, SZ did auth using only PAP.
I confirmed SZ is trying only PAP via wireshark on server side.
Did you test about it?
Hi Jeronimo,
Can you please tell me the model and version of your SZ?
Hi Bruno.
The version which I tried is 6.1.0.0.935 with vSZ-E.
Hello @Jeronimo,
I you would like to enable CHAP Test AAA. You need enable reversible encryption password in AD server. Please review below Document for more info on the same.Ruckus has nothing to do with the encryption method, we can only choose the Authentication Protocol type in configuration.
https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryptionRegards,
Parik
Thanks for your mention.
B utA main point of this oservtion is vsz don't try chap method though i choose chap.
The ariticle is not related this symptom.
I have confirmed this symptom via free-radius and windows nps both.
When i tried to auth pa and chap using other supplicant not vSZ, i had confirmed chap or pap was shooted.
Has Anyone tested it?
Hi @Jeronimo,
The symptoms you mentioned is usual. The settings in AAA profile is just for Testing the user credentials using PAP or CHAP. That doesn't mean we could use the same method in Dot1x authentication. For wireless client authentication the protocol used is client perspective and much more secure than just PAP/CHAP. They could use one of these, EAP/PEAP, EAP/MSCHAP-V2, EAP/TLS.
Regards,
Hi parik.
As your mention, if this symptom is usual, rukcus has to remove chap method on aaa test window.
Main goal of Test aaa tool is simple checking whether the id/pass was registered or active via pap or chap.
The reason of removing this is someone who want to check via pap or chap method feels very confusing.
Why does chap method exist on aaa test window?