cancel
Showing results for 
Search instead for 
Did you mean: 

Hello! Does Ruckus ZoneDirector support MSCHAPV2 in 9.6 build 15 ?

khaqan_faridi
New Contributor II
 
3 REPLIES 3

sid_sok
Contributor II
It should work, for client authentication the ZD/AP is only a tunnel between the client and the radius server. The client and server will negotiate what to use, the AP and ZD should only forward traffic between the two.

The UG notice for PAP and now CHAP is only in reference to the ability to use the ZD to run a test against the radius server. The ZD's test of the radius server only uses PAP or CHAP.

rodrigus_feitos
New Contributor
But CHAP is not the same MSCHAP. How can that work?

sid_sok
Contributor II
Are you talking about Test the AAA server or are you talking about an actual client authenticating?

If you are talking about a real client, there is not much you need to set on the ZD, just the IP address of the Radius server, the Shared Secret and the Auth port. 

The rest, negotiation for security protocol to use is done between the Client and the radius server.

The ZD will just tunnel the authentication traffic between the client and Radius.  If the client and Radius server are configured to use MSCHAPv2 it will work.
Labels