Specifications

8-32 AAA Commands
protocol Protocolusedforauthentication.Specifyoneofthefollowing:
eapmd5—ExtensibleAuthenticationProtocol(EAP)withmessagedigest
algorithm 5.Forwiredauthenticationclients:
–Useschallengeresponsetocomparehashes
–Providesnoencryptionorintegritycheckingfortheconnection
Note: The eap-md5 option does not work with Microsoft wired authentication clients.
eaptls—EAPwithTransportLayerSecurity(TLS):
–Providesmutualauthentication,integrityprotectednegotiation,and
keyexchange
–RequiresX.509publickeycertificatesonbothsidesoftheconnection
–Providesencryptionandintegritycheckingfortheconnection
CannotbeusedwithRADIUSserverauthentication(requiresuser
informationtobeintheswitch’slocal
database)
peapmschapv2—ProtectedEAP(PEAP)withMicrosoftChallenge
HandshakeAuthenticationProtocolversion 2(MSCHAPV2).For
wirelessclients:
–UsesTLSforencryptionanddataintegritycheckingandserverside
authentication
–ProvidesMSCHAPV2mutualauthentication
–Onlytheserversideoftheconnectionneedsacertificate.
ThewirelessclientauthenticatesusingTLS
tosetupanencrypted
session.ThenMSCHAPV2performsmutualauthenticationusingthe
specifiedAAAmethod.
passthrough—MSSsendsalltheEAPprotocolprocessingtoaRADIUS
server.
method1
method2
method3
method4
AtleastoneanduptofourmethodsthatMSSusestohandleauthenti cat ion.
Specifyoneormore
ofthefollowingmethodsinpriorityorder.MSSapplies
multiplemethodsintheorderyouenterthem.
Amethodcanbeoneofthefollowing:
local—UsesthelocaldatabaseofusernamesandusergroupsontheRAS
forauthentication.
servergroupname—UsesthedefinedgroupofRADIUSserversfor
authentication.
YoucanenteruptofournamesofexistingRADIUSserver
groupsasmethods.
RADIUSserverscannotbeusedwiththeEAPTLSprotocol.
Formoreinformation,see“Usage.”