Designing Access Controls

Select an EAP Method for 802.1X

Table 3-75shows which EAP methods are supported by several 802.1X supplicants. You can check the documentation for your supplicants and devices and fill in your own rows in the table.

Table 3-75. EAP Methods Supported by 802.1X Supplicants

802.1X

EAP-MD5

EAP-TLS

EAP-TTLS

PEAP

EAP-SIM

EAP-TNC

LEAP

Supplicant

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Windows

 

X

 

 

 

X

 

 

 

native

 

 

 

 

Inner

 

 

 

 

 

 

 

 

protocol:

 

 

 

 

 

 

 

 

MS-CHAPv2

 

 

 

 

 

 

 

 

 

 

 

 

 

Mac native

X

X

 

X

 

X

 

 

X

 

 

 

Inner

Inner

 

 

 

 

 

 

protocol:

protocol:

 

 

 

 

 

 

PAP

MS-CHAPv2

 

 

 

 

 

 

MS-

 

 

 

 

 

 

 

 

 

CHAPv2

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Xsupplicant

X

X

 

X

 

X

X

X

X

 

 

 

Inner

Inner

 

 

 

 

 

 

protocol:

protocol:

 

 

 

 

 

 

PAP

GTC

 

 

 

 

 

 

CHAP

MS-

 

 

 

 

 

 

MS-CHAP

 

CHAPv2

 

 

 

 

 

 

MS-

 

 

 

 

 

 

 

 

 

CHAPv2

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Juniper

X

X

 

X

 

X

X

 

X

Odyssey

 

 

Inner

Inner

 

 

 

 

 

 

protocol:

protocol:

 

 

 

 

 

 

UAC

UAC

 

 

 

 

 

 

MS-

MS-

 

 

 

 

 

 

 

CHAPv2

 

CHAPv2

 

 

 

 

 

 

 

 

 

 

 

 

 

ProCurve

X

 

 

 

 

 

 

 

 

Switches,

 

 

 

 

 

 

 

 

 

APs, and RPs

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

As you can see, if you are using the native Windows supplicant, you should choose PEAP with Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAPv2) as the inner method. EAP-PEAP was created and is supported by Microsoft, and deployment in a Microsoft environment should be relatively pain free.

3-103