Page 1 of 1

Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Sat Nov 13, 2010 10:31 am
by mastabog
Hi,

I'm new to Mikrotik and RouterOS but not new to routers and wireless networking. I'm using an RB411 with a R52 wifi mini-pci card. I'd like to know whether this combo coupled with RouterOS (v4.13 or v5.0rc3) can connect as a client wirelessly using WPA2 Enterprise using PEAP and MS-CHAPv2 (identity and password, not certificates). I need this to connect to "eduroam" networks, some of you may know of them.

I have briefly looked through the options in winbox on a routerboard in our lab. I really liked the plethora of configuration options and I'm considering buying a routerboard for myself but being able to use it as a client in WPA2-EAP + PEAP + MS-CHAPv2 is critical for me.

Could a kind soul tell me if it's possible and maybe guide me through setting it up on the RouterOS/winbox?

Thanks in advance

p.s. I've done it many times until now on laptops and other routers running OpenWRT (using wpa_supplicant).

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Tue Nov 16, 2010 5:40 am
by JorgeAmaral
Sorry mate, but it´s on the todo list.

A couple of us already had asked for that feature.

I believe that it will support it, but there's no time-line, so we will have to wait.

Best regards,

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Tue Nov 16, 2010 7:19 am
by mastabog
Wow ... and when I saw the looks of that winbox interface I thought that there is nothing that this thing cannot do! I was still hoping I missed something or that winbox does not show controls for all features.

Such a shame. This is needed for eduroam networks (http://www.eduroam.org), which are already popular throughout Europe and (almost) all of them use WPA2-EAP with PEAP. Most universities/research institutions have eduroam APs throughout the respective city. I got this RB411 especially for this purpose ...

Nevertheless, minutes ago I just finished compiling and flashing the RB411 with the latest OpenWRT trunk. I then got it working on the nearby eduroam network in less than 2 minutes with wpa_supplicant.

Since RouterOS is built on linux, wpa_supplicant could easily be incorporated without much effort and then we could use the RB in client mode with any auth and encryption type. Please?!?

I actually feel bad for scraping off RouterOS entirely as I loved the plethora of features and the winbox interface ... but in my situation it was all useless without WPA2-EAP + PEAP.

Cheers,

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Wed Feb 16, 2011 1:06 pm
by Kokel
Well, it it possible to use PEAP in the Passtrough mode. The AP will then passtrough eap packets in radius to a radius server, such as freeradius or NPS.
PEAP isn't supported nativly...

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Sat Feb 19, 2011 11:27 pm
by mastabog
But I need to use the mikrotik as a wifi client which is required to use WEP2-EAP with PEAP/MSCHAPv2 ... it's such a pity this is not supported. Why is that?

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Fri Mar 11, 2011 9:23 pm
by Harunaga
We are forced to use the CPE UBNT Nanostation because they support the protocol EAP-PEAP-MSCHAPv2 :(

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Sun Mar 13, 2011 6:24 am
by mastabog
We are forced to use the CPE UBNT Nanostation because they support the protocol EAP-PEAP-MSCHAPv2 :(
Funny you should mention that ... I bought some Ubiquiti devices for the exact same reason.

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Wed Aug 17, 2011 1:22 pm
by Kokel
Well, why don't you switch your authentication mode to eap-tls? Only protecting your wireless network with EAP-TLS or WPA2/CCMP(strong passwords) will make you sleep well. Everyone with a laptop and a wifi card is able to mitm a peap connection to get the informatin aout of the inner tunnel.

So, it is better to switch the AP Mode of the Access Point performing authentication. Buying equipment for less secure operation from my pov is a bad workaround.

Greetz, kokel

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Thu Aug 08, 2013 10:17 pm
by fabiopires
it's already supported..

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Mon Sep 09, 2013 1:31 am
by vicentnb1
it's already supported..
Really? How you do that? :?

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Wed Nov 06, 2013 4:58 pm
by awightman
it's already supported..
Really? How you do that? :?
Fabio probably means if you set it up as a non-client -
I've been asking the same question, and it was raised in feature requests years ago - don't expect it to be supported anytime soon I guess

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Mon Sep 22, 2014 8:41 pm
by ic32k
There is some way to connect as client at this kind of wireless networks???

Thank you!!

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Fri Mar 03, 2017 6:05 pm
by vilican
Any new information about this problem? Has this feature been implemented yet or is planned?
Thanks in advance.

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Sat Apr 29, 2017 7:30 pm
by pe1chl
It is now working in release 6.39!

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Tue Nov 21, 2017 3:22 pm
by mgleria
It is now working in release 6.39!
Could you please enlighten me about that? I need to configure an AP of the cAP series in client mode connected to a network with WPA2 Enterprise. I just updated the operating system to 6.40.5 version.

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Fri Mar 23, 2018 12:23 pm
by vecernik87
I am also interested. Tried to connect mikrotik to eduroam but it always ended up with network disconnected because 802.1x was not authenticated. :(

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Mon Aug 27, 2018 7:24 pm
by russman
From my mikrotik test unit I can connect to my SSIDs protected with WPA2 PSK no problem.
I can connect from my laptop to my PEAP protected SSID with no problems, however, I can't connection from my mikrotik. I've went through all my settings on the NPS server and AP and tried a number of other settings that didn't make sense for connecting this mikrotik as a PEAP client but its a no go.

I'm looking through RADIUS logs and the Windows PC client is passing the credentials on for authentication in the logs. The mikrotik is not sending a username from what I can see, however, the mikrotik log says authentication failed.

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Mon Aug 27, 2018 9:07 pm
by russman
Update: Digging through the logs it looks like Mikrotik is providing the "Supplicant Identity" on the general tab of the Security Profile as the EAP authentication username. So I decided to put the userman into that field and it works. Its using the Supplicant Identity as the username and the EAP MSCHAPv2 password as the password.

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Mon Aug 27, 2018 10:50 pm
by pe1chl
No, the "Supplicant Identity" field is used for what is usually called "anonymous identity" in WPA2-EAP.
The "MSCHAPv2 Username" field is used for the username.

When you are not concerned with keeping the username secret and/or have no control over the configuration of the remote end, you can put the same thing in both of these fields.

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Posted: Tue Mar 05, 2024 11:06 am
by toniojst
Hi, i have the same problem but with normal TLS security not with MSCHAPv2. As you can see here i have also problem with that mikrotik not provide identity. What can be wrong?

Provide link of my post where is all info and images: viewtopic.php?p=1059141&hilit=wpa2+enterprise#p1059141