Wireless Access

last person joined: 17 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

EAP-TLS vs. PEAP

This thread has been viewed 13 times
  • 1.  EAP-TLS vs. PEAP

    Posted Apr 14, 2018 09:50 PM

    Hi,

      I was in a conversation with my boss and we started arguing about what we should do for our new campus, EAP-TLS or EAP-PEAP. to be honest, I don't know which one is better and why from Aruba point of view? Any help would be highly appreciated. 



  • 2.  RE: EAP-TLS vs. PEAP
    Best Answer

    EMPLOYEE
    Posted Apr 14, 2018 10:03 PM


  • 3.  RE: EAP-TLS vs. PEAP

    EMPLOYEE
    Posted Apr 15, 2018 01:52 PM
    PEAP uses legacy authentication protocols. EAP-TLS is always recommended.


  • 4.  RE: EAP-TLS vs. PEAP

    Posted May 01, 2018 11:21 PM

    Thanks for the reply, that was really helpful 



  • 5.  RE: EAP-TLS vs. PEAP

    Posted May 02, 2018 11:18 AM

    be sure to mark it as accepted if that was the correct answer for you.



  • 6.  RE: EAP-TLS vs. PEAP

    Posted May 03, 2018 11:29 AM

    Also if I'm not mistaken it's worth adding that EAP-PEAP also consists of an inner authentication method. When people refer to just PEAP they usually mean EAP-PEAP as the outer protocol and EAP-MSCHAPv2 as the inner. You could also do EAP-PEAP and tunnel EAP-TLS inside.



  • 7.  RE: EAP-TLS vs. PEAP

    EMPLOYEE
    Posted May 03, 2018 11:34 AM
    PEAP/EAP-TLS is only supported on Windows clients.


  • 8.  RE: EAP-TLS vs. PEAP

    Posted Apr 02, 2019 04:04 PM

    So EAP-TLS will not work on Android and IOS at all?



  • 9.  RE: EAP-TLS vs. PEAP

    EMPLOYEE
    Posted Apr 02, 2019 04:18 PM
    EAP-TLS is fully supported on both platforms.

    PEAP/EAP-TLS is only supported on Windows.


  • 10.  RE: EAP-TLS vs. PEAP

    Posted Apr 02, 2019 10:39 PM
    Thanks for clarifying! Can an eap-tls connection be established if either of the certificates is untrusted/unaccepted?