Are you connecting to OpenLDAP or ActiveDirectory or similar?
Do you want to use EAP-PEAP-MSCHAPv2 or EAP-TTLS PAP/MSCHAPv2?
Please note for ActiveDirectory with MSCHAPv2: you will need a domain join for this. For MSCHAPv2 you will need to have NTLM_Auth in place on your RADIUS server. The Aruba Instant internal RADIUS-server does not support a domain join and NTLM_Auth.
If you are using OpenLDAP and want to use MSCHAPv2 then you need to store either plain-text passwords or NT-Passwords (like AD does). If you are using PAP you can store passwords with any hashing algorithm.
I would advise you to use an external RADIUS server if possible.