Little more background on this. In order to do an MSCHAPv2 authentication, which you should avoid and move to TLS instead (search MSCHAPv2 cracked for the why), you need access to either the user password in plaintext or the NT-hash of the password.
LDAP servers try to avoid storing plaintext passwords and NT hashes, so they don't have access to the information to perform an MSCHAPv2 authentication.
So the short summary is indeed that LDAP servers don't support the use of PEAP-MSCHAPv2 authentication and you will need a RADIUS that has deeper integration into your authentication system (like AD). This is also the reason why ClearPass needs to be joined to the domain to support MSCHAPv2, as the domain join is needed to get access to the NT-hashes.