Community discussions

MikroTik App
 
Brimspark
just joined
Topic Author
Posts: 1
Joined: Sat Oct 06, 2018 9:45 pm

Can WPA2 EAP-TLS be used without an external radius server?

Sat Oct 06, 2018 10:21 pm

Hi all, I'm looking to move to a new router platform, and I'm hoping one of these can do what I need it to.


Right now I have a Banana Pi R1 configured with hostapd using TLS authentication for wireless clients. I started using it 18 months ago because I was fed up of ISP supplied hardware just being... You know what *most* ISP supplied hardware is like. I'd been using Debian for 10 years so routing, forwarding and address translation through iptables was already familiar to me, and with hostapd being able to serve an EAP access point without an external radius server was just awesome. But obviously, these SBC's aren't designed to be run 24/7, and it frequently needs rebooting. Sometimes it dies in such a way that you have to remove the SD card and fsck it in another machine to get it back online. It's time for a replacement.


I'm hoping something like the hAP ac can replace it, but when I search online, I notice people saying that you can't use EAP without an external radius server - is this true? For a large corporate environment, this won't be a problem, but for a home (or SOHO) user like me, it's not always practical to have a dedicated server running just for this job. I don't really want to run a radius server on a 24/7 availability VPS because it's just asking for trouble to store your wi-fi credentials offsite, but I also don't want to run one on my main computer, since it's not always on -- and it uses a lot of power when it actually is on (It's a Threadripper).


Does anybody know if RouterOS has its own internal radius server for use with EAP connections (like hostapd does)? Or if not, if it ever will in the future?

Who is online

Users browsing this forum: GoogleOther [Bot] and 95 guests