Community discussions

MikroTik App
 
mastabog
just joined
Topic Author
Posts: 6
Joined: Sat Nov 13, 2010 4:12 am

Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Sat Nov 13, 2010 10:31 am

Hi,

I'm new to Mikrotik and RouterOS but not new to routers and wireless networking. I'm using an RB411 with a R52 wifi mini-pci card. I'd like to know whether this combo coupled with RouterOS (v4.13 or v5.0rc3) can connect as a client wirelessly using WPA2 Enterprise using PEAP and MS-CHAPv2 (identity and password, not certificates). I need this to connect to "eduroam" networks, some of you may know of them.

I have briefly looked through the options in winbox on a routerboard in our lab. I really liked the plethora of configuration options and I'm considering buying a routerboard for myself but being able to use it as a client in WPA2-EAP + PEAP + MS-CHAPv2 is critical for me.

Could a kind soul tell me if it's possible and maybe guide me through setting it up on the RouterOS/winbox?

Thanks in advance

p.s. I've done it many times until now on laptops and other routers running OpenWRT (using wpa_supplicant).
 
JorgeAmaral
Trainer
Trainer
Posts: 199
Joined: Wed Mar 04, 2009 11:53 pm
Location: /ip route add type=blackhole

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Tue Nov 16, 2010 5:40 am

Sorry mate, but it´s on the todo list.

A couple of us already had asked for that feature.

I believe that it will support it, but there's no time-line, so we will have to wait.

Best regards,
 
mastabog
just joined
Topic Author
Posts: 6
Joined: Sat Nov 13, 2010 4:12 am

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Tue Nov 16, 2010 7:19 am

Wow ... and when I saw the looks of that winbox interface I thought that there is nothing that this thing cannot do! I was still hoping I missed something or that winbox does not show controls for all features.

Such a shame. This is needed for eduroam networks (http://www.eduroam.org), which are already popular throughout Europe and (almost) all of them use WPA2-EAP with PEAP. Most universities/research institutions have eduroam APs throughout the respective city. I got this RB411 especially for this purpose ...

Nevertheless, minutes ago I just finished compiling and flashing the RB411 with the latest OpenWRT trunk. I then got it working on the nearby eduroam network in less than 2 minutes with wpa_supplicant.

Since RouterOS is built on linux, wpa_supplicant could easily be incorporated without much effort and then we could use the RB in client mode with any auth and encryption type. Please?!?

I actually feel bad for scraping off RouterOS entirely as I loved the plethora of features and the winbox interface ... but in my situation it was all useless without WPA2-EAP + PEAP.

Cheers,
 
Kokel
just joined
Posts: 11
Joined: Sun Nov 14, 2010 10:31 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Wed Feb 16, 2011 1:06 pm

Well, it it possible to use PEAP in the Passtrough mode. The AP will then passtrough eap packets in radius to a radius server, such as freeradius or NPS.
PEAP isn't supported nativly...
 
mastabog
just joined
Topic Author
Posts: 6
Joined: Sat Nov 13, 2010 4:12 am

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Sat Feb 19, 2011 11:27 pm

But I need to use the mikrotik as a wifi client which is required to use WEP2-EAP with PEAP/MSCHAPv2 ... it's such a pity this is not supported. Why is that?
 
User avatar
Harunaga
newbie
Posts: 29
Joined: Tue May 04, 2010 11:43 am
Location: Chelyabinsk, Russia

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Fri Mar 11, 2011 9:23 pm

We are forced to use the CPE UBNT Nanostation because they support the protocol EAP-PEAP-MSCHAPv2 :(
 
mastabog
just joined
Topic Author
Posts: 6
Joined: Sat Nov 13, 2010 4:12 am

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Sun Mar 13, 2011 6:24 am

We are forced to use the CPE UBNT Nanostation because they support the protocol EAP-PEAP-MSCHAPv2 :(
Funny you should mention that ... I bought some Ubiquiti devices for the exact same reason.
 
Kokel
just joined
Posts: 11
Joined: Sun Nov 14, 2010 10:31 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Wed Aug 17, 2011 1:22 pm

Well, why don't you switch your authentication mode to eap-tls? Only protecting your wireless network with EAP-TLS or WPA2/CCMP(strong passwords) will make you sleep well. Everyone with a laptop and a wifi card is able to mitm a peap connection to get the informatin aout of the inner tunnel.

So, it is better to switch the AP Mode of the Access Point performing authentication. Buying equipment for less secure operation from my pov is a bad workaround.

Greetz, kokel
 
fabiopires
just joined
Posts: 5
Joined: Tue Aug 06, 2013 4:33 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Thu Aug 08, 2013 10:17 pm

it's already supported..
 
User avatar
vicentnb1
just joined
Posts: 20
Joined: Tue Jul 30, 2013 1:16 am

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Mon Sep 09, 2013 1:31 am

it's already supported..
Really? How you do that? :?
 
awightman
just joined
Posts: 3
Joined: Wed Oct 16, 2013 1:58 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Wed Nov 06, 2013 4:58 pm

it's already supported..
Really? How you do that? :?
Fabio probably means if you set it up as a non-client -
I've been asking the same question, and it was raised in feature requests years ago - don't expect it to be supported anytime soon I guess
 
ic32k
just joined
Posts: 7
Joined: Mon Sep 22, 2014 8:37 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Mon Sep 22, 2014 8:41 pm

There is some way to connect as client at this kind of wireless networks???

Thank you!!
 
vilican
just joined
Posts: 1
Joined: Fri Mar 03, 2017 6:00 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Fri Mar 03, 2017 6:05 pm

Any new information about this problem? Has this feature been implemented yet or is planned?
Thanks in advance.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10240
Joined: Mon Jun 08, 2015 12:09 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Sat Apr 29, 2017 7:30 pm

It is now working in release 6.39!
 
mgleria
just joined
Posts: 2
Joined: Tue Nov 21, 2017 3:15 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Tue Nov 21, 2017 3:22 pm

It is now working in release 6.39!
Could you please enlighten me about that? I need to configure an AP of the cAP series in client mode connected to a network with WPA2 Enterprise. I just updated the operating system to 6.40.5 version.
 
User avatar
vecernik87
Forum Veteran
Forum Veteran
Posts: 882
Joined: Fri Nov 10, 2017 8:19 am

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Fri Mar 23, 2018 12:23 pm

I am also interested. Tried to connect mikrotik to eduroam but it always ended up with network disconnected because 802.1x was not authenticated. :(
 
russman
Frequent Visitor
Frequent Visitor
Posts: 98
Joined: Thu May 20, 2010 7:23 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Mon Aug 27, 2018 7:24 pm

From my mikrotik test unit I can connect to my SSIDs protected with WPA2 PSK no problem.
I can connect from my laptop to my PEAP protected SSID with no problems, however, I can't connection from my mikrotik. I've went through all my settings on the NPS server and AP and tried a number of other settings that didn't make sense for connecting this mikrotik as a PEAP client but its a no go.

I'm looking through RADIUS logs and the Windows PC client is passing the credentials on for authentication in the logs. The mikrotik is not sending a username from what I can see, however, the mikrotik log says authentication failed.
 
russman
Frequent Visitor
Frequent Visitor
Posts: 98
Joined: Thu May 20, 2010 7:23 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Mon Aug 27, 2018 9:07 pm

Update: Digging through the logs it looks like Mikrotik is providing the "Supplicant Identity" on the general tab of the Security Profile as the EAP authentication username. So I decided to put the userman into that field and it works. Its using the Supplicant Identity as the username and the EAP MSCHAPv2 password as the password.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10240
Joined: Mon Jun 08, 2015 12:09 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Mon Aug 27, 2018 10:50 pm

No, the "Supplicant Identity" field is used for what is usually called "anonymous identity" in WPA2-EAP.
The "MSCHAPv2 Username" field is used for the username.

When you are not concerned with keeping the username secret and/or have no control over the configuration of the remote end, you can put the same thing in both of these fields.
 
toniojst
just joined
Posts: 3
Joined: Thu Jul 13, 2023 6:07 pm

Re: Can I do CLIENT mode WPA2 Enterprise (802.1x) PEAP?

Tue Mar 05, 2024 11:06 am

Hi, i have the same problem but with normal TLS security not with MSCHAPv2. As you can see here i have also problem with that mikrotik not provide identity. What can be wrong?

Provide link of my post where is all info and images: viewtopic.php?p=1059141&hilit=wpa2+enterprise#p1059141

Who is online

Users browsing this forum: No registered users and 27 guests