WPA Enterprise using cloud auth and EAP-TLS?

HPITS
HPITS Posts: 7
First Comment Second Anniversary
edited March 2023 in Nebula

Nebula AP with WEP Enterprise and cloud auth is currently using the insecure PEAP-MSChap2? Can it be configured with EAP-TLS?

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,317  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @HPITS ,

    Nebula cloud authentication provides a simple and easy-to-use authentication service with the authentication method as PEAP-MSChap2, which provides a certain level of security by providing encryption for user credentials during the authentication process. It is suitable for small and medium-sized businesses that do not have a certificate infrastructure, as it does not require client-side certificates to be installed.

    Compare to PEAP-MSChap2, EAP-TLS provides a higher level of security as it requires both the client and server to authenticate using certificates. So, if you requires a higher level of security for their network, you can configure WPA Enterprise with My RADIUS server.

    image.png

    Zyxel_Judy

    Untitled Image
  • ChrisKringle
    ChrisKringle Posts: 2  Freshman Member
    First Comment Friend Collector

    Hi Judy

    is there a kind of timeline available to implement RFC 6613 (Radius/TLS, also known RadSec)? i advised customers to implement zyxel hardware, but for some of my public sector customers it is mandatory or a a criterium to have this implemented and supported.

    many thanks, Chris

  • ChrisKringle
    ChrisKringle Posts: 2  Freshman Member
    First Comment Friend Collector

    hey @Zyxel_Judy - this helps a lot and i apologize to hijack this one also as a kind of feature request to implement Radsec as well - if i need to raise a new topic, please let me know, but as of today, i am dealing with Zyxel Hardware together with AAD joined Devices (Intune Managed) and Cloud Radius to fulfil my customer needs - and also want to implement the more advanced one called Radius/TLS as described in RFC6614. i do not want to raise a comparison against competitors as i like and advised customers to use Zyxel, but for some of those it is a A criterium for public tender.
    hope you can understand some concerns and maybe you can provide some insights or a timeline or an "if"…?
    all the best, chris

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,697  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @ChrisKringle

    RADsec for AP has already been raised. Below is the idea post.

    Nebula support for RADsec — Zyxel Community

    We are still evaluating it. You may leave your comment in this idea post and give it a vote.

    Zyxel Melen


Nebula Tips & Tricks