Proxy PEAP to one Radius Server - EAP-TLS to another Radius Server

Basile Bluntschli basile.bluntschli at gmail.com
Thu Aug 13 15:05:04 CEST 2015


Hi Alan

maybe I was not clear with my initial question.

My switch will have the radius server A configured. All radius requests
will be sent to the radius server A.
If supplicant X wants to authenticate with PEAP, radius server A would
handle the full request.
If Supplicant Z wants to authenticate with EAP-TLS radius server A would
proxy the whole request to Radius Server B.

Is there a way to do this?

Thanks
Basile



2015-08-13 14:34 GMT+02:00 Alan DeKok <aland at deployingradius.com>:

> On Aug 13, 2015, at 2:25 PM, Basile Bluntschli <
> basile.bluntschli at gmail.com> wrote:
> > thanks for your fast reply!
> > So impossible means, it is not possible with EAP? (nothing to do with
> > unlang?)
>
>   It's impossible because it was designed to be impossible, by the people
> who created EAP.  You can't change one EAP type into another.
>
>   Alan DeKok.
>
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>


More information about the Freeradius-Users mailing list