Yes, TEAP can use EAP-TLS as the (both) inner methods.
Yes, you can have TEAP and EAP-TLS in the same service.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Oct 27, 2023 10:16 AM
From: PD28
Subject: Tunnel EAP (TEAP) Windows 11
Hi Herman,
Thanks for your advise/comments on this, I too with you and always trying to use EAP-TLS whenever possible.. but sometime if a machine is shared between group of users, not sure TEAP method two (Secondary Auth) will work with EAP-TLS as well..?
Original Message:
Sent: Oct 27, 2023 09:58 AM
From: Herman Robers
Subject: Tunnel EAP (TEAP) Windows 11
Please note that MSCHAPv2 is strongly deprecated, and EAP-TLS (client certificate authentication, also as inner methods for TEAP) is probably the only way to go.
The link discusses credential guard, as also mentioned in the other response, which I think it the reason the 'Use my Windows login' is greyed out. Be prepared that future versions of Windows may make it even harder to use legacy/insecure authentication like MSCHAPv2.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Oct 24, 2023 12:26 PM
From: PD28
Subject: Tunnel EAP (TEAP) Windows 11
Hi All,
I am trying to configure EAP-TEAP for Windows 11 machines and see that it does not allow me to select "Automatically use my Windows logon name and password.." option which is greyed out. (see below). Appreciate if someone can advise how to fix this.
I found this (https://learn.microsoft.com/en-us/answers/questions/1036203/cant-configure-teap-settings-for-wired-connection) article but seems it just not a straight forward and also not sure this will have any security breach.
