Forum Discussion

Luca_55898's avatar
Luca_55898
Icon for Nimbostratus rankNimbostratus
Oct 25, 2012

BIGIP RADIUS Auth - ms-chap support?

Hi,

 

We authenticate our admins who logon to our BIG-IP devices using RADIUS.

 

Anyone know if BIG-IP can support ms-chap so this can be encrypted?

 

If we access the BIG-IP of HTTPS should I even be concerned about RADIUS?

 

4 Replies

  • Whether you should be concerned depends. The connection between client and F5 is secure; whether the connection between the F5 and RADIUS server(s) is, only you know but I assume it's internal and probably via the management interface so it's probably OK. Just FYI, I believe RADIUS is gaining TLS sometime soon.
  • Anyone know if BIG-IP can support ms-chap so this can be encrypted?sol12666: The BIG-IP system RADIUS implementation only supports the PAP authentication method

     

    http://support.f5.com/kb/en-us/solutions/public/12000/600/sol12666

     

     

  • that SOL has been updated yesterday with the same statement.. only PAP is supported. As far as I know there is no plans by F5 to support RadSec but there is to support APM AAA auth with Diameter. RFE ID 399198: "Diameter authentication for APM" At this time, the AAA radius supports only PAP.. what are doing the F5 security evangelists here? :-)