How Do Different Authentication Modes Support AD/LDAP Authentication?
- MAC address authentication and administrator authentication support AD/LDAP authentication. By default, the device uses PAP authentication. Therefore, AD/LDAP authentication is available on the device without the need for you to modify the configuration.
- 802.1X authentication does not support AD/LDAP authentication.
- Portal authentication supports AD/LDAP authentication, but the authentication mode must be set to PAP.
- By default, the built-in Portal server uses CHAP. Therefore, you need to run the portal local-server authentication-method { chap | pap } command to set the authentication mode to PAP.
- The authentication mode on the external Portal server must be set to PAP.
AD/LDAP authentication supports only PAP because the server data source requires the real user name and password. In CHAP mode, the user name and password cannot be restored after being encrypted using hash.