- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-27-2022 08:05 AM
According to PAN documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certifications/fips-cc-security-functions
MS-CHAPv2 is not compatible with FIPS-CC mode. It is recommended to use RADIUS with TLS.
However, in my test with my PAN-820 in FIPs mode, it works perfectly with RADIUS PEAP with MSCHAP-v2.
Can you even trust PAN documentation?
08-04-2022 03:15 AM
that seems a bit combative 😛
maybe the documentation could do with a little rewording, or the protocol could be removed from configuration options
FIPS-CC classifies MS-CHAPv2 as insecure, but this should not mean the protocol becomes unusable. The recommendation is to use a more secure alternative
08-04-2022 07:45 AM
I have to disagree with you a bit here. If PAN classifies MS-CHAPv2 as insecure, it should have listed PAP as well because PAP is the least secure method, even worse than MS-CHAPv2. PAP not only sends password (encrypted with weak encryption) along with username in clear-text over the wire. MS-CHAPv2 does not do that. And yet, PAP is available in FIPS-CC mode. Go figure.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!