- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-21-2016 02:20 PM
Currently, my PA-3050 devices (PAN-OS 6.1.12) utilize RADIUS authentication. I know that this uses the completely unencrypted PAP protocol.
I have asked PAN about MS-CHAP v2 support in the past and was told that the device must be placed into FIPS mode in order to gain the ability to do RADIUS authentication over MS-CHAP v2, but by putting a device into FIPS mode you are effectively performing a factory reset.
I've always thought that was completely ridiculous. If the device supports MS-CHAP v2 in FIPS mode, it's clearly capable of using the protocol. Why not make MS-CHAP v2 available in standard mode as a choice over PAP?
In any case, I've seen that PAN has removed the FIPS mode from newer PAN-OS releases. As such, is PAN adding MS-CHAP v2 support? Or are they dropping MS-CHAP v2 support entirely along with the associated FIPS mode?