PEAP-MSCHAPv2 to work, a certificate will be required on the domain controller, which needs to be signed by an Internal PKI CA. As you can see above that my DC01 has a certificate issued by my Root CA SOS.local On the firewall side, you should have the following configuration: From the screenshot above, we can see the certificate profile applied "PEAP-Cert", which will have by signing CA and authentication protocol is selected as PEAP-MSCHAPv2 After the config above, you can create an authentication profile with the RADIUS profile above an apply it to your Portal or gateway or both. Hope that helps!
... View more