We don't have access to the cisco in this matter. I just spoke with them on the phone again and he assured me this is what will happen: They are proxying the radius auth to us. They will present us with a CHAP request, if that failes, their radius will fail over to PAP. However we are getting taht error instead, and it seems that we are, instead of ignoring their CHAP request, sending back an invalid password reply, or some other variant on Access-Reject. Is there a way to prevent it from sending that Access-Reject when CHAP fails?
--E ----- Original Message ----- From: "Chris Parker" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Monday, June 10, 2002 3:35 PM Subject: Re: force pap in a chap first environment > At 03:18 PM 6/10/2002 -0400, Enesha Fairluck wrote: > >Greetings all > > > > I hope someone can help me. We are trying to get some wholesale dialups > >from a company, and they just sprung on us that they are a chap environment. > >THey claimed that our client should be able to force pap, but that has not > >been the case thus far..Is there an easy way to do that? > > If the NAS presents CHAP as an option to the client before PAP is > presented as an option, Windows will *always* accept it. > > The only way for PAP and CHAP to co-exist with Windows dialup clients, is > for the NAS to offer PAP before CHAP. > > On cisco you set the order thus: > > int x/x/x:x:x > > ppp authentication pap chap callin > > On Ascend/Lucent with recent TAOS select the > > "PAP-Preferred" option > > -Chris > -- > \\\|||/// \ StarNet Inc. \ Chris Parker > \ ~ ~ / \ WX *is* Wireless! \ Director, Engineering > | @ @ | \ http://www.starnetwx.net \ (847) 963-0116 > oOo---(_)---oOo--\------------------------------------------------------ > \ Wholesale Internet Services - http://www.megapop.net > > > > - > List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html > > - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
