WPA3 Enterprise with Firewalla gold pro (latest beta and latest box) and Firewalla AP7 and Android phones
-
Hi there,
What Android device are you using? For devices that require you to select the authentication method, we recommend using:
- EAP Method: PEAP
- Phase 2 Authentication: MSCHAPV2
- CA Certificate: Trust on First Use
Which shouldn't require you to download the certificate on your device itself. For a full guide, see here: https://help.firewalla.com/hc/en-us/articles/46524481560467-WPA-Enterprise-Wi-Fi-with-RADIUS#h_01KAW66GB3M23SKEV5NXTXWR3Y
Let me know if that helps (or if I misunderstood your questions).
-
Very strange, tofu worked this time and prompted me to trust the Firewalla radius cert as expected. Oddly, I had previously tried domain and tofu and these hadn't worked. Thanks for the link. I had seen that in my searches. Can i use Synology as my radius server after turning on 3rd party radius on the latest Firewalla beta release and use a trusted cert to avoid using the default untrusted tofu cert?
-
Tofu will work for now with your recommended configuration then. Are there any further plans to better access the radius server certificate from the Firewalla UI to possibly allow upload and download of trusted certs? The reason for asking is tofu does not block out mitm attacks, but it's certainly much better than bypassing certificate validation all together.
Please sign in to leave a comment.
Comments
5 comments