To run WiFi with WPA and PEAP using Cisco Aeronet and Windows IAS/NPS, you need the following:
- Cisco Aeronet Access Point
- Windows Server (2003/2008) running IAS/NPS as the Radius server
- Server authentication certificate (commercial or self-signed)
Setting the Access Point
Login to the access point using HTTP/HTTPS, navigate to Security - Server Manager

Create a new radius server, point it to the Windows IAS/NPS (installed later). Speficy the shared secret and port for authentication and accounting

Set the default server priorities to or the new Radius server's IP address you just added

Navigate to Security - SSID Manager

Create a new SSID, attach it to the VLAN and tick the Radio checkbox

For Client Authentication Settings, tick Open Authentication with EAP and Network EAP. Change the Server Priorities to Customize or use defaults

For Client Authentication Key Management, select Mandatory for Key Management and tick WPA

SSID Settings. (optional) select Multiple SSID if you are running this SSID as multiple SSID

Navigate to Security - Encryption Manager

Select Encryption Modes to Chipher with AES CCMP + TKIP

Select Encryption Keys to Key 2 and let the value blank

Setting IAS/NPS
Once the NPS installed, run the wizard to setup the Wireless network.
We need to add a radius client which is the IP address of the Cisco Access Point

Navigate to Advancced tab, select the vendor name to Cisco

Navigate to Policies and select Connection Request Policies. Select the Secure Wireless Policy

Most of the following settings are the default value








Navigate to Use Windows authentication for all users. The following settings are having the default value


Navigate to Secure Wireless Connections. The following settings are having the default value

We specify which AD Security Group has access to this policy


Up to this stage, you need to import a server authentication certificate. This can be a commercial certificate or self-signed certificate. If you use self-signed certificate, you need to make sure the clients machine that is going to connect to this WiFi must trust the Root CA who generate this certificate
Select Microsoft Protected EAP (PEAP) and select Edit

If you have the certificate installed correctly, you should see the option which certificate you want to use

On the Settings tab






