Skip to main content

Android - EAP-PEAP Configuration

Configure Android devices to connect securely to IronWifi WPA-Enterprise wireless networks using EAP-PEAP authentication. This guide covers manual configuration for individual devices and automated deployment through Mobile Device Management solutions.

Overview

EAP-PEAP (Protected Extensible Authentication Protocol) provides secure wireless authentication using a username and password protected by a TLS tunnel. All Android versions support EAP-PEAP natively.

Prerequisites

  • Android 4.0 or later
  • Valid IronWifi user credentials
  • Wireless network configured with WPA2-Enterprise

Configuration Steps

Android 10 and Later

  1. Open Settings > Network & Internet > Wi-Fi
  2. Tap your enterprise network (or tap Add network)
  3. Configure the following settings:
    • EAP method: PEAP
    • Phase 2 authentication: MSCHAPV2
    • CA certificate: Use system certificates (or select specific CA)
    • Online certificate status: Do not verify (or Request status)
    • Domain: Your RADIUS server domain (optional)
    • Identity: Your username (usually email address)
    • Anonymous identity: Leave blank or enter anonymous
    • Password: Your password
  4. Tap Connect

Android 9 and Earlier

  1. Open Settings > Wi-Fi
  2. Tap your enterprise network
  3. Configure:
    • EAP method: PEAP
    • Phase 2 authentication: MSCHAPV2
    • CA certificate: Do not validate (or select certificate)
    • Identity: Your username
    • Password: Your password
  4. Tap Connect

Certificate Configuration

Using System Certificates (Android 10+)

Android 10 introduced the ability to use system certificates:

  1. Select CA certificate: Use system certificates
  2. Enter Domain: radius.ironwifi.com (or your RADIUS hostname)

Installing a Custom CA Certificate

If your organization uses a private CA:

  1. Download the CA certificate to your device
  2. Open Settings > Security > Encryption & credentials
  3. Tap Install a certificate > CA certificate
  4. Select the downloaded certificate file
  5. When configuring Wi-Fi, select your installed certificate

MDM Deployment

For enterprise deployment via MDM (Mobile Device Management):

Android Enterprise (Work Profile)

Create a Wi-Fi configuration profile with:

  • SSID: Your network name
  • Security: WPA2-Enterprise
  • EAP type: PEAP
  • Phase 2: MSCHAPV2
  • Identity: ${user.email} (variable)
  • Certificate: Deploy CA certificate

Samsung Knox

Use Knox Configure to deploy:

  1. Create a Wi-Fi policy
  2. Set EAP configuration
  3. Push to enrolled devices

Troubleshooting

"Authentication Problem" Error

  1. Verify your username and password
  2. Check that your account is active in IronWifi
  3. Try removing and re-adding the network

Certificate Validation Failed

  1. Check the CA certificate is correctly installed
  2. Verify the domain name matches the RADIUS server
  3. Ensure the certificate hasn't expired

Cannot Connect After Android Update

  1. Remove the saved network
  2. Re-enter credentials
  3. May need to reinstall CA certificate

Network Disconnects Randomly

  1. Disable battery optimization for Wi-Fi
  2. Go to Settings > Apps > Wi-Fi > Battery > Unrestricted
  3. Check for Android system updates

Identity Configuration

Standard Identity

Use your full email address: user@company.com

Anonymous Identity

For privacy, configure anonymous identity:

  • Identity: user@company.com (encrypted)
  • Anonymous identity: anonymous@company.com (visible)