XIQ Authentication Service

  • 2 March 2021
  • 2 replies

Userlevel 2

I have set up a test XIQ Pilot environment using an AP 305C. I was participating in a demo where they said that if you did not have a RADIUS server available you could use CloudIQ Authentication Service however they were not very clear on all the setting.

Which Key Management method should be chosen?

Which Encryption method should be chosen?

On the client device

What is the EAP method?

What is the phase 2 authentication method?

What “Domain” should be entered?


Thank you,



2 replies

Userlevel 6

Hi Chris, a lot of those settings are going to be personal preference or based on what your client devices can use. 

Key Management- I’d stick with WPA2-802.1x unless you have some older client devices, in which case I’d set it to Auto so you can use WPA1 or WPA2. 

Encryption Method- I’d recommend using CCMP(AES) over TKIP, but here again we need to think about the client base and what it can use. Unless you have some very, very old client devices to work with, CCMP is the one to use. 

EAP- Extensible Authentication Protocol (EAP) is an authentication framework, providing some common functions/negotiations of authentication methods. Basically it’s a common framework for end devices to use when trying to authenticate to an unknown network. 

Phase 2 authentication method- This is an extra layer of protection in the authentication process, to prevent things like replay attacks. MS-CHAPv2 is an example of this. 

Domain- Typically you’d use the domain your end users will be coming from, but if you can elaborate on where you’re seeing the domain section, I can try to be more specific. 


Hope that helps!


Userlevel 2

Hi Sam,

I understand about setting the parameters when using your own RADIUS server but I was asking about using the ExtremeCloud IQ Authentication Service.  See picture.

In training videos for XIQ the instructor has said that this can be used instead of an onsite RADIUS server.  Unfortunately the video does not give all the details on how to configure it.  

I created some users and had their credential sent to me but they won’t connect.  When I use PEAP my mobile device asks for a Domain.  See picture

When I have set up 802.1X networks with my own Radius server it never asks for the Domain.  I tried to use but that didnt do the trick.

Any ideas?