You will place use-tunneled-reply=yes in peap config.
This is right config 3Com 4500(V3.03.00): # domain default enable company # dot1x dot1x authentication-method eap undo dot1x handshake enable # radius scheme Radius server-type extended primary authentication x.x.x.x primary accounting x.x.x.x key authentication qwerty key accounting qwerty user-name-format without-domain # domain company scheme radius-scheme Radius vlan-assignment-mode string accounting optional # # interface Ethernet1/0/1 stp edged-port enable broadcast-suppression pps 3000 packet-filter inbound link-group 4999 rule 0 dot1x port-method portbased dot1x # File "users": username Tunnel-Type = VLAN Tunnel-Medium-Type = IEEE-802 Tunnel-Private-Group-ID = "2" - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html