Ieee 802.1X Client Using Eap/Tls Certificate - Psion Teklogix 9160 G2 User Manual

Wireless gateway
Hide thumbs Also See for 9160 G2:
Table of Contents

Advertisement

Appendix B: Security Settings on Wireless Clients/RADIUS Server

IEEE 802.1x Client Using EAP/TLS Certificate

3. Click Properties to bring up the Protected EAP Properties dialog and configure the
following settings.
Table B.6 Protected EAP Properties Settings
Validate Server Certificate
Select Authentication Method
4. Click Configure to bring up the EAP MSCHAP v2 Properties dialog.
On this dialog, disable (click to uncheck) the option to Automatically use my Windows
logon name . . . etc.
Click OK on all dialogs (starting with the EAP MSCHAP v2 Properties dialog) to close
and save your changes.
Logging On To The Wireless Network With An IEEE 802.1x PEAP Client
IEEE 802.1x PEAP clients should now be able to associate with the access point. Client
users will be prompted for a user name and password to authenticate with the network.
B.6.2

IEEE 802.1x Client Using EAP/TLS Certificate

Extensible Authentication Protocol (EAP) Transport Layer Security (TLS), or EAP-TLS, is
an authentication protocol that supports the use of smart cards and certificates. You have the
option of using EAP-TLS with both WPA/WPA2 Enterprise (RADIUS) and IEEE 802.1x
modes if you have an external RADIUS server on the network to support it.
Note: If you want to use IEEE 802.1x mode with EAP-TLS certificates for authentication
and authorization of clients, you must have an external RADIUS server and a Public
Key Authority Infrastructure (PKI), including a Certificate Authority (CA), server
configured on your network. It is beyond the scope of this document to describe these
configuration of the RADIUS server, PKI, and CA server. Consult the documentation
for those products.
Some good starting points available on the Web for the Microsoft Windows PKI soft-
ware are:
"How to Install/Uninstall a Public Key Certificate Authority for Windows 2000" at
http://support.microsoft.com/default.aspx?scid=kb;en-us;231881
B-18
Psion Teklogix 9160 G2 Wireless Gateway User Manual
Disable this option (click to uncheck the box).
Note: This example assumes you are using the Built-in Authentication server on
the AP. If you are setting up EAP/PEAP on a client of an AP that is using an
external RADIUS server, you might certificate validation and choose a certif-
icate, depending on your infrastructure.
Choose Secured password (EAP-MSCHAP v2).
, and

Advertisement

Table of Contents
loading

Table of Contents