8. When the Certificate Request Wizard appears, click Next.
9. Select Computer, then click Next.
Figure 38: Certificate Template Screen
10. Ensure that your certificate authority is checked, then click Next.
11. Review the policy change information and click Finish.
12. Click Start - Run, type cmd and press enter.
Enter secedit /refreshpolicy machine_policy
This command may take a few minutes to take effect.
48
PC and Server Configuration
Internet Authentication Service (Radius) Setup
1. Select Start - Programs - Administrative Tools - Internet Authentication Service
2. Right-click on Clients, and select New Client.
Figure 39: Service Screen
3. Enter a name for the access point, click Next.
4. Enter the address or name of the Wireless Access Point, and set the shared secret, as
entered on the Security Settings of the Wireless Access Point.
5. Click Finish.
6. Right-click on Remote Access Policies, select New Remote Access Policy.
7. Assuming you are using EAP-TLS, name the policy eap-tls, and click Next.
8. Click Add...
If you don't want to set any restrictions and a condition is required, select Day-And-Time-Restrictions, and click Add...
Figure 40: Attribute Screen
9. Click Permitted, then OK. Select Next.
10. Select Grant remote access permission. Click Next.
49
Wireless Access Point User Guide
11.Click Edit Profile... and select the Authentication tab. Enable Extensible Authentication
Protocol, and select Smart Card or other Certificate. Deselect other authentication methods listed. Click OK.
Figure 41: Authentication Screen
12. Select No if you don't want to view the help for EAP. Click Finish.
50
PC and Server Configuration
Remote Access Login for Users
1. Select Start - Programs - Administrative Tools- Active Directory Users and Computers.
2. Double click on the user who you want to enable.
3. Select the Dial-in tab, and enable Allow access. Click OK.
Figure 42: Dial-in Screen
51
Wireless Access Point User Guide
802.1x Client Setup on Windows XP
Windows XP ships with a complete 802.1x client implementation. If using Windows 2000,
you can install SP3 (Service Pack 3) to gain the same functionality.
If you don't have either of these systems, you must use the 802.1x client software provided
with your wireless adapter. Refer to your vendor's documentation for setup instructions.
The following instructions assume that:
• You are using Windows XP
• You are connecting to a Windows 2000 server for authentication.
• You already have a login (User name and password) on the Windows 2000 server.
Client Certificate Setup
1. Connect to a network which doesn't require port authentication.
2. Start your Web Browser. In the Address box, enter the IP address of the Windows 2000
Server, followed by /certsrv
e.g
http://192.168.0.2/certsrv
3. You will be prompted for a user name and password. Enter the User name and Password
assigned to you by your network administrator, and click OK.
Figure 43: Connect Screen
4. On the first screen (below), select Request a certificate, click Next.
52
PC and Server Configuration
Figure 44: Wireless CA Screen
5. Select User certificate request and select User Certificate, the click Next.
6. Click Submit.
Figure 45: Request Type Screen
53
Wireless Access Point User Guide
Figure 46: Identifying Information Screen
7. A message will be displayed, then the certificate will be returned to you.
Click Install this certificate.
Figure 47:Certificate Issued Screen
8. . You will receive a confirmation message. Click Yes.
54
PC and Server Configuration
Figure 48: Root Certificate Screen
9. Certificate setup is now complete.
802.1x Authentication Setup
1.Open the properties for the wireless connection, by selecting Start - Control Panel -
Network Connections.
2. Right Click on the Wireless Network Connection, and select Properties.
3. Select the Authentication Tab, and ensure that Enable network access control using IEEE
802.1X is selected, and Smart Card or other Certificate is selected from the EAP type.
Figure 49: Authentication Tab
Encryption Settings
The Encryption settings must match the APs (Access Points) on the Wireless network you
wish to join.
•Windows XP will detect any available Wireless networks, and allow you to configure
each network independently.
55
Wireless Access Point User Guide
•Your network administrator can advise you of the correct settings for each network.
802.1x networks typically use EAP-TLS. This is a dynamic key system, so there is no
need to enter key values.
Enabling Encryption
To enable encryption for a wireless network, follow this procedure:
1. Click on the Wireless Networks tab.
Figure 50: Wireless Networks Screen
2. Select the wireless network from the Available Networks list, and click Configure.
3. Select and enter the correct values, as advised by your Network Administrator.
For example, to use EAP-TLS, you would enable Data encryption, and click the checkbox
for the setting The key is provided for me automatically, as shown below.
56
Figure 51: Properties Screen
PC and Server Configuration
Setup for Windows XP and 802.1x client is now complete.
57
Wireless Access Point User Guide
Using 802.1x Mode (without WPA)
This is very similar to using WPA-Enterprise.
The only difference is that on your client, you must NOT enable the setting The key is
provided for me automatically.
Instead, you must enter the WEP key manually, ensuring it matches the WEP key used on the
Access Point.
Figure 52: Properties Screen
Note:
On some systems, the "64 bit" WEP key is shown as "40 bit" and the "128 bit" WEP key is
shown as "104 bit". This difference arises because the key input by the user is 24 bits less than
the key size used for encryption.
58
Chapter 5
Operation and Status
5
This Chapter details the operation of the Wireless Access Point and the status
screens.
Operation
Once both the Wireless Access Point and the PCs are configured, operation is automatic.
However, you may need to perform the following operations on a regular basis.
•If using the Access Control feature, update the Trusted PC database as required. (See
Access Control in Chapter 3 for details.)
•If using 802.1x mode, update the User Login data on the Windows 2000 Server, and
configure the client PCs, as required.
General Screen
Use the General link on the main menu to view this screen.
59
Wireless Access Point User Guide
Figure 53: General Screen
60
Loading...
+ 31 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.