Cisco Systems CB21AG Configuring EAP Types, Overview of EAP-FAST, Configuring PEAP-GTC, page

Page 55
Configuring EAP Types

C H A P T E R 3

Configuring EAP Types

This chapter explains the EAP types that are used for authenication to wireless networks.

The following topics are covered:

Overview of EAP-FAST, page 3-1

How EAP-FAST Works, page 3-2

Configuring EAP-FAST, page 3-4

Overview of LEAP, page 3-17

How LEAP Works, page 3-17

Configuring LEAP, page 3-18

Overview of PEAP-GTC, page 3-21

How PEAP-GTC Works, page 3-22

Configuring PEAP-GTC, page 3-23

Overview of EAP-FAST

Note For additional information about EAP-FAST, see RFC4851.

EAP-FAST is an EAP method that enables secure communication between a client and an authentication server by using Transport Layer Security (TLS) to establish a mutually authenticated tunnel. Within the tunnel, data in the form of type, length, and value (TLV) objects are used to send further authentication-related data between the client and the authentication server.

EAP-FAST supports the TLS extension as defined in RFC 4507 to support the fast re-establishment of the secure tunnel without having to maintain per-session state on the server. EAP-FAST-based mechanisms are defined to provision the credentials for the TLS extension. These credentials are called Protected Access Credentials (PACs).

EAP-FAST provides the following:

Mutual authentication

An EAP server must be able to verify the identity and authenticity of the client, and the client must be able to verify the authenticity of the EAP server.

Immunity to passive dictionary attacks

Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista

 

OL-16534-01

3-1

 

 

 

Image 55
Contents 800 553-NETS Fax 408 Software ReleaseAmericas Headquarters Cisco Systems, Inc 170 West Tasman Drive San Jose, CATurn the television or radio antenna until the interference stops Preface Network Configurations Using Client AdaptersAd Hoc Wireless LAN FCC Safety Compliance StatementInserting the Card Advanced Roaming SettingTwo-Phase Tunneled Authentication Obtaining Client Adapter SoftwareFinding the Version of the LEAP Module Accessing LEAP Properties for ConfigurationConfiguring LEAP Configuring and Starting LoggingEnglish Translation D-7 Creating Strong Passwords A-9Antenna Installation Warning EAP Messages A-1English Translation ChannelsAcknowledgments and Licensing F-1 Chinese TranslationOL-16534-01 viiiAudience, page Purpose, page Organization, page Conventions, page PrefaceAudience PurposeConventions OrganizationVaroitus Tämä varoitusmerkki merkitsee vaaraa. Olet tilanteessa, joka voi johtaa ruumiinvammaan. Ennen kuin työskentelet minkään laitteiston parissa, ota selvää sähkökytkentöihin liittyvistä vaaroista ja tavanomaisista onnettomuuksien ehkäisykeinoista. Tässä julkaisussa esiintyvien varoitusten käännökset löydät liitteestä Translated Safety Warnings käännetyt turvallisuutta koskevat varoitukset Obtaining Documentation, Obtaining Support, and Security Guidelines Related PublicationsInstalling the Client Adapter Driver and Software, page Product Overview and InstallationNetwork Configurations Using Client Adapters, page Safety information, page Unpacking the Client Adapter, pagecard Introduction to the Client AdaptersTerminology PC-CardbusLEDs Hardware ComponentsRadio Radio AntennaAd Hoc Wireless LAN Network Configurations Using Client AdaptersSoftware Components Figure 1-1 Ad Hoc Wireless LAN Wireless Infrastructure with Workstations Accessing a Wired LANFCC Safety Compliance Statement Safety informationSafety Guidelines Warnings Unpacking the Client Adapterhttp//support.microsoft.com/kb/935222 Package ContentsSystem Requirements http//support.microsoft.com/kb/932063For Infrastructure Devices Site RequirementsFor Client Devices Inserting a PC-Cardbus Card Inserting the Client Adapter1-10 Assemble the antenna see the “Assembling the Antenna” section on page Inserting a PCI CardChanging the Bracket Insert the card see the “Inserting the Card” section on page1-12 Inserting the Card1-13 Assembling the Antenna1-14 Mounting the AntennaStep 1 Perform one of the following 1-15Step 8 If the Found New Hardware Wizard window appears, click Cancel 1-16Step 6 Click Client Adapters and Client Software Step 5 Click Wireless SoftwareStep 7 Click Cisco Aironet Wireless LAN Client Adapters Obtaining Client Adapter Software1-18 Installing the Client Adapter Driver and SoftwareFigure 1-11 Cisco Aironet Installation Program Window 1-19Hardware Insertion Figure 1-13 Cisco Aironet Installation Program-Setup Status Window 1-20Step 8 Click Finish 1-211-22 Creating a New Profile and Configuring Basic Settings, page Configuring Wireless ProfilesOverview of Wireless Profiles, page Accessing Microsoft Vista Network and Sharing Center, pageAccessing Microsoft Vista Network and Sharing Center Overview of Wireless ProfilesCreating a New Profile and Configuring Basic Settings Cisco Aironet 802.11a/b/g Wireless Adapter see Figure Creating a New Profile and Configuring Basic Settings Step 7 In this dialog box, enter information for the wireless network that you want to add.Table 2-1 lists and describes general settings for the profile. Follow the instructions in the table to configure these settings Setting Encryption Types” section on pageWhat to Enter and Encryption Types” section on page Chapter 3, “Configuring EAP Types.” The enterprise network EAPProfile Management General Settings continued What to Enter 2-10 Security and Encryption TypesWEP Shared Security with Static WEP Keys WPA and WPA22-11 802.1X with Dynamic WEP KeysCCKM Fast Secure Roaming Accessing a Profile That Was Created Previously2-12 2-13 Viewing and Changing the Settings of a ProfileFigure 2-7 Network and Sharing Center Window Figure 2-8 Wireless Network properties Dialog Box-Connection Tab 2-14in Table 2-1 on page is available, Choose Control Panel Manage Wireless NetworksSettings dialog box. See the “Radio Measurement” section on page 2-18 and the “Advanced Roaming Setting” section on pageFigure 2-9 Wireless Network properties Dialog Box-Security Tab 2-162-17 2-18 Radio Measurement2-19 Advanced Roaming Setting2-20 Configuring PEAP-GTC, page Configuring EAP TypesConfiguring EAP-FAST, page Overview of LEAP, page How LEAP Works, page Configuring LEAP, pageHow EAP-FAST Works Two-Phase Tunneled AuthenticationTwo-Phase Tunneled Authentication, page Protected Access Credentials, pageServer Certificate Validation Protected Access CredentialsConfiguring EAP-FAST Settings in the Connection Tab, page Configuring EAP-FASTAccessing EAP-FAST Properties for Configuration Accessing EAP-FAST Properties for Configuration, pageConfiguring EAP-FAST Settings in the Connection Tab Default anonymous Default OnUse Protected Access Default OnDefault None Default EnabledPAC box and the Validate Server Certificate box at the same time Default OffOverview of the User Credentials Tab Usernames and PasswordsClient Certificates 3-10 Configuring EAP-FAST Settings in the User Credentials TabFigure 3-3 User Credentials Tab in EAP-FAST Properties Window Mode with OTP” section on page information about OTP, see the “Understanding PIN Mode and Token3-11 Figure 3-5 Next Token Prompt Window Understanding PIN Mode and Token Mode with OTP3-12 Figure 3-4 New PIN Prompt Window3-13 Configuring EAP-FAST Settings in the Authentication TabTable 3-3 lists and describes options for authentication 3-14Figure 3-6 Authentication Tab in EAP-FAST Properties Window Select an authentication Default Disableda certificate on this computer radio button in the User 3-153-16 Finding the Version of the EAP-FAST ModuleFigure 3-7 About Tab in EAP-FAST Properties Window How LEAP Works Overview of LEAP3-17 Configuring LEAP Settings in the Network Credentials Tab, page Configuring LEAPAccessing LEAP Properties for Configuration Accessing LEAP Properties for Configuration, page3-19 Configuring LEAP Settings in the Network Credentials TabFigure 3-8 Wireless Network Properties Window LEAP Network Credentials 3-20Settings Table 3-4 LEAP Network Credentials SettingsFinding the Version of the LEAP Module Overview of PEAP-GTC3-21 3-22 How PEAP-GTC WorksConfiguring PEAP-GTC Settings in the Connection Tab, page Configuring PEAP-GTCAccessing PEAP-GTC Properties for Configuration Accessing PEAP-GTC Properties for Configuration, pageFigure 3-10 Wireless Network Properties Window 3-243-25 Configuring PEAP-GTC Settings in the Connection TabFigure 3-11 Connection Tab in PEAP-GTC Properties Window If the Validate server certificate box is checked but the Do not Default anonymousIf the Validate server certificate box is checked and the Do not prompt user to authorize new servers or trusted certificate3-27 Configuring PEAP-GTC Settings in the User Credentials Tabwhich is the case for the Prompt automatically for username and Default Offpassword option and Token Mode with OTP” section on pagePEAP-GTC User Credentials Options continued 3-29Figure 3-13 New PIN Prompt Window Figure 3-14 Next Token Prompt Window Understanding PEAP-GTC AuthenticationFinding the Version of the PEAP-GTC Module 3-30The LEAP XML Schema, page Logging for EAP Modules, page Performing Administrative TasksUsing Microsoft Tools to Perform Administrative Tasks, page The EAP-FAST XML Schema, page The PEAP-GTC XML Schema, pageOverview of Group Policy Objects, page Using Microsoft Tools to Perform Administrative TasksOverview of Group Policy Objects Adding a Group Policy Object Editora. Go to File Add/Remove Snap-in Creating a EAP Group Policy Object in Windows Vistag. From the Select Group Policy Object dialog box, click Finish Configuring Machine Authentication for EAP-FAST Configuring Machine Authentication for PEAP-GTC Configuring Single Sign-On for EAP-FASTConfiguring Single Sign-On for PEAP-GTC and LEAP The EAP-FAST XML Schema xsdocumentation xselement xschoice xselement name=authenticateWithToken xscomplexType xssequence xselement xselement name=sendViaInnerMethod xscomplexType xsall 4-10xscomplexType name=PasswordFromProfile xssimpleContent 4-114-12 xsannotation xselement xschoice xselement name=enableFastReconnect 4-134-14 xssimpleType xsrestriction base=xsstring xsenumeration value=exactly 4-15xselement name=anyServerName type=Empty xsannotation 4-164-17 The PEAP-GTC XML Schema4-18 xscomplexContent xscomplexType xscomplexType name=IdentityPattern 4-19xscomplexType name=TokenSource xschoice 4-20xschoice xssequence xscomplexType 4-214-22 4-23 The LEAP XML SchemaattributeFormDefault=unqualified xselement name=eapLeap type=EapLeap 4-244-25 Step 2 Right-click Command Prompt and select Run as administrator Configuring and Starting LoggingConfiguring and Starting Logging, page Step 1 Choose Start All Programs Accessorieswevtutil sl Cisco-EAP-LEAP/Debug /efalse Disabling Logging and Flushing Internal Bufferswevtutil sl Cisco-EAP-FAST/Debug /efalse wevtutil sl Cisco-EAP-PEAP/Debug /efalsewevtutil sl Cisco-EAP-LEAP/Debug /lfn“pathtoetllogfile” Locating Log Fileswevtutil sl Cisco-EAP-FAST/Debug /lfn“pathtoetllogfile” wevtutil sl Cisco-EAP-PEAP/Debug /lfn“pathtoetllogfile”Removing a Client Adapter, page Routine ProceduresUpgrading the Client Adapter Software, page Removing a PC-Cardbus Card Removing a Client AdapterRemoving a PCI Card Upgrading the Client Adapter Software Step 5 Click Update the previous installation Figure 5-3 Cisco Aironet Installation Program-Setup Status Window Step 8 Click Finish Troubleshooting with Cisco Aironet Client Diagnostics, page Troubleshooting and DiagnosticsEnabling Client Reporting, page Figure 6-1 Network and Sharing Center Window Troubleshooting with Cisco Aironet Client DiagnosticsFigure 6-3 Cisco Aironet Client Diagnostics Dialog Box-Choose Adapter Figure 6-2 Cisco Aironet Client Diagnostics Dialog BoxFigure 6-5 Cisco Aironet Client Diagnostics Dialog Box-Testing Delay Figure 6-7 Aironet Desktop Utility-Stop Running Diagnostics Figure 6-6 Cisco Aironet Client Diagnostics Dialog Box-Test WindowEnabling Client Reporting Creating Strong Passwords, page A-9 EAP-FAST Error Messages and PromptsEAP-FAST Error Messages and Prompts, page A-1 PEAP-GTC and LEAP Error Messages and Prompts, page A-6Appendix A EAP Messages EAP-FAST Error Messages and Prompts Page Recommended Action Enter a username Recommended Action Press OK to continue PEAP-GTC and LEAP Error Messages and Prompts Page Page Characteristics of Strong Passwords Creating Strong PasswordsCharacteristics of Weak Passwords A-10 Password Security BasicsRadio Specifications, page B-3 Technical SpecificationsA P P E N D I X B Physical Specifications Radio Specifications 5725 to 5805 MHz 5150 to 5250 MHz5250 to 5350 MHz 5470 to 5725 MHzOutdoor typical Indoor typicalSafety and Regulatory Compliance Specifications Power SpecificationsExplosive Device Proximity Warning, page C-2 Translated Safety WarningsAntenna Installation Warning, page C-3 A P P E N D I X CExplosive Device Proximity Warning Antenna Installation Warning Warning for Laptop Users Page Page Declaration of Conformity for RF Exposure, page D-7 Declarations of Conformity and Regulatory InformationA P P E N D I X D Department of Communications - Canada, page D-3FCC Certification Number LDK102050 CB21AG European Community, Switzerland, Norway, Iceland, and Liechtenstein Department of Communications - CanadaCanadian Compliance Statement Page Declaration of Conformity Statement Cisco Aironet CB21AG Wireless LAN Client AdapterCisco Aironet PI21AG Wireless LAN Client Adapter 03-6434-6500 Declaration of Conformity for RF ExposureJapanese Translation English TranslationChinese Translation 2.4- and 5-GHz Client AdaptersEnglish Translation 5-GHz Client Adapters Brazil/Anatel ApprovalD-10 AIR-CB21AG-W-K9D-11 AIR-PI21AG-W-K9D-12 A P P E N D I X E Channels, page E-2 Maximum Power Levels and Antenna Gains, page E-4Channels, Power Levels, and Antenna Gains IEEE 802.11a ChannelsRegulatory Domains IEEE 802.11b/gIEEE 802.11b Maximum Power Levels and Antenna GainsIEEE 802.11g Maximum Power Levels and Antenna Gains A P P E N D I X F Acknowledgments and LicensingAppendix F Acknowledgments and Licensing OL-16534-01 Appendix F Acknowledgments and LicensingOL-16534-01 A P P E N D I X G AbbreviationsList of Acronyms continued Table G-1
Related manuals
Manual 34 pages 15 Kb Manual 286 pages 35.03 Kb Manual 22 pages 28.37 Kb Manual 22 pages 55.14 Kb