SmartBridges sB3210 manual Test TLS

Page 49

i n t e l l i g e n t

w i r e l e s s

p l a t f o r m

At the RADIUS tab for authentication:

Active = Yes

Server IP = 192.168.1.10

Port Number = 1812

Shared Secret = AP_Shared_Secret

6. Test TLS

The final step is to test the server. With Windows XP computer off, start the server in the debug mode by entering:

/usr/local/radius/sbin/run-radius -X -A

The server should start, displaying various debug information before it displays:

----- Example --------------------------------------------

Listening on IP address *, ports 1812/udp and 1813/udp, with proxy on 1814/udp. Ready to process requests

----------------------------------------------------------

If you don't see the message, look through the debug information for errors and missing information. If you see this message, start the Windows XP computer.

When the Windows XP starts, you will see various messages and certificates exchanged between the client and the server. If all is well, you should see the client authenticated and the user logged on. The following partial example is from Document 3. It shows the last few lines of a successful authentication:

-----Example ---------------------------------------------

...

MS-MPPE-Recv-Key = 0xe032765ca06c052e5fe7c2a7534a4252daec44a08505bdb459d4 fa81e70390f2221d2b06071eb0625e0ba67452a890909662

MS-MPPE-Send-Key = 0xe03131ce085bc266127528e749bd4753d3e1702df2d4d8c080351 380f52eae2c24a9fa78015c24e0d140bcd01b23d6c0cacc

EAP-Message = "\003_\000\004"

Message-Authenticator = 0x00000000000000000000000000000000 Finished request 5

Going to the next request

-----------------------------------------------------------

If you see MS-MPPE-Recv-Key and MS-MPPE-Send-Key, the server authenticated the client. You should be able to surf.

7. Change Server Configuration for PEAP

To change the server for PEAP authentication, only a few changes need to be made.

a. users -- Return to the users file and add the user password:

jbibe User-Password == "My-XP-Password"

b. Radiusd.conf -- Return to the radiusd.conf file and make the following changes:

 

airPoint™ Nexus User Configuration Guide

Page 49 of 55

 

Image 49
Contents Version AirPoint Nexus SB3210Table of Contents Overview of User Guide About This DocumentRelated Publications Technical Support Center Introduction AirPoint Nexus Configuration FeaturesSystem Requirements Pre-Installation Checklist for airPoint ChecklistsEconomical One radio model sB3210 Parameters Units Site a Site BSignature of Engineer Name Date Rssi Post-Installation Checklist for airPointChecklist Parameters Units Site a Site B User Login and License Agreement AirPoint ConfigurationLicense Agreement Description of Parameters Descriptions Web GUI Administrator Password ChangeNavigation Menu Bar Using the Configuration PagesDescription of Menus Menu Item Menu Sub-items Editable Boxes for Parameter EditingNone Menu Item Menu Sub-items DescriptionWEP Only Internal ACLTools Help Ethernet Configurations AirPoint Bridge Configuration ParametersWireless Configuration Wireless Settings Items Descriptions AirPoint Bridge Wireless SettingsItems Descriptions Radio ProtocolRadio Protocol Parameters AirPoint Bridge Performance Settings Configuring Spanning Tree Protocol STP Bridge ConfigurationDefault STP Values Setting Default Value Range Purpose Setting Default Value Range Purpose T e l l i g e n t R e l e s s A t f o r m 11 Bridge Configuration Security WEP only Wireless Equivalent PrivacyWDS Table T e l l i g e n t R e l e s s A t f o r m Internal ACL with WEP disabled External ACL Radius & Internal ACL WPA-Radius External ACLRadius & Internal ACLWPA radius Traffic Statistics Traffic StatisticsTools System ConfigurationSnmp Security System Configuration DescriptionsSnmp Security Configuration Reset OptionsDelayed Reset NTP Time Server SetupProfile Manager NTP Time SettingsProfile Manager Menu Items Save ProfileProfile Calendar Load Operating ProfilePing Test Result Link TestThroughput Test Result Link Budget Planning10 Link Budget Planning Calculator Link Budget AirPoint Nexus Firmware Upgrade Firmware UpgradeSuccessful upgrade pop-up window Appendix a Configuration of the Radius Server Produce Certificates T e l l i g e n t R e l e s s A t f o r m Configure Server for TLS Install Windows XP Certificates and Setup Client for TLS Test TLS Change Windows XP for Peap Abbreviations Acronyms Appendix B Useful terms and definitionsWPA Snmp Appendix C Snmp Trap Appendix D License