Appendix C: Security Settings On Wireless Clients And RADIUS Server Setup
WPA/WPA2 Enterprise (RADIUS) Client Using EAP-TLS Certificate
C-24 Psion Teklogix 9160 G2 Wireless Gateway User Manual

Logging On To The Wireless Network With A WPA/WPA2 Enterprise (RADIUS)

PEAP Client

“WPA/WPA2 Enterprise (RADIUS)” PEAP clie nts should now be able to asso ciate
with the access point. Client users will be prompted for a user name and password to
authenticate with the network.
C.7.2 WPA/WPA2 Enterprise (RADIUS) Client Using EAP-TLS Certificate
Extensible Authentication Protocol (EAP) Transport Layer Security (TLS),
or EAP-TLS, is an authentication protocol that supports the use of smart cards
and certificates. You have the option of using EAP-TLS with both WPA/WPA2
Enterprise (RADIUS) and IEEE 802.1x modes if you have an external RADIUS
server on the network to support it.
Note: If you want to use IEEE 802.1x mode with EAP-TLS certificates for
authentication and authorization of clients, you must have an external
RADIUS server and a Public Key Authority Infrastructure (PKI), includ-
ing a Certificate Authority (CA), server configured on your network. It is
beyond the scope of this document to describe these configuration of the
RADIUS server, PKI, and CA server. Consult the documentation for those
products.
Some good starting points available on the Web for the Micr osoft Windows
PKI software are:
“How to Install/Uninstall a Public Key Certificate Authority for Windows
2000” at

http://support.microsoft.com/default.aspx?scid=kb;en-us;231881

, and
How to “Configure a Certificate Server” at
http://support.microsoft.com/default.aspx?scid=kb;en-us;318710#3
.
To use this type of security, you must do the foll owing:
1. Add the 9160 G2 Wireless Gateway to the list of RADIUS server cli-
ents. (See “Configuring An External RADIUS Server To Recognize
The 9160 G2 Wireless Gateway” on page C-30.)