Aruba PEAP-GTC Supplicant Plug-In Guide

Similar documents
Configuring the Client Adapter through the Windows XP Operating System

Instructions for connecting to the FDIBA Wireless Network. (Windows XP)

Configuring 802.1X Authentication Client for Windows 8

Instructions for connecting to winthropsecure

Protected EAP (PEAP) Application Note

Configuring the Client Adapter through the Windows XP Operating System

Configuring the Client Adapter through Windows CE.NET

Using PEAP and WPA PEAP Authentication Security on a Zebra Wireless Tabletop Printer

Network Access Flows APPENDIXB

simplifying... Wireless Access

Managing External Identity Sources

Manual UCSFwpa Configuration for Windows 7

Configuring 802.1X Settings on the WAP351

Windows 7 Configuration for ORU Wireless Networks

Network Security 1. Module 7 Configure Trust and Identity at Layer 2

The SSID to use and the credentials required to be used are listed below for each type of account: SSID TO CREDENTIALS TO BE USED:

Zebra Setup Utility, Zebra Mobile Printer, Microsoft NPS, Cisco Access Point, PEAP and WPA-PEAP

Instructions for connecting to the FDIBA Wireless Network (Windows Vista)

PROTECTED EXTENSIBLE AUTHENTICATION PROTOCOL

Internet Access: Wireless WVU.Encrypted Network Connecting a Windows 7 Device

Securewireless Windows 7 Setup Guide

Secure Access Configuration Guide For Wireless Clients

Wireless for Windows 7

Configuring EAP-FAST CHAPTER

Configuring WPA2 for Windows XP

Rhodes University Wireless Network

Manually Configuring Windows 7 for Wireless PittNet

Wireless Fusion Enterprise Mobility Suite. User Guide for Version 3.20

Connecting to the NJITSecure wireless network.

NT 0018 Instructions for Setting Up UoE_Secure (XP)

Zebra Mobile Printer, Zebra Setup Utility, Cisco ACS, Cisco Controller PEAP and WPA-PEAP

ONUnet ONU Setup Guide for Windows 7

Manually Configuring Windows 8 for Wireless PittNet

Connecting to the Eduroam WiFi

Cisco Secure ACS for Windows v3.2 With PEAP MS CHAPv2 Machine Authentication

Zebra Setup Utility, Zebra Mobile Printer, Microsoft IAS, Cisco Access Point, PEAP and WPA-PEAP

User Databases. ACS Internal Database CHAPTER

Cisco Exam Questions and Answers (PDF) Cisco Exam Questions BrainDumps

Troubleshooting CHAPTER

Using EAP Authentication

How to connect to Wi-Fi

Configuring Authentication Types

Using the Cisco Unified Wireless IP Phone 7921G Web Pages

Install Certificate on the Cisco Secure ACS Appliance for PEAP Clients

Release Notes for Cisco Aironet a/b/g Client Adapters (CB21AG and PI21AG) for Windows Vista 1.1

Auburn Montgomery AUM Wi-Fi. Windows 7. User s Guide & System Documentation

IMPORTANT INFORMATION FOR CURTIN WIRELESS ACCESS - STUDENT / WINDOWS XP -

BEFORE INSTALLATION: INSTALLATION:

b/g/n 1T1R Wireless USB Adapter. User s Manual

INFORMATION SYSTEMS SERVICE NETWORKS AND TELECOMMUNICATIONS SECTOR

Using EAP-TTLS and WPA EAP-TTLS Authentication Security on a Wireless Zebra Tabletop Printer

Zebra Setup Utility, Zebra Mobile Printer, Microsoft NPS, Cisco Controller, PEAP and WPA-PEAP

LAB: Configuring LEAP. Learning Objectives

Configuring 802.1X Authentication Client for Windows 8

ENHANCING PUBLIC WIFI SECURITY

Package Content IEEE g Wireless LAN USB Adapter... x 1 Product CD-ROM.x 1

IEEE a/b/g Wireless USB 2.0 Adapter. User s Manual Version: 1.2

WDT3250 RF Setup Guide

For my installation, I created a VMware virtual machine with 128 MB of ram and a.1 GB hard drive (102 MB).

SDK Driver Supplicant sdcgina sdc_gina SCU scutray sdc_applet

PEAP under Unified Wireless Networks with ACS 5.1 and Windows 2003 Server

SDK Driver Supplicant sdcgina sdc_gina SCU scutray sdc_applet

Configuring the Client Adapter

Using the Cisco Unified Wireless IP Phone 7921G Web Pages

Configure Network Access Manager

UMDNJ Wireless Documentation Windows 7

Summary. Deployment Guide: Configuring the Cisco Wireless Security Suite 1 OL

150Mbps N Wireless USB Adapter

Wireless Setup Instructions for Windows 7

GHz g. Wireless A+G. User Guide. Notebook Adapter. Dual-Band. Dual-Band WPC55AG a. A Division of Cisco Systems, Inc.

Secure ACS for Windows v3.2 With EAP TLS Machine Authentication

Wireless LAN Security. Gabriel Clothier

ResNet Guide. For the University of Redlands. Determine Your Operating System... 2 Windows 8 / 8.1 Wireless Connection Instructions...

ClearPass QuickConnect 2.0

Network. NEC Portable Projector NP905/NP901W WPA Setting Guide. Security WPA. Supported Authentication Method WPA-PSK WPA-EAP WPA2-PSK WPA2-EAP

Connecting to the eduroam Wireless Network. 1. If you are using a PC, move the. 2. Next Click or Tap the Settings. Help Sheet Windows 8.

PEAP under Cisco Unified Wireless Networks with ACS 4.0 and Windows 2003

Configure 802.1x - PEAP with FreeRadius and WLC 8.3

Wireless-N USB Adapter User s Manual

Cisco 4400 Series Wireless LAN Controllers PEAP Under Unified Wireless Networks with Microsoft Internet Authentication Service (IAS)

WL 5011s g Wireless Network Adapter Client Utility User Guide

Configuring Funk Odyssey Software, Avaya AP-3 Access Point, and Avaya

Protected EAP (PEAP) Application Note

WZC Wireless Connection Method (Windows XP, Vista, 7) - 1 -

Setting Up Cisco SSC. Introduction CHAPTER

Johns Hopkins

A Division of Cisco Systems, Inc. GHz g. Wireless-G. USB Network Adapter. User Guide WIRELESS WUSB54G. Model No.

NetMotion Integration with GreenRADIUS - Quick Start Guide

Connect to eduroam WiFi

Quick Installation Guide

Wired Dot1x Version 1.05 Configuration Guide

RSA SecurID Ready with Wireless LAN Controllers and Cisco Secure ACS Configuration Example

Johns Hopkins

Cisco 802.1x Wireless using PEAP Quick Reference Guide

802.1x Radius Setup Guide Working AirLive AP with Win X Radius Server

To Activate your Wireless Account

ForeScout CounterACT. Configuration Guide. Version 4.3

IT Quick Reference Guides Connecting to SU-Secure using Windows 8

Connecting Devices to the PSD-BYOD Network

Part 1: Connecting to HawkNET on your Windows XP PC

Transcription:

Aruba PEAP-GTC Supplicant Plug-In Guide This document describes the installation and configuration of a supplicant plug-in which supports Protected Extensible Authentication Protocol (PEAP) with EAP-Generic Token Card (GTC) authentication for Windows XP clients. This software can only be installed and used in conjunction with an Aruba Mobility Controller with the AAA FastConnect feature enabled. This document describes the following topics: Overview on page 2 Installing the Supplicant Plug-In Software on page 3 Configuring PEAP with EAP-GTC on the Windows XP Client on page 4 Log File on page 8 NOTE: PEAP with EAP-GTC is only supported on Aruba Mobility Controllers running ArubaOS version 2.5.4 or later. The Mobility Controller administrator must enable the AAA FastConnect feature and configure EAP-GTC as the inner EAP type, as described in the ArubaOS User Guide. PEAP-GTC Supplicant Plug-In Guide 1

Overview The Extensible Authentication Protocol (EAP) type Protected EAP (PEAP) uses Transport Layer Security (TLS) to create an encrypted tunnel. Within the TLS tunnel, the client can be authenticated using one of the following inner EAP methods: EAP-Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAPv2): Described in RFC 2759, this EAP method is widely supported by Microsoft clients. This is the default method and is supported by ArubaOS version 2.5.1 and later. EAP-Generic Token Card (GTC): Described in RFC 2284, this EAP method permits the transfer of unencrypted usernames and passwords from client to server. The main uses for EAP-GTC are one-time token cards such as SecureID and the use of LDAP or RADIUS as the user authentication server. You can also enable caching of user credentials on the controller as a backup to an external authentication server. This method is supported by ArubaOS version 2.5.4 and later. The current Wireless Zero Configuration (WZC) under Windows XP only supports PEAP with EAP-MS-CHAPv2. To use PEAP with EAP-GTC authentication in your wireless network, you need to install and configure Aruba s supplicant plug-in software on your Windows XP clients. 2 PEAP-GTC Supplicant Plug-In Guide 0510278-02 November 2006

Installing the Supplicant Plug-In Software Download the software for the PEAP with EAP-GTC supplicant plug-in from the Aruba Networks support website. Install the software by opening the installer package on a Windows XP client and following the instructions in the InstallShield Wizard. FIGURE 1 InstallShield Wizard for Installing Plug-In Software NOTE: You must reboot the Windows XP client after installing or uninstalling the supplicant plug-in software. PEAP-GTC Supplicant Plug-In Guide 3

Configuring PEAP with EAP-GTC on the Windows XP Client This section describes how to configure PEAP with EAP-GTC on a Windows XP client after you install the supplicant plug-in software. 1. On the Windows XP client, open the Wireless Network Connection Properties dialog box (Figure 2). A. Right-click on the My Network Places icon and select Properties. B. In the Network Connections window, right-click on Wireless Network Connection and select Properties. FIGURE 2 Wireless Network Connection Dialog Box 2. Select the Wireless Networks tab. 3. Under the Preferred networks section, click Add. The Wireless network properties dialog box appears with the Association tab selected (Figure 3). Enter the following information: Network name (SSID): Enter the network SSID Network Authentication: Select Open, WPA, or WPA2 from the drop-down menu Data encryption: Select WEP, TKIP, or AES from the drop-down menu 4 PEAP-GTC Supplicant Plug-In Guide 0510278-02 November 2006

FIGURE 3 Wireless Network Properties Association Tab 4. Click on the Authentication tab (Figure 4). Select Protected EAP (PEAP) from the EAP type drop-down menu. NOTE: EAP GTC does not work with machine authentication, therefore you must deselect the Authenticate as computer when computer information is available checkbox PEAP-GTC Supplicant Plug-In Guide 5

FIGURE 4 Wireless Network Properties Authentication Tab 5. Click on Properties to display the Protected EAP Properties dialog box (Figure 5). Enter the following selections: Select the Validate server certificate checkbox. Select EAP Token from the Select Authentication Method drop-down menu. NOTE: When you select EAP Token as the authentication method, no dialog box is displayed if you click the Configure button. 6 PEAP-GTC Supplicant Plug-In Guide 0510278-02 November 2006

FIGURE 5 Protected EAP Properties Dialog Box 6. Click OK. PEAP-GTC Supplicant Plug-In Guide 7

Log File The supplicant plug-in software logs authentication events in C:\Program Files\ Aruba Wireless Networks\EAP-GTC\gtc.log. Inspecting the log file is normally not necessary, however if there is a problem with client authentication, you can view the log file with a text editor. For example, the following messages in the log file indicate a successful client authentication (messages are preceded by the date and time of the event): [INFO] RasEapMakeMessage :: Got EAPCODE_success [INFO] RasEapMakeMessage :: Authentication succeeded The following messages in the log file indicate a client authentication failure because the wrong password was entered for the authentication: [INFO] RasEapMakeMessage :: Got EAPCODE_failure [ERROR] RasEapMakeMessage :: Authentication failed. Wrong password. The following messages in the log file indicate that the AAA FastConnect feature is not enabled on the Mobility Controller: [INFO] RasEapMakeMessage :: Got EAPCODE_Request [ERROR] RasEapMakeMessage :: AAA FastConnect (dot1x termination) is not enabled on the Aruba switch 8 PEAP-GTC Supplicant Plug-In Guide 0510278-02 November 2006