Extension Wireless Access (EWA) v2.0 The Extension Wireless Network (EWA) is broken into two parts: the public network (vce pub) and the private network (vce wlan). The public network (vce pub) is secured with a password that changes periodically, and none of the network traffic is encrypted. This network is suitable for the general public to use on their private computers. The private network (vce wlan) is secured with you Hokies ID and password and all network traffic from your computer to Virginia Tech is encrypted. This network is only to be used by Virginia Tech Faculty, Staff, and Students with valid Hokies accounts. To access the public network (vce pub), simply click on the vce pub network from the detected wireless network list and enter the current password. Contact the Ag Help Desk (540 231 4865) to obtain the current password. To access the private network (vce wlan), you first need to meet the prerequisites, and then follow the instructions for your operating system. Prerequisites: 1. You must have a Hokies account. 1. For Employees, use the self service tool: https://hokiespw.ais.vt.edu/selfservice/ (note: if you do not know your hokies password, contact 4Help (540 231 4357) and request a Hokies password change) 2. For Students, see the Obtaining a Hokies Account for Student on page 2. 2. You must have the Virginia Tech Certificate Authority Root (VTCA Root) installed. 1. Go to http://www.pki.vt.edu 2. On the right hand blue bar, click on Install VTCA Root 3. Follow the installation instructions for your operating system 3. Your Hokies account must be a member of the AG OU (AG Organizational Unit). Unless you created a Hokies recently, then you are probably already a member of the AG OU. To verify or to be added, contact the Ag Help Desk, aghelp@vt.edu or 540 231 4865. Detailed connection instructions: Windows XP (page 3) Windows Vista (page 5) Windows 7 (page 9) Mac OS 10.5/10.6 (page 13) extension_wireless_access.pdf Page 1
Obtaining a Hokies Account for Students Students have to be sponsored to be able to get the account. Also, it is expected that once a student leaves (or no longer has use for the HOKIES account) the requesting department is responsible for having the account deleted. The Dean, Director, or Department Head must fill out this form: http://4help.vt.edu The following text should be copied into the problem form: Please forward to IRM. We need to get a HOKIES account for the Graduate Student <Student Name> (<student_pid>). An Exchange account is not needed. IRM will then verify the request with the Dean, Director, or Department Head via email. Once the account is approved, IRM will send the Dean, Director, or Department Head the information about the HOKIES account including the account s temporary password. Once the student no longer needs the account, the department must submit a request to remove the account from the VT Active Directory. Use the same form as above to complete that process. The Dean, Director, or Department Head can designate another person in the department to request and approve accounts if they prefer. To do so, they will need to fill out the IRM Signature Authorization Letter found here: http://www.security.vt.edu/irm/forms/signatureletter.pdf It is the responsibility of the requesting students department to sponsor, request and terminate HOKIES ID s for wireless access. AHNR IT, CALS Administration, VCE/AREC/4H Center Administration will not process requests for sponsorship of student/non employee HOKIES accounts. extension_wireless_access.pdf Page 2
Windows XP 1. Click Start > Control Panel > Network Connections. 2. Right click on the Wireless Network Connection in the list and select Properties. 3. Click on the Wireless Networks tab, then click Add (note: If you do not see a Wireless Networks tab, then Windows is not managing your wifi connection. You need to turn off the application that is managing your wifi connection. Call the Ag Help Desk for help.) 4. On the Wireless network properties window: a. Network name (SSID): vce wlan b. Network Authentication: WPA2 c. Data encryption: AES 5. Click the Authentication tab. a. EAP type: Protected EAP (PEAP) b. Uncheck: Authenticate as computer c. Uncheck: Authenticate as guest d. Click the Properties extension_wireless_access.pdf Page 3
6. On the Protected EAP Properties window: a. Check: Validate server certificate (default) b. Trusted Root Certification Authorities: Check: Virginia Tech Root CA c. Uncheck: Do not prompt user to authorize new servers or trusted certification authorities. d. Select Authentication Method: Secured Password (EAP MSCHAPv2) e. Check: Enable Fast Reconnect (default) f. Click Configure 7. Uncheck: Automatically use my Windows logon name and password 8. Click OK to close the Protected EAP Properties window. 9. Click OK to close the vce wlan properties window. 10. Click OK to close the Wireless Network Connection Properties. 11. In your system tray, the Wireless Network Connection bubble will pop up once the network has been detected. Left click anywhere in the bubble (Do NOT click the X). 12. On the Enter Credentials window: a. User name field: <your_hokies_id> b. Password field: <your_hokies_password> c. Logon domain: HOKIES d. Click OK 13. Verify that you are connected to the wireless network by going to a webpage of your choice. You are now connected to the office network. You do not need to repeat this procedure unless you delete the vce wlan wireless network from the list. This will automatically connect you to any EWA capable network within range of your computer. extension_wireless_access.pdf Page 4
Windows Vista 1. Click the Windows Button, then right click Network and select Properties. 2. In the Network and Sharing Center window, click Manage Wireless Networks. 3. In the Manage Wireless Networks window, click Add. 4. Click Manually Create a Network Profile. 5. On the Manually connect to a wireless network window: a. Network name: vce wlan b. Security type: WPA Enterprise c. Encryption type: AES d. Check: Start this connection automatically (default) e. Click Next extension_wireless_access.pdf Page 5
6. You should see that vce wlan was successfully added as a wireless network. Next, click Change Connection Settings. 7. On the vce wlan Wireless Network properties window: a. Check: Connect Automatically when this network is in range (default) b. Check: Connect to a more preferred network if available (default) c. Click on the Security tab 8. On the vce wlan Wireless Network properties window: a. Security type: WPA2 Enterprise (default) b. Encryption type: AES (default) c. Check: Cache user information for subsequent connections to this network (default) d. Click Settings 9. In the Protected EAP Properties window: a. Check: Validate server certificate (default) b. Trusted Root Certification Authorities: Virginia Tech Root CA c. Uncheck: Do not prompt user to authorize new servers or trusted certification authorities. (default) d. Check: Enable Fast Reconnect (default) e. Click Configure extension_wireless_access.pdf Page 6
10. Uncheck: Automatically use my Windows logon name and password 11. Close all the open windows by: a. Click OK to close the EAP MSCHAPv2 Properties window b. Click OK to close the Protected EAP Properties window c. Click OK to close the vce wlan Wireless Network Properties window 12. Click Connect to in the Manually connect to a network window. 13. Select the vce wlan network under Wireless Network Connections in the list, and then click Connect. 14. Next, click anywhere in the Additional information bubble that appears in the system tray (Do NOT click the X). 15. In the Enter Credentials window: a. User name field: <your_hokies_id> b. Password field: <your_hokies_password> c. Logon domain: HOKIES d. Click OK extension_wireless_access.pdf Page 7
16. The first time you successfully connect to the vce wlan wireless network, you will see the Set Network Location dialog, click Work, then close the next dialog that appears. 17. Verify that you are connected to the wireless network by going to a webpage of your choice. You are now connected to the office network. You do not need to repeat this procedure unless you delete the vce wlan wireless network from the list. This will automatically connect you to any EWA capable network within range of your computer. extension_wireless_access.pdf Page 8
Windows 7 1. Click the Windows Button, then Control Panel 2. Click Network and Internet 3. Click on View Network Status and Tasks 4. Click on Manage wireless networks 5. In the Manage Wireless Networks window, click Add 6. The Manually Connect to a Wireless Network dialog will appear. Click Manually Create a Network Profile extension_wireless_access.pdf Page 9
7. On the Manually connect to a wireless network: a. Network name: vce wlan b. Security type: WPA Enterprise c. Encryption type: AES d. Check Start this connection automatically (default) e. Click Next 8. You should see that vce wlan was successfully added as a wireless network. Next, click Change Connection Settings 9. On the vce wlan Wireless Network properties window, Connection tab: a. Check: Connect Automatically when the network is in range (default) b. Check: Connect to a more preferred network if available c. Click the Security tab 10. On the vce wlan Wireless Network properties window, Security tab: a. Check: Remember my credentials for this connection each time I m logged on (default) b. Click Settings extension_wireless_access.pdf Page 10
11. In the Protected EAP Properties window: a. Check: Validate server certificate (default) b. Trusted Root Certification Authorities: Virginia Tech Root CA. c. Uncheck: Do not prompt user to authorize new servers or trusted certification authorities. (default) d. Check: Enable Fast Reconnect (default) e. Click Configure 12. Uncheck: Automatically use my Windows logon name and password 13. Close all the open windows by: a. Click OK to close the EAP MSCHAPv2 Properties window b. Click OK to close the Protected EAP Properties window c. Click OK to close the vce wlan Wireless Network Properties window d. Click OK to close the Manually connect to a wireless network window 14. Next, click anywhere in the Additional information bubble that appears in the system Tray (Do NOT click the X). 15. In the Windows Security dialog: a. User name field: hokies\<your_hokies_id> b. Password field: <your_hokies_password> c. Click OK extension_wireless_access.pdf Page 11
16. The first time you successfully connect to the vce wlan wireless network, you will see the Set Network Location dialog, click Work, then close the next dialog that appears. 17. Verify that you are connected to the wireless network by going to a webpage of your choice. You are now connected to the office network. You do not need to repeat this procedure unless you delete the vce wlan wireless network from the list. This will automatically connect you to any EWA capable network within range of your computer. extension_wireless_access.pdf Page 12
Mac OS 10.5/10.6 1. In the upper right hand corner, click on the WiFi icon and choose Open Network Preferences 2. Select the AirPort connection and then click Advanced. 3. Click the 802.1X tab. 4. On the Network window: Click on the + and choose Add User Profile extension_wireless_access.pdf Page 13
5. On the 802.1X window: a. Under User Profiles: vce wlan b. User Name: hokies\<your_hokies_id> c. Password: <your_hokies_password> d. Wireless Network: vce_wlan e. Uncheck: TTLS f. Check: PEAP (default) g. Click OK 6. On the Network window: a. Click Apply b. Set Network Name: vce wlan c. Once connected, click the red X to close the window 7. Verify that you are connected to the wireless network by going to a webpage of your choice. You are now connected to the office network. You do not need to repeat this procedure unless you delete the vce wlan wireless network from the list. This will automatically connect you to any EWAcapable network within range of your computer. extension_wireless_access.pdf Page 14