Windows PEAP-GTC Supplicant Plug-In



Similar documents
How to connect to the diamonds wireless network with Vista.

Configuring Eduroam in Windows Vista

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

Eduroam wireless network Windows Vista

CruzNet Secure Set-Up Instructions for Windows Vista

Installation Guides - Information required for connection to the Goldfields Institute s (GIT) Wireless Network

How to Access Coast Wi-Fi

Instructions for connecting to the FDIBA Wireless Network. (Windows XP)

Windows Vista and Windows 7 Wireless Configuration For NCC Faculty and Staff Owned Laptops

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows 7

Connecting to Secure Wireless (iitk-sec) on Fedora

Wireless Network Configuration Guide

User Guide for eduroam

INFORMATION SYSTEMS SERVICE NETWORKS AND TELECOMMUNICATIONS SECTOR

Network Services One Washington Square, San Jose, CA

Connec ng to Northwest s WIFI with Windows 7

Windows Vista: Connecting to the wireless network at Hood College

Connecting to the Rovernet WPA2 Secured Wireless Network with Windows 7

Configuring Windows 7 to Use Encrypted (WPA-E) Wireless Services a...

Connecting to UNOSECURE using Windows 7

Configuring WPA-Enterprise/WPA2 with Microsoft RADIUS Authentication

Windows 8 & RT Wireless Configuration For NCC Student Owned Laptops

Instructions for connecting to the LSC-O Secure Wireless Network

Setting up Windows XP for WPA Wireless Access (ISU-OIT-WPA)

How To Connect To A Wireless Network On Windows 7 (Windows 7) On A Pc Or Mac Or Ipad (Windows) On Pc Or Ipa (Windows 8) On Your Computer Or Mac (Windows). (Windows.7) On An

How to connect to NAU s WPA2 Enterprise implementation in a Residence Hall:

Defender EAP Agent Installation and Configuration Guide

Connecting to the University Wireless Network

Using WPA Enterprise on Windows XP to Access Cleveland State University s Wireless Network (WoWnet)

802.1X Client Software

How To Set Up Isu-Oit-Wpa On Windows 7 For Wireless Access (Isu- Oit- Wpa) On A Pc Or Mac Or Ipa (Windows 7) On An Ipa Or Ipac (Windows

How to connect to VUWiFi

Configuring WPA2 for Windows XP

6. After connecting reopen the wireless connections window. Right click on RamNet and select properties. Page 2 of 7

WIRELESS SETUP GUIDES FOR WINDOWS 8

Airnet-Student is a new and improved wireless network that is being made available to all Staffordshire University students.

Management Authentication using Windows IAS as a Radius Server

ICT DEPARTMENT. Windows 7. Wireless Authentication Procedures for Windows 7 & 8 Users For Linux and windows XP users visit ICT office

How To Set Up Hopkins Wireless On Windows 7 On A Pc Or Mac Or Ipad (For A Laptop) On A Network Card (For Windows 7) On Your Computer Or Ipa (For Mac Or Mac) On An Ipa Or

WIRELESS SETUP FOR WINDOWS 7

Instructions for connecting to winthropsecure. Windows 7/8 Quick Connect Windows 7/8 Manual Wireless Set Up Apple Quick Connect Apple Settings Check

Automatic Setup... 1 Manual Setup... 2 Installing the Wireless Certificates... 18

Wireless LAN Client Configuration Guide for Windows Configuring 802.1X Authentication Client for Windows 7

AeroLab Wireless Network Code of Conduct. Connecting to the AeroLab Wireless Network

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows Vista

eduroam wireless setup guide for Windows 7, XP and Vista

Manual Configuration Instructions

How to install and use the File Sharing Outlook Plugin

Extension Wireless Access (EWA) v2.0

Johns Hopkins

How to configure 802.1X authentication with a Windows XP or Vista supplicant

Windows XP Exchange Client Installation Instructions

IT Quick Reference Guides Connecting to SU-Secure using Windows 8

Canterbury College Eduroam Wi-Fi Guide

WiFi troubleshooting. How s your WiFi signal? Android WiFi settings. ios WiFi settings

How to Connect to UAB s Wireless Networks

Edith Cowan University Information Technology Services Centre

Connecting to eduroam using Windows 8

KU Information Technology provides wireless access for both the KU campus community and for guest users at many points across campus.

Connect to the Sheridan College / Gillette College - STUDENT Secure Wireless Network with the PEAP Client (Windows XP Pro)

Internet Access: Wireless WVU.Encrypted Network Connecting a Windows 7 Device

How to set up Outlook Anywhere on your home system

INTRODUCTION... 2 Windows Windows Mac OS X Ubuntu Advanced routing Windows Mac OS X Ubuntu...

RSC-Secure-Wireless provides...

Wireless Setup for Windows 8

Manually Configuring Windows Vista for Wireless PittNet

Securing Wireless LANs with LDAP

UCO_SECURE Wireless Connection Guide: Windows 8

Configuring Eduroam on Microsoft Windows Vista and 7 (all editions, 32 and 64 bits)

Eduroam wireless network - Windows 7

WIRELESS FUSION ENTERPRISE MOBILITY SUITE USER GUIDE FOR VERSION H3.40

Mac OS X Secure Wireless Setup Guide

IMAP and SMTP Setup in Clients

Massey University Wireless Network Client Configuration Windows 7

GPC JagTalk Secure Wireless Network. Connection Instructions

Guide to Configuring the UHU Wireless Network for Windows Vista

Video Administration Backup and Restore Procedures

Setting up SJUMobile (Wireless Internet Access for personal devices)

How to Setup PPTP VPN Between a Windows PPTP Client and the DIR-130.

Sample. Configuring the RADIUS Server Integrated with ProCurve Identity Driven Manager. Contents

Configure WorkGroup Bridge on the WAP131 Access Point

How to Configure Outlook Client for Exchange

Pulse Policy Secure. Layer 2 and the Pulse Policy Secure Series RADIUS Server. Product Release 5.1. Document Revision 1.0 Published:

Eduroam wireless network Apple Mac OSX 10.5

Global VPN Client Getting Started Guide

Step-by-step Guide for Configuring Cisco ACS server as the Radius with an External Windows Database

Creating and Installing a Self Signed Certificate for PEAP/EAP-TLS Authentication

The back story of our Wireless (reading will help you understand what is going on in the building):

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

vwlan External RADIUS 802.1x Authentication

Instructions for accessing the new TU wireless Network

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

PEAP-TLS: Microsoft Supplicant configuration (Windows 7) and Aruba ClearPass

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

Eduroam wireless network Apple Mac OSX 10.4

Wi- Fi settings for Windows XP

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

1. Open Thunderbird. If the Import Wizard window opens, select Don t import anything and click Next and go to step 3.

Transcription:

Windows PEAP-GTC Supplicant Plug-In Configuration Guide This document describes the installation and configuration of a supplicant plug-in that supports Protected Extensible Authentication Protocol (PEAP) with EAP-Generic Token Card (GTC) authentication for Windows clients. This software can only be installed and used in conjunction with an Aruba Mobility Controller with the AAA FastConnect (EAP Termination) feature enabled. This software supports 32-bit and 64-bit versions of Windows XP, Windows Vista, and Windows 7. This document describes the following topics: Overview on page 1 Installing the Supplicant Plug-In Software on page 1 Configuring PEAP with EAP-GTC on the Windows Client on page 2 Log Files on page 6 NOTE PEAP with EAP-GTC is only supported on Aruba Mobility Controllers running ArubaOS version 2.5.4 or later. The Mobility Controller administrator must enable the AAA FastConnect feature and configure EAP-GTC as the inner EAP type, as described in the ArubaOS User Guide. Overview The Extensible Authentication Protocol (EAP) type Protected EAP (PEAP) uses Transport Layer Security (TLS) to create an encrypted tunnel. Within the TLS tunnel, the client can be authenticated using one of the following inner EAP methods: EAP-Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAPv2): Described in RFC 2759, this EAP method is widely supported by Microsoft clients. This is the default method and is supported by ArubaOS 2.5.1 and later. EAP-Generic Token Card (GTC): Described in RFC 2284, this EAP method permits the transfer of unencrypted usernames and passwords from client to server. The main uses for EAP-GTC are one-time token cards such as SecureID and the use of LDAP or RADIUS as the user authentication server. You can also enable caching of user credentials on the controller as a backup to an external authentication server. This method is supported by ArubaOS 2.5.4 and later. The current Wireless Zero Configuration (WZC) under Windows only supports PEAP with EAP-MS- CHAPv2. To use PEAP with EAP-GTC authentication in your wireless network, you need to install and configure the Aruba supplicant plug-in software on your Windows clients. Installing the Supplicant Plug-In Software Download the software for the PEAP with EAP-GTC supplicant plug-in from the Aruba Networks support website. Versions are available for both 32-bit and 64-bit Windows. Install the software by opening the installer package on a Windows client and following the instructions in the InstallShield Wizard shown in Figure 1. rev 2.0 November 2010 1

Figure 1 The InstallShield Wizard h Configuring PEAP with EAP-GTC on the Windows Client This section describes how to configure PEAP with EAP-GTC on a Windows client after you install the supplicant plug-in software. 1. On the Windows client, open the Network and Sharing Center window shown Figure 2. Figure 2 Network and Sharing Center 2. Click Manage Wireless Networks. 3. In the Manage Wireless Networks window shown in Figure 3, click Add. 2 Windows PEAP-GTC Supplicant Plug-In Configuration Guide

Figure 3 The Manage Wireless Networks Window 4. Click on the Manually create a network profile option shown in Figure 4. Figure 4 Manually Create a Profile 5. Enter the following information into the Wireless Network Information window shown in Figure 5: Network name: Enter the network SSID Security type: Select WPA2-Enterprise, WPA-Enterprise, or 802.1x from the drop-down list. Encryption type: Select AES, TKIP, or WEP from the drop-down list. Windows PEAP-GTC Supplicant Plug-In Configuration Guide 3

Figure 5 Configure Wireless Network Information 6. Click Next. 7. Select the Change connection settings option shown in Figure 6. Figure 6 Change Connection Settings 8. The Wireless Network properties dialog box appears with the Connection tab selected, as shown in Figure 7. Click on the Security tab. 4 Windows PEAP-GTC Supplicant Plug-In Configuration Guide

Figure 7 Wireless Network Properties 9. Select Protected EAP from the Choose a network authentication method drop-down menu shown in Figure 8. Figure 8 Select Protected EAP NOTE While EAP-GTC (EAP token) appears in both the inner and outer authentication method lists, it should only appear in the inner method list. This is a bug in Windows Vista. If you see this issue, check with Microsoft for a possible fix. 10. Click on Settings to display the Protected EAP Properties dialog box shown in Figure 9. Windows PEAP-GTC Supplicant Plug-In Configuration Guide 5

Figure 9 Protected EAP Properties 11. Select EAP Token from the Select Authentication Method drop-down list. NOTE When you select EAP Token as the authentication method, no dialog box is displayed if you click on the Configure button. 12. Click OK. Log Files The supplicant plug-in software logs authentication events to the Windows tracing directory located at \Windows\Tracing\eap-gtc.log. Inspecting the log file is normally not necessary; however, if there is a problem with client authentication, you can view the log file with a text editor. To enable logging, access the Windows command-line interface (command.exe) and issue the following command: Netsh ras set tracing eap-gtc enable To disable logging, access the Windows command-line interface and issue the command: Netsh ras set tracing eap-gtc disable The following messages in the log file indicate a successful client authentication (messages are preceded by the date and time of the event): RasEapMakeMessage :: Got EAPCODE_success RasEapMakeMessage :: Authentication succeeded The following messages in the log file indicate a client authentication failure because the wrong password was entered for the authentication: RasEapMakeMessage :: Got EAPCODE_failure RasEapMakeMessage :: Authentication failed. Wrong password. 6 Windows PEAP-GTC Supplicant Plug-In Configuration Guide

The following messages in the log file indicate that the AAA FastConnect feature is not enabled on the Mobility Controller: RasEapMakeMessage :: Got EAPCODE_Request RasEapMakeMessage :: AAA FastConnect (dot1x termination) is not enabled on the Aruba switch www.arubanetworks.com 1344 Crossman Avenue Sunnyvale, California 94089 2010 Aruba Networks, Inc. All rights reserved. Phone: 408.227.4500 Fax 408.227.4550 7 Windows PEAP-GTC Supplicant Plug-In Configuration Guide