How to Connect to the Secure Wi-Fi Network AKK / SCS Version 1.31 1/8/2010
Prerequisites: How to Connect to the Secure Wi-Fi Network Connecting to the Secure Wi-Fi network requires a NetID and password. You can obtain your NetID and password at http://neiuport.neiu.edu by clicking on the Look up your NetID and E-Mail Address link from the main NEIUport web Page 2 of 14. If you have Windows XP Service Pack 2 (SP2), install the Wireless Client Update for Windows XP SP2: http://support.microsoft.com/kb/917021. This update will add WPA2 support to your computer. This is a free update from Microsoft. Users of Windows XP SP3 do not require this update. Download and install the latest SecureW2 EAP Suite (v2.0.6) software from the following location: http://www.securew2.com. Important Information: This document was written specifically for users of Windows XP Service Pack 3 (SP3) and users of Windows XP Service Pack 2 (SP2) with the Wireless Client Update for Windows XP SP2. While some menus may appear visually different, the methodology and configuration of the SecureW2 EAP Suite to connect to the secure Wi-Fi network at NEIU should operate similarly for users of Windows Vista and Windows 7. It is recommended that you install Windows XP Service Pack 3 (SP3) for maximum compatibility, security, and Wi-Fi connectivity. Features in SP3 improve the speed and functionality of Wi-Fi greatly over those in SP2. As of this writing, the NEIU Secure Wi-Fi network uses WPA2 (Wireless Protected Access 2) with AES (Advanced Encryption Standard) encryption. Should this change in the future, it will be reflected in this document. As of this writing, the SecureW2 EAP Suite is version 2.0.6 and is the most current version of the SecureW2 software suite. This document is written using this version of the SecureW2 EAP Suite. SCS neither manages nor maintains the Wi-Fi network at NEIU but does provide this document as a helpful resource to students who wish to take advantage of the secure Wi-Fi network. 3 rd party applications from Intel, Broadcom, or other vendors may take control of the Wi-Fi adapter built into your computer and not allow you to follow these instructions. Be sure to only allow the Microsoft Wireless Configuration software to manage your Wi-Fi adapter. Questions regarding this document should be directed to: Student Computing Services, Room B107 Web: http://www.neiu.edu/~scs E-Mail: scs@neiu.edu Main Office: (773) 442-4390 2
Table of Contents How to Connect to the Secure Wi-Fi Network... 2 o Prerequisites... 2 o Important Information... 2 Table of Contents... 3 Getting Started... 4 o Wireless Network Connection Manager... 4 o Wireless Network Connection Properties... 5-6 The SecureW2 EAP Suite... 7 o Configuring the SecureW2 EAP Suite... 8-9 Logging on to the Secured_WPA2 Wi-Fi Network... 10 o Username and Password Prompt o Installing the Secured_WPA2 Certificate... 10-11 Troubleshooting... 11 3
Getting Started Before you begin, ensure that you have downloaded and installed the Wireless Client Update for Windows XP SP2 (detailed on Page 2). It is freely available at the following link http://support.microsoft.com/kb/917021. Windows XP users who have SP3 installed do not need this update. You must also install the SecureW2 EAP Suite software and reboot your computer before continuing further. Configuring the Secure W2 EAP Suite Begin by clicking on the Wireless Network Connection icon ( Connection Manager as is shown below. ) in the System Tray to bring up the Wireless Network You should see both the Unsecured and Secured_WPA2 networks appear. Select the Secured_WPA2 network connection and then click on the Change Advanced Settings link. 4
Wireless Network Connection Manager: Advanced Settings Clicking on the Change Advanced Settings link should have opened the Wireless Network Connection Properties window as is shown below. Both the Unsecured and Secured_WPA2 networks should be visible. If not, you may need to return to the Wireless Network Connection manager and refresh ( ) the network lists. Use Windows to configure my wireless network settings should be checked on. When 3 rd party software takes control of your Wi-Fi adapter, they un-check this option. Select the Secured_WPA2 network from the list of preferred networks and click on the Properties button. Wireless Network Connection Properties: Association After clicking on the Properties button, you should now see the Secured_WPA2 Properties window as is shown on the left. Network Authentication should be set to WPA. Data Encryption should be set to AES. All other settings should be left alone. Click on the Authentication tab to continue. 5
Wireless Network Connection Properties: Authentication The Authentication tab will show a drop-down list detailing some EAP Types. Select SecureW2 EAP-TTLS from the list. By default, Authenticate as computer when computer information is available is already checked on. All other options should remain unchanged. Continue on by clicking on the Connection tab. Wireless Network Connection Properties: Connection The Connection tab will give you the option of automatically connecting to the Secured_WPA2 network whenever your computer or Wi-Fi adapter detects that it is in range. By default this option is checked on but you may un-check it as a mater of personal preference. If you aren t sure, leave this option alone. Now, return to the Authentication tab and continue to the next page. 6
The SecureW2 EAP Suite Once back at the Authentication tab of the Secured_WPA2 properties window (see page 6), you will want to click on the Properties button below SecureW2 EAP-TTLS. This will open the SecureW2 EAP Suite windows as is shown below. The main screen of the SecureW2 EAP Suite appears as is show to the left. You will use the Default profile settings. To continue, click on the Configure button. Configuring the SecureW2 EAP Suite The following tabs will be shown when the Configure button (from above) is pressed: Connection, Certificates, Authentication, and User Account. Ensure that your settings match this and the following screens on the next page exactly. Changing the options could cause your login to fail. 7
Configuring the SecureW2 EAP Suite Click on each of the remaining tabs and ensure your settings match the images below. By default, these options should already be set for you. If they are different, ensure the options are set exactly as the images show. When your settings match, click the Advanced button and proceed to the next page. 8
Configuring the SecureW2 EAP Suite: Advanced Options After clicking on the Advanced button from the SecureW2 EAP Suite configuration screen, you will see the SecureW2 Configuration Advanced window as is shown below. By default, all of the options will be un-checked. You will want to check on the box that says Allow users to setup new connections. After you do this, click the OK button. This will bring you back to the Configuration window. Click OK again to return to the main SecureW2 EAP Suite screen. Click OK one last time to exit. Note: If you receive a message that states You have not configured any trusted root CA. Secure W2 Will use the current Windows Certificate Trust. Continue?, you can click OK and continue. The CA (Certificate Authority) is covered on page 10. You should now be back to the Secured_WPA2 Properties windows. Click OK to save all the configuration changes. This will return you to the Wireless Network Connections Properties window (top of page 5). Click OK to save all changes and exit. Testing the Connection to the Secured_WPA2 After following all of the above steps carefully, you should now be ready to connect to the Secured_WPA2 Wi-Fi network. Remember that you will need your NetID and a password in order to log on successfully. Click on the Wireless Network Connection icon ( ) in the System Tray and bring up the Wireless Connection Manager (from page 4) and select the Secured_WPA2 network. Once Secured_WPA2 is selected, click on the Connect button. You should see a Balloon Tip appear above the Wireless Network Connection icon as is shown below. You should see the Balloon Tip as is shown on the right. If not, it s possible you have Balloon Tips turned off. Use a search engine and find Enable Notification Area Balloon Tips. Click on the Balloon Tip and continue to the next page. 9
Logging on to the Secured_WPA2 Wi-Fi Network When you click the Balloon Tip for the first time, you will be presented with the SecureW2 login screen as is shown below. Enter your NEIU NetID and password into the appropriate boxes. Leave the box titled Domain blank. Enter your NEIU NetID into the Username box and password into Password box. Note: Leave the box titled Domain blank. Click OK to continue. For security reasons, it is recommended that you do not check the box for Save user credentials. Secured_WPA2 Certificate Prompt After clicking OK to log on to the Secured_WPA2 Wi-FI network, you will see a second Balloon Tip appear asking you to select a Certificate. If you have Balloon Tips disabled, you will not be able to continue to the next step. You should see the second Balloon Tip appear as is shown on the right. Click on the Balloon Tip and you will be presented with a window and a prompt to accept a Secure Wireless CA certificate. Selecting and Installing the Secured_WPA2 Certificate Click on the certificate called NEIU Wireless CA and press the Install Certificate button. This secure Wi-Fi certificate is issued from the NEIU Wireless CA (Certificate Authority)*. * The NEIU Secure Wireless Certificate is set to expire on 2/2/2011 and may require you to accept a new certificate after this date to connect to the secure wireless network. 10
Selecting and Installing the Secured_WPA2 Certificate If successful, you should see a message stating the Certificate was installed successfully. Click OK to dismiss the message and click OK again to finish logging on to the Secured_WPA2 Wi-Fi network. Troubleshooting If you ve followed all of the directions above and are still having problems, it s possible that you need to update the driver and software for your Wi-Fi adapter. Visit your computer manufacturer s web site and see if there are any available driver updates for the Wi-Fi adapter in your computer. You should ensure that your computer is fully up to date with all of the available patches, security updates, and hardware updates from the Windows Update web site. Always be sure to run Windows Update and install all the critical updates. It is highly recommended that Windows XP SP3 be installed for maximum compatibility with current Wi-Fi standards. If the computer fails to install the NEIU Wireless Client certificate, you may have to un-install the SecureW2 EAP Suite software, restart your computer, and re-install the SecureW2 EAP Suite software and try again beginning on page 4. If you had a previous version of the SecureW2 Suite installed and are upgrading to a more current version, you may already have the NEIU Wireless CA certificate installed in which case you must uninstall it. To uninstall the certificate, go to your Control Panel > Internet Options > Content > Certificates > Trusted Root Certification Authorities. Scroll down and click on NEIU Wireless CA and click the Remove button. Close the Internet Options window and re-install the NEIU Wireless CA certificate (per the instructions on page 10). If the computer fails to log in, you may need to verify that your NetID and password were entered correctly. Return to the steps on page 9 and try again. If it continues to fail, verify that your NetID and password are correct by logging on to NEIUport. If you are able to log onto NEIUport without a problem, there may be a configuration setting for the SecureW2 EAP Suite that was not set correctly. Verify the settings for the SecureW2 EAP Suite by starting on page 4 and follow the configuration steps on the subsequent pages. If you have Windows XP Service Pack 2 (SP2), install the Wireless Client Update for Windows XP SP2: http://support.microsoft.com/kb/917021. This update will add WPA2 support to your computer. This is a free update from Microsoft. Users of Windows XP SP3 do not require this update. If you have followed all of the aforementioned directions and can establish a connection to NEIU s access point, you may change your connection settings. Oftentimes the DNS setting must be changed to automatic, this allows for a dynamic IP assignment; which in turn grants internet access. 11
How to configure your PC to automatically obtain a DNS server address The following step by step instructions will show you how to familiarize your computer with NEIU s DNS servers automatically. In cases where you computer can connect to the access point but not the internet, these steps will likely correct the issue. Windows XP users should follow these steps: 1. Click Start, locate and click on the Control Panel. 2. Depending on how your control panel is configured you will either first click A and then on the following screen click B, or simply B. 3. Next, right click on your wireless connection, and select properties from the dropdown menu. 4. After clicking properties, double click on Internet Protocol (TCP/IP) 12
5. On the resultant window, ensure that each of the following options is selected: Obtain an IP address automatically, and Obtain DNS Server address automatically. It should look like the following image. 6. Lastly click OK on both this and the previous windows, to put the changes into effect. 7. Test your internet connection. Windows Vista users should follow these steps: 1. Click the windows button and locate the search/run text box. 2. Type network this should bring up a few results, find and click Network and sharing center. 3. Click on Manage network connections, it is located along the left side of the network and sharing center window. 4. Double click on your wireless connection and on the window that pops up - select Properties. 5. Click Continue when or if Vista pops up a warning window. The changes we are making are not potentially harmful. 13
6. When you see the window pictured below, double click on Internet Protocol Version 4 (TCP/IPv4). 7. On the resultant window, ensure that each of the following options is selected: Obtain an IP address automatically, and Obtain DNS Server address automatically. It should look something like the following image. 8. Lastly click OK on both this and the previous windows, to put the changes into effect. 9. Test your internet connection. AKK / SCS 14