Cisco AIR-CB21AG-W-K9 Configuration Guide - Page 69

Authentication Settings, Description, Default, one-time password, a certificate on this computer

Page 69 highlights

Chapter 3 Configuring EAP Types Configuring EAP-FAST Table 3-3 Authentication Settings Authentication Settings Select an authentication method Description Select the inner tunnel EAP method from the drop-down list. Available methods are EAP-GTC, EAP-MSCHAPv2, EAP-TLS, and Any Method. The Any Method option allows the EAP-FAST module to choose any of the supported methods that the EAP server requests. The method must also be appropriate to the user credentials that are used. Default: Any Method Note EAP-GTC is the only option available if you selected the Use one-time password radio button in the User Credentials tab. Note EAP-TLS is the only option available if you selected the Use a certificate on this computer radio button in the User Credentials tab. Configure Enable fast reconnect Enable posture validation Note The use of the Any Method value to allow all methods is unsupported by Cisco or Microsoft and is not recommended. This configuration is used "as-is"; Cisco makes no guarantee that there will not be adverse performance to the system if unsupported methods are used. Unsupported methods should never be used in a production environment. Click the Configure button to configure EAP-TLS options. This option is available only if EAP-TLS is the selected authentication method. When you click this button, the standard Windows Vista EAP-TLS Properties Screen appears. Default: Disabled Check this box to allow session resumption. The EAP-FAST module supports fast reconnect (also called session resumption) by using the User Authorization PAC. When you enable fast reconnect, you can roam or return from suspend mode without re-entering your credentials. Fast reconnect can be used across different network access servers. Default: On Note If you switch profiles, logs off, or reboot, fast reconnect is not attempted. You must be reauthenticated. Check this box to allow the health information of the host machine to be queried. Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista OL-16534-01 3-15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

3-15
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista
OL-16534-01
Chapter 3
Configuring EAP Types
Configuring EAP-FAST
Table 3-3
Authentication Settings
Authentication Settings
Description
Select an authentication
method
Select the inner tunnel EAP method from the drop-down list.
Available methods are EAP-GTC, EAP-MSCHAPv2, EAP-TLS, and
Any Method.
The Any Method option allows the EAP-FAST module to choose any
of the supported methods that the EAP server requests. The method
must also be appropriate to the user credentials that are used.
Default:
Any Method
Note
EAP-GTC is the only option available if you selected the
Use
one-time password
radio button in the User Credentials tab.
Note
EAP-TLS is the only option available if you selected the
Use
a certificate on this computer
radio button in the User
Credentials tab.
Note
The use of the Any Method value to allow all methods is
unsupported by Cisco or Microsoft and is not recommended.
This configuration is used “as-is”; Cisco makes no guarantee
that there will not be adverse performance to the system if
unsupported methods are used. Unsupported methods should
never be used in a production environment.
Configure
Click the
Configure
button to configure EAP-TLS options. This
option is available only if EAP-TLS is the selected authentication
method. When you click this button, the standard Windows Vista
EAP-TLS Properties Screen appears.
Default:
Disabled
Enable fast reconnect
Check this box to allow session resumption.
The EAP-FAST module supports fast reconnect (also called session
resumption) by using the User Authorization PAC. When you enable
fast reconnect, you can roam or return from suspend mode without
re-entering your credentials. Fast reconnect can be used across
different network access servers.
Default:
On
Note
If you switch profiles, logs off, or reboot, fast reconnect is not
attempted. You must be reauthenticated.
Enable posture validation
Check this box to allow the health information of the host machine to
be queried.