Cisco AIR-CB21AG-W-K9 Configuration Guide - Page 80

PEAP-GTC Connection Settings, Description, Default, Validate server certificate, Do

Page 80 highlights

Configuring PEAP-GTC Chapter 3 Configuring EAP Types Table 3-5 lists and describes PEAP-GTC connection settings. Table 3-5 PEAP-GTC Connection Settings PEAP-GTC Connection Settings Description Use anonymous outer identity Check this box to enable identity privacy protection. If this box is checked, the Outer identity field is enabled, and the outer identity in this field is used in response to an EAP identity request, which is sent in the clear. Default: On Outer identity field Enter an outer identity if the Use anonymous outer identity check box is checked. Follow an administrator's instructions, or follow RFC 4282 for guidelines about what to enter in the outer identity field. Default: anonymous Note The maximum numberl of characters allowed in this field is 256. Validate server certificate Check this box to validate the server certificate that is used to establish a tunnel. If the Validate server certificate box is checked and the Do not prompt user to authorize new servers or trusted certificate authorities box is checked, you must select one or more Trusted Root CA certificates from the list of trusted Certificate Authority certificates that are installed on the host system. If the Validate server certificate box is checked but the Do not prompt user to authorize new servers or trusted certificate authorities box is not checked, the list can be empty, and the user is prompted to validate the certificate. If authentication succeeds, then the Root CA that signed the server certificate is marked as trusted in the profile. The name of the server is then added to the Connect to only these servers field. Default: On Connect to only these servers Check this box to enter an optional server name that must match the server certificate that is presented by the server. You can enter multiple server names; separate multiple server names with semicolons. The PEAP-GTC module only allows connections to continue without prompting if the subject field (CN) or the subject alternative name in the server certificate matches the server names that you enter in this field. Default: Off Note You can use an asterisk (*) as a wildcard character in server names only if the asterisk appears before the first period (.) in the name.domain.com format. For example, "*.cisco.com" matches any server name that ends with ".cisco.com." If you put an asterisk anywhere else in the server name, it is not treated as a wildcard character. 3-26 Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista OL-16534-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

3-26
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista
OL-16534-01
Chapter 3
Configuring EAP Types
Configuring PEAP-GTC
Table 3-5
lists and describes PEAP-GTC connection settings.
Table 3-5
PEAP-GTC Connection Settings
PEAP-GTC Connection Settings
Description
Use anonymous outer identity
Check this box to enable identity privacy protection. If this box is
checked, the Outer identity field is enabled, and the outer identity in
this field is used in response to an EAP identity request, which is sent
in the clear.
Default:
On
Outer identity field
Enter an outer identity if the Use anonymous outer identity check box
is checked. Follow an administrator’s instructions, or follow
RFC 4282 for guidelines about what to enter in the outer identity
field.
Default:
anonymous
Note
The maximum numberl of characters allowed in this field
is 256.
Validate server certificate
Check this box to validate the server certificate that is used to
establish a tunnel.
If the
Validate server certificate
box is checked and the
Do not
prompt user to authorize new servers or trusted certificate
authorities
box is checked, you must select one or more Trusted Root
CA certificates from the list of trusted Certificate Authority
certificates that are installed on the host system.
If the
Validate server certificate
box is checked but the
Do not
prompt user to authorize new servers or trusted certificate
authorities
box is not checked, the list can be empty, and the user is
prompted to validate the certificate. If authentication succeeds, then
the Root CA that signed the server certificate is marked as trusted in
the profile. The name of the server is then added to the
Connect to
only these servers
field.
Default:
On
Connect to only these servers
Check this box to enter an optional server name that must match the
server certificate that is presented by the server. You can enter
multiple server names; separate multiple server names with
semicolons. The PEAP-GTC module only allows connections to
continue without prompting if the subject field (CN) or the subject
alternative name in the server certificate matches the server names
that you enter in this field.
Default:
Off
Note
You can use an asterisk (*) as a wildcard character in server
names only if the asterisk appears before the first period (.) in
the name.domain.com format. For example, “*.cisco.com”
matches any server name that ends with “.cisco.com.” If you
put an asterisk anywhere else in the server name, it is not
treated as a wildcard character.