Netgear WFS709TP WFS709TP Setup Manual - Page 128

Configuring 802.1x Authentication, EAP-Generic Token Card GTC: Described in RFC 2284

Page 128 highlights

WFS709TP ProSafe Smart Wireless Switch Software Administration Manual In this scenario, the supplicant must be configured for Protected EAP (PEAP), as the WFS709TP only supports PEAP. PEAP uses Transport Layer Security (TLS) to create an encrypted tunnel. Within the tunnel, one of the following EAP methods is used: • EAP-Generic Token Card (GTC): Described in RFC 2284, this EAP method permits the transfer of unencrypted usernames and passwords from client to server. The main uses for EAP-GTC are one-time token cards such as SecureID and the use of an LDAP or RADIUS server as the user authentication server. You can also enable caching of user credentials on the WFS709TP as a backup to an external authentication server. • EAP-Microsoft Challenge Authentication Protocol version 2 (MS-CHAPv2): Described in RFC 2759, this EAP method is widely supported by Microsoft clients. A RADIUS server must be used as the backend authentication server. Note: You must install a server certificate in the WFS709TP for AAA FastConnect, as described in "Installing a Server Certificate" on page 13-19. If you are using the WFS709TP's internal database for user authentication, you need to add the names and passwords of the users to be authenticated. If you are using an LDAP server for user authentication, you need to configure the LDAP server on the WFS709TP, and configure user IDs and passwords. If you are using a RADIUS server for user authentication, you need to configure the RADIUS server on the WFS709TP. Configuring 802.1x Authentication On the WFS709TP, use the following steps to configure a wireless network that uses 802.1x authentication: 1. Configure the 802.1x RADIUS authentication server. Note: If you are using EAP-GTC within a PEAP tunnel, you can configure either an LDAP or a RADIUS server as the authentication server. If you are using AAA FastConnect, you can use a non-802.1x server or the WFS709TP's internal database. See Chapter 6, "Configuring AAA Servers". 2. Configure 802.1x authentication. See "802.1x Authentication Page" on page 7-5. 3. Configure the VLANs to which the authenticated users will be assigned. See Chapter 3, "Configuring Network Parameters". 7-4 Configuring 802.1x Authentication v1.0, June 2007

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222

WFS709TP ProSafe Smart Wireless Switch Software Administration Manual
7-4
Configuring 802.1x Authentication
v1.0, June 2007
In this scenario, the supplicant must be configured for Protected EAP (PEAP), as the WFS709TP
only supports PEAP. PEAP uses Transport Layer Security (TLS) to create an encrypted tunnel.
Within the tunnel, one of the following EAP methods is used:
EAP-Generic Token Card (GTC): Described in RFC 2284, this EAP method permits the
transfer of unencrypted usernames and passwords from client to server. The main uses for
EAP-GTC are one-time token cards such as SecureID and the use of an LDAP or RADIUS
server as the user authentication server. You can also enable caching of user credentials on the
WFS709TP as a backup to an external authentication server.
EAP-Microsoft Challenge Authentication Protocol version 2 (MS-CHAPv2): Described in
RFC 2759, this EAP method is widely supported by Microsoft clients. A RADIUS server must
be used as the backend authentication server.
If you are using the WFS709TP’s internal database for user authentication, you need to add the
names and passwords of the users to be authenticated. If you are using an LDAP server for user
authentication, you need to configure the LDAP server on the WFS709TP, and configure user IDs
and passwords. If you are using a RADIUS server for user authentication, you need to configure
the RADIUS server on the WFS709TP.
Configuring 802.1x Authentication
On the WFS709TP, use the following steps to configure a wireless network that uses 802.1x
authentication:
1.
Configure the 802.1x RADIUS authentication server.
2.
Configure 802.1x authentication. See
“802.1x Authentication Page” on page 7-5
.
3.
Configure the VLANs to which the authenticated users will be assigned. See
Chapter 3,
“Configuring Network Parameters”
.
Note:
You must install a server certificate in the WFS709TP for AAA FastConnect,
as described in
“Installing a Server Certificate” on page 13-19
.
Note:
If you are using EAP-GTC within a PEAP tunnel, you can configure either an
LDAP or a RADIUS server as the authentication server. If you are using AAA
FastConnect, you can use a non-802.1x server or the WFS709TP’s internal
database. See
Chapter 6, “Configuring AAA Servers”
.