
Step 2 of 2: TTLS Server
1. Select one of the following credential retrieval methods:
Validate Server Certificate or Specify
Server or Certificate Name.
2. Click OK to save the setting and close the page.
Create a Windows XP* Profile with PEAP Network Authentication
PEAP authentication: PEAP settings are required for the authentication of the client to the authentication
server. The client uses EAP-TLS to validate the server and create a TLS-encrypted channel between client
and server. The client can use another EAP mechanism, such as Microsoft Challenge Authentication
Protocol (MS-CHAP) Version 2, over this encrypted channel to enable server validation. The challenge and
response packets are sent over a non-exposed TLS encrypted channel. The following example describes
how to use WPA with AES-CCMP or TKIP encryption with PEAP authentication.
To set up a client with PEAP Authentication: Obtain and install a client certificate. See
Create a Windows
XP* Profile for TLS authentication or consult your administrator.
1. Click Profiles on the WiFi connection utility main window. Or if you are acting as the administrator,
open the
Administrator Tool.
2. On the Profiles list, click Add to open the Create WiFi Profile General Settings.
3. Profile Name: Enter a descriptive profile name.
4. WiFi Network Name (SSID): Enter the network identifier.
5. Operating Mode: Click Network (Infrastructure). (This parameter is set to Infrastructure if you
are using the Administrator Tool.)
6. Administrator Profile Type: Select
Persistent or Pre-logon/Common. (This step applies only if you
are using the Administrator Tool.)
7. Click Next to open the Security Settings.
8. Click Enterprise Security.
9. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise (Recommended).
10. Data Encryption: Select one of the following:
AES-CCMP is recommended.
11. Enable 802.1X: Selected by default.
12. Authentication Type: Select PEAP to be used with this connection.
Step 1 of 2: PEAP User
PEAP relies on Transport Layer Security (TLS) to allow unencrypted authentication types such as EAP-
Generic Token Card (GTC) and One-Time Password (OTP) support.
1. Authentication Protocol: Select either
GTC, MS-CHAP-V2 (Default), or TLS. See Authentication
Protocols.
2. User Credentials: Select one of the following:
Use Windows logon, Prompt each time I connect, or
Use the following.
3. Roaming Identity: A Roaming Identity may be populated in this field or you can use %domain%\%
username% as the default format for entering a roaming identity.
Comentarios a estos manuales