802.1X Wireless Test Setup

802.1X Wireless Test Setup

<p>Don Berry Microsoft Corporation Phone 425.936.8418 Microsoft One Microsoft Way [email protected] Redmond, WA 98052</p><p>802.1x Wireless Test Setup</p><p>Implementing and testing of 802.1x using Microsoft Windows XP</p><p>DC DHCP DNS RRAS IIS IAS Client CA</p><p>Server</p><p> Figure 1: Test Setup Configuration without AP</p><p>Chapter 1 Overview</p><p>Note: Please ensure that client and server computer make and model are listed on the Windows 2000 Hardware Compatibility List. http://www.microsoft.com/hcl </p><p>Creating Parent Domain</p><p>Install Windows XP Server Family: 1. Cycle through different OS versions: (srv, dtc, ent) 2. Select different file systems on install (FAT, FAT32, NTFS) Note: If you are using anything other that NTFS you must convert the file system before you promote this computer to a Domain Controller (ex. Convert c: /fs:ntfs)</p><p>Promote your computer to a Domain Controller: 1. Open a command window and type dcpromo; this will invoke the Active Directory Installation Wizard Click NEXT.</p><p>.</p><p>802.1X SETUP INSTRUCTIONS</p><p>2. Select: Domain Controller for new domain. Click NEXT.</p><p>2 802.1X SETUP INSTRUCTIONS</p><p>3. Select: Create a new domaintree. Click NEXT.</p><p>4. Select: Create a new forest of domain trees. Click NEXT.</p><p>3 802.1X SETUP INSTRUCTIONS</p><p>5. Installing DNS (if required)</p><p>6. Enter the FQDN: (ex. MyDomain.nttest.Microsoft.com). Click NEXT. Note: The domains NETBIOS name will be displayed. Click NEXT.</p><p>4 802.1X SETUP INSTRUCTIONS</p><p>7. The installation wizard will now prompt for an Active Directory database and log file location. Click NEXT.</p><p>8. The installation wizard will now require a Shared System Volume Location. Note: This location must be on an NTFS Partition. Click NEXT.</p><p>5 802.1X SETUP INSTRUCTIONS</p><p>9. Select: Permissions compatible with pre-Windows 2000 servers. Click NEXT. </p><p>6 802.1X SETUP INSTRUCTIONS</p><p>10. Enter a Directory Services Restore Mode Administrator Password. Click NEXT. Click NEXT. Click FINISH. Note: The computer will now begin configuring and promoting your computer to a domain controller.</p><p>11. Active Directory Wizard will display database and log file settings. Click NEXT to continue.</p><p>7 802.1X SETUP INSTRUCTIONS</p><p>12. Active Directory Installation complete. Click FINISH.</p><p>13. Active Directory Installation requires reboot. Click RESTART NOW.</p><p>Configuring DHCP server</p><p>1. Get a server with Whistler Server Build 2438, or higher on it. 2. Assign the server a static IP address. Example:10.0.0.1 3. Install DHCP server. 4. Create a single scope. – e.g. 10.0.0.10 through 10.0.0.254 5. Ensure that the DHCP server is authorized and scope is activated. 6. This ensures DHCP server is up and running fine and giving out addresses.</p><p>Ensure clients on the private wired network get addresses from the server. </p><p>8 802.1X SETUP INSTRUCTIONS</p><p>Configuring Active Directory</p><p>For the Domain Controller, we need to configure so that passwords are stored in reversible encrypted format for all users. This is required for EAP-MD5 login.</p><p>Go to Active Directory for Users and Computers Start > Programs > Administrative Tools > Active Directory Users and Computers > Domain name > Action > Properties</p><p>From the properties screen, click the Group Policies tab. Highlight the “Default Domain Policy” and click edit.</p><p>9 802.1X SETUP INSTRUCTIONS</p><p>Create a user. Be sure to allow dial up access, and on the account tab, check the box to store passwords reversibly encrypted. Make the user an administrator on the client, also. Configuring Certificate Server Templates</p><p>INSTALLING, CONFIGURING ENTERPRISE CERTIFICATE TEMPLATES</p><p>Installing Enterprise Certificate Templates for the first time </p><p>Invoke Certificate Template Management Console. 1. Click: Start  Run  Enter: certtmpl.msc. Click OK.</p><p>2. You must be either the Enterprise Administrator or the Parent Domain Administrator in order to propagate templates to the Active Directory. Click YES.</p><p>3. If you have the correct credentials you will receive confirmation of Certificate Templates installation. Click OK.</p><p>10 802.1X SETUP INSTRUCTIONS</p><p>Note: Once the Administrator clicks OK, the Certificate Templates Management Console will open.</p><p>Configuring Enterprise Certificate Templates </p><p>Setting Computer Template to allow authenticated users enroll permissions.</p><p>Double-click Computer Template above, to expose Properties.</p><p>11 802.1X SETUP INSTRUCTIONS</p><p>Click on the Security tab.</p><p>12 802.1X SETUP INSTRUCTIONS</p><p>Check Enroll for Authenticated Users. Click OK.</p><p>Do the same thing for Users.</p><p>INSTALLING AND CONFIGURING SERVICES </p><p>Once this is done, we need to install other necessary services on the server machine. Thru My Computer->Control Panel->Add/Remove Programs, add the following components: Services to be installed</p><p>1. Certificate services 2. Internet Information Services - IIS 3. Internet Authentication Service (IAS)</p><p>Certificate Services</p><p>13 802.1X SETUP INSTRUCTIONS</p><p>1. Select Enterprise Root CA</p><p>2. Enter the CA Identifying Information..</p><p>14 802.1X SETUP INSTRUCTIONS</p><p>3. Accept the default, or enter data storage locations. These paths can be PATH or UNC. Click NEXT. FINISH Note: At this point the component wizard will complete the CS configuration.</p><p>15 802.1X SETUP INSTRUCTIONS</p><p>4. Select: Certificate Services, under Details select both: Certificate Services CA and Certificate Services Web Enrollment Support. Note: I will refer to Web Enrollment Support as a “Web Proxy”. Click OK.</p><p>Configuring Certificate Authority to issue Certificate Templates </p><p>1. Click Start  Programs  Administrative tools  Certificate Authority 2. Rclick: certificate template-- new certificate template to issue</p><p>16 802.1X SETUP INSTRUCTIONS</p><p>3. Select all Certificate Templates. Click OK.</p><p>Create a computer certificate for the server machine.</p><p>Type the command gpupdate /force at the command prompt.</p><p>17 802.1X SETUP INSTRUCTIONS</p><p>Configuring Internet Authentication Service</p><p>Setup IAS server</p><p>Create RADIUS client Create a client for RAS server, which needs to authenticate using IAS. </p><p>Since the RAS server will exist on the same machine as the IAS server, create a client with the server’s IP address. </p><p>Create Remote Access policies Create a new profile for every authentication mechanism that we need i.e., EAP-MD5, EAP-TLS.</p><p>In the profile for each policy, set the appropriate authentication mechanism and set the Session-Timeout attribute to the desired value. Be sure to allow dial in permissions.</p><p>Create Connections Policy</p><p>INTERNET AUTHENTICATION SERVICE > CONNECTION REQUEST POLICIES > ACTION > NEW > CONNECTION REQUEST POLICY</p><p>Create a Connection Request policy using custom set up. The policy name is assigned by the user and should include only Day-And-Time-Restrictions</p><p>18 802.1X SETUP INSTRUCTIONS</p><p>Testing IAS Services</p><p>IAS VPN Test Procedure</p><p>1. Ensure that on IAS, the EAP-MD5 profile is the first one from top in order.</p><p>2. Ensure that RRAS has "RADIUS Authentication" and "RADIUS Accounting" as the providers.</p><p>Routing and Remote Access > “Server name (Local)” > Action> Properties > Security Tab</p><p>19 802.1X SETUP INSTRUCTIONS</p><p>Client Test configuration</p><p>1. Create VPN connectoid on a client machine in the network for VPNing into the RRAS server. 2. Choose “Advanced (custom setting)” under the security tab for connectoid properties. 3. Set the authentication mechanism on the connectoid as EAP-MD5 – “MD5-Challenge”. 4. Connect to the VPN server, by double-clicking on the connectoid. 5. Use user credentials of the user created above.</p><p>Ensure MD5 login is fine using VPN from client machine.</p><p>From the client machine, log onto the domain as the user that you created above. </p><p>Downloading Certificates</p><p>1. Ensure that on IAS, the EAP-TLS profile is the first one from top in order. 2. In internet explorer type: http://<certificate server name or IP address>/certsrv This will connect via the web-interface to the certificate server. Request a certificate for the current user and install it on the client machine. To ensure that a certificate was loaded on the client machine using the "certificate services" mmc snapin.</p><p>Configuring Wireless Access</p><p>From network connections, right click your wireless connection. Click properties. On the WLAN tab you should see a list of all visible networks, if the driver and firmware support all the required OIDs. Click on the Access point you want to associate with and click copy. </p><p>20 802.1X SETUP INSTRUCTIONS</p><p>Configure the properties. It will appear in the list of preferred networks. Click on the Authentication tab, and check the EAP authentication using smartcard, or other certificate. Testing TLS Authentication Services – Wireless </p><p>The client should use the certificate that was downloaded above to authenticate the user . If you set up reply messages on your remote access policies, and check the box to show the network connection icon on the taskbar, on your network connection properties, you will see this as soon as it happens. Check the event viewer, System events, for verification of access, and/or error messages from IAS.</p><p>21</p>

View Full Text

Details

  • File Type
    pdf
  • Upload Time
    -
  • Content Languages
    English
  • Upload User
    Anonymous/Not logged-in
  • File Pages
    22 Page
  • File Size
    -

Download

Channel Download Status
Express Download Enable

Copyright

We respect the copyrights and intellectual property rights of all users. All uploaded documents are either original works of the uploader or authorized works of the rightful owners.

  • Not to be reproduced or distributed without explicit permission.
  • Not used for commercial purposes outside of approved use cases.
  • Not used to infringe on the rights of the original creators.
  • If you believe any content infringes your copyright, please contact us immediately.

Support

For help with questions, suggestions, or problems, please contact us