configuring windows 7 to do automatic 802 · pdf file · 2017-07-27configuring...

13
Configuring Windows 7 to do automatic 802.1x Introduction This document covers how to configure Windows 7 PC’s to connect automatically to the Loughborough University 802.1x wired network at SportPark. Benefits of this configuration include the PC can connect to the 802.1x network before the user logs on to Windows, so the computer can talk to domain controllers before a user logs in. The user does not need to enter a University username/password themselves each time they logon to the PC. Drawbacks of this configuration include the password must be stored on the computer itself, which may not be desirable from a security point of view. The University credentials stored by Windows will always be used regardless of who is using the PC. Where more than one person uses a PC, this may not be desirable since the University would record all internet activity against the University credentials used.

Upload: vohuong

Post on 19-Mar-2018

219 views

Category:

Documents


2 download

TRANSCRIPT

ConfiguringWindows7todoautomatic802.1x

IntroductionThisdocumentcovershowtoconfigureWindows7PC’stoconnectautomaticallytotheLoughboroughUniversity802.1xwirednetworkatSportPark.

Benefitsofthisconfigurationinclude

• thePCcanconnecttothe802.1xnetworkbeforetheuserlogsontoWindows,sothecomputercantalktodomaincontrollersbeforeauserlogsin.

• TheuserdoesnotneedtoenteraUniversityusername/passwordthemselveseachtimetheylogontothePC.

Drawbacksofthisconfigurationinclude

• thepasswordmustbestoredonthecomputeritself,whichmaynotbedesirablefromasecuritypointofview.

• TheUniversitycredentialsstoredbyWindowswillalwaysbeusedregardlessofwhoisusingthePC.WheremorethanonepersonusesaPC,thismaynotbedesirablesincetheUniversitywouldrecordallinternetactivityagainsttheUniversitycredentialsused.

Instructionsforconfiguringautomatic802.1xlogin

EnsuretheWiredAutoConfigServiceisenabled

• OpenServices(ControlPanel>SystemandSecurity>AdministrativeTools>Services)

• RightclickontheWiredAutoConfigserviceandchooseProperties

• SetStartuptypetoAutomatic.ClickonStartandwaitfortheservicetostart.ClickApply,thenclickOK.

InstalltheLoughboroughUniversitynetworkcertificate• Downloadthecertificatefromhttps://sportpark-portal.lboro.ac.uk/sportparkportal-files/lboro-

ca.derandsaveittoaconvenientlocation,suchasthedesktop.

FortheComputertoperformautomaticWired802.1x,ourcertificateneedstoininstalledtotheComputerAccount.Bydefault,certificatesareinstalledforUseraccounts,sowewillimportitusingtheCertificatessnap-in.

• Searchformmcfromthestartmenuandtherunclickonmmctoopenit.

• Notethatyoumustlaunchmmcwithadministrativeprivileges(otherwiseitcannotaccessthecertificatestorefortheComputerAccount).Ifyouarenotalreadyrunningwithadministrativerights,youcanrightclickontheentryformmcinthestartmenuandchooseRunasadministrator

• OntheFilemenuforConsole1–[ConsoleRoot],clickAdd/RemoveSnapIn.

• IntheAddStandaloneSnap-indialogbox,selectCertificatesandclickAdd

• IntheCertificatessnap-inwindow,chooseComputeraccountandclickNext.(IftheCertificatessnap-inwindowabovedidnotappear,doublecheckthatyouhaveadministrativeaccess).

• IntheSelectComputerwindow,chooseLocalcomputerandclickFinishandthenclickOKtoclosetheAddorRemoveSnap-inswindow

• EnsuringthatyouareintheCertificates(LocalComputer)tree,rightclickonTrustedRootCertificationAuthorities>CertificatesandchooseAllTasks>Import…

• IntheCertificateImportWizard,clickNext

• Providethelocationofthelboro-ca.cercertificatefileyousavedearlier,thenclickNext.

• IntheCertificateImportWizard,choosePlaceallcertificatesinthefollowingstoreandthenclickBrowse

• Fromthelist,chooseTrustedRootCertificationAuthoritiesandclickOK.

• BackattheCertificateImportWizard,clickNextandthenFinish

• Ifpromptedwiththeabovesecuritywarning,chooseYes

• ClickOK.(Youcannowclosethemmcconsole)

ConfiguretheNetworkAdaptorforWired802.1x

• OpentheControlPanel\NetworkandInternet\NetworkConnections,thenrightclicktheLocalAreaConnectionandchooseProperties

• IntheLocalAreaConnectionPropertieswindow,choosetheAuthenticationtab.Thenensure

thatEnableIEEE802.1Xauthenticationisticked.Forthenetworkauthenticationmethod,chooseMicrosoft:ProtectedEAP(PEAP).NowclicktheSettingsbutton.

• IntheProtectedEAPPropertieswindow:o EnsurethatValidateservercertificateandEnableFastReconnectareticked.o FromthelistofTrustedRootCertificationAuthoritiesticktheboxnextto

LoughboroughUniversityNetworkServicesCertificateAuthorityo SettheAuthenticationMethodtoSecuredPassword(EAP-MSCHAPv2).

Afteryouhaveconfirmedthesesettings,clicktheConfigurebutton

• IntheEAPMSCHAPv2Propertiesdialog,ensurethatAutomaticallyusemyWindowslogonnameandpassword(anddomainifany)isNOTtickedandclickOK.

• ThenclickOKtoclosetheProtectedEAPPropertieswindow.

• BackattheLocalAreaConnectionPropertieswindow,clicktheAdditionalSettingsbutton

• IntheAdvancedsettingswindow:

o TicktheboxnexttoSpecifyauthenticationmodeandchooseUserauthentication.o ClicktheSavecredentialsbutton

o IntheWindowsSecuritydialogthatappears,entertheLoughboroughUniversity

networkcredentialsfortheuserwhowillusethePCandclickOK

o BackattheAdvancedsettingswindow,ensurethatEnablesinglesignonforthisnetworkisNOTtickedandthenclickOK

o Finally,backattheLocalAreaConnectionPropertieswindow,clickOK.

OncetheLocalAreaConnectionPropertieswindowisclosed,Windowsshouldauthenticateusingthecredentialsprovidedandshouldbeconnectedtothecorrectnetwork.