how to configure dot1x

Upload: carlos-celestino

Post on 07-Apr-2018

243 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/4/2019 How to Configure Dot1x

    1/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    HOW TO CONFIGURE 802.1X / PEAPWITH RADIUS SERVER (IAS) AND ACTIVE DIRECTORY USING

    WIRELESS SWITCH THROUGH OF THE WIRELESS SWITCHMANAGER

  • 8/4/2019 How to Configure Dot1x

    2/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    WIRELESS SWITCH MANAGER

    1. Configuring the Access Point

    - Select the TAB Configuration- Select the option Wireless- Select the option Access Points- Select the option Create- Select the option Directly Connected MAP- Uses wizard to configure to choose the AP model

  • 8/4/2019 How to Configure Dot1x

    3/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    2. Access Point Configured- Deploy the configuration to the Wireless Switch- Select the option Deploy

  • 8/4/2019 How to Configure Dot1x

    4/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    3. Configuring the Service Profile OpenNOTE:- This step is necessary to verify if the connection from Wireless Client to the AP

    connected on WX is working in an open SSID without authentication. It can be deletedwhen the 802.1X is working correctly.

    - Select the TAB Configuration- Select the option Wireless- Select the option Wireless Services- Select the option Create- Select the option Open Access Service Profile- Uses wizard to configure the SSID Open

  • 8/4/2019 How to Configure Dot1x

    5/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    4. Service Profile Open with the SSID Open Configured- Deploy the configuration to the Wireless Switch- Select the option Deploy

  • 8/4/2019 How to Configure Dot1x

    6/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    5. Configuring the RADIUS Client on WX- Select the TAB Configuration- Select the option AAA- Select the option Radius

    - Select the option Create- Select the option Radius Server- Uses wizard to configure the Radius

  • 8/4/2019 How to Configure Dot1x

    7/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    6. Radius Configured- Deploy the configuration to the Wireless Switch- Select the option Deploy- NOTE:- The IP Address is the IP from the Radius Server (ie. IAS)

    - The Key configured here must be the same configured on Radius Server (ie. IAS)

  • 8/4/2019 How to Configure Dot1x

    8/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    7. Configuring the the Service Profile 802.1X- Select the TAB Configuration- Select the option Wireless- Select the option Wireless Services

    - Select the option Create- Select the option 802.1X Service Profile

  • 8/4/2019 How to Configure Dot1x

    9/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    8. Do not forget to select the Radius in the Service Profile 802.1X wizard- Select the EAP Type: External RADIUS Server- Select the Server Group configured previously on Avaliable RADIUS Server

    Groups

  • 8/4/2019 How to Configure Dot1x

    10/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    9. Service Profile 802.1X Configured- Deploy the configuration to the Wireless Switch- Select the option Deploy

  • 8/4/2019 How to Configure Dot1x

    11/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    ACTIVE DIRECTORY

    10. Configuring the group on Active Directory- Open the Active Directory Users and Computers

    - Select Users under Domain (ie LAB3COM)- Right-Click in Users- Select New / Group

  • 8/4/2019 How to Configure Dot1x

    12/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the Group name

  • 8/4/2019 How to Configure Dot1x

    13/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    11. Configuring the Users on Active Directory- Select Users under Domain (ie LAB3COM)- Right-Click in Users- Select New / User

  • 8/4/2019 How to Configure Dot1x

    14/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the First Name- Enter with the User logon name

  • 8/4/2019 How to Configure Dot1x

    15/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the Password for the user created

  • 8/4/2019 How to Configure Dot1x

    16/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    12. Configuring the user to the group on Active Directory- Double-click in the user created- Select the TAB Member Of

  • 8/4/2019 How to Configure Dot1x

    17/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Click on Add

  • 8/4/2019 How to Configure Dot1x

    18/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the name of the group created in the option Enter the objectnames to select

  • 8/4/2019 How to Configure Dot1x

    19/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - User added to the group

  • 8/4/2019 How to Configure Dot1x

    20/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the TAB Dial-in- Select the option Allow Access

  • 8/4/2019 How to Configure Dot1x

    21/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    IAS RADIUS

    1. Configuring the Radius Client on IAS- Right-Click on RADIUS Client

    - New RADIUS Client

  • 8/4/2019 How to Configure Dot1x

    22/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the name- Enter with IP from Radius Client (This the IP from Wireless Switch)

  • 8/4/2019 How to Configure Dot1x

    23/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the Client-Vendor- Enter with the Shared secret (This the same configured on Wireless Switch).

    The key configuration on WX was described on item 6 of this manual.

  • 8/4/2019 How to Configure Dot1x

    24/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Radius Client configured on IAS

  • 8/4/2019 How to Configure Dot1x

    25/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    2. Configuring the Remote Access Policies on IAS- Right-Click on Remote Access Policies- Select New Remote Access Policy

  • 8/4/2019 How to Configure Dot1x

    26/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the policy nama

  • 8/4/2019 How to Configure Dot1x

    27/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the Access Method

  • 8/4/2019 How to Configure Dot1x

    28/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the option add

  • 8/4/2019 How to Configure Dot1x

    29/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the name of the group in the item Enter the object names toselect

  • 8/4/2019 How to Configure Dot1x

    30/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Group selected- Click on Next

  • 8/4/2019 How to Configure Dot1x

    31/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select PEAP- Select Configure

  • 8/4/2019 How to Configure Dot1x

    32/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the certificate

  • 8/4/2019 How to Configure Dot1x

    33/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Click Finish- The policy has been created

  • 8/4/2019 How to Configure Dot1x

    34/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    3. Configuring the IAS to use the AD- Right-Click on Internet Authentication Service (Local)- Select Register Server in Active Directory

  • 8/4/2019 How to Configure Dot1x

    35/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

  • 8/4/2019 How to Configure Dot1x

    36/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    WIRELESS CLIENT CENTRINO

    1. Configuring the Client- Open the Wireless Connection- Select Properties

  • 8/4/2019 How to Configure Dot1x

    37/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the TAB Wireless Networks- Click on Add

  • 8/4/2019 How to Configure Dot1x

    38/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Enter with the SSID- Select the Network Authentication- Select Data Encryption

  • 8/4/2019 How to Configure Dot1x

    39/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the TAB Authentication- Select the EAP Type / PEAP

  • 8/4/2019 How to Configure Dot1x

    40/45

  • 8/4/2019 How to Configure Dot1x

    41/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Uncheck the option Validate server certificate- Select the Authentication Method (EAP-MSCHAPv2)- Click on Configure

  • 8/4/2019 How to Configure Dot1x

    42/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Uncheck the option automatically use my Windows logon name andpassword (and domain if any).

  • 8/4/2019 How to Configure Dot1x

    43/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    EVENT VIEWER

    1. Troubleshooting- The event viewer can be used to verify if the Radius packet is being analyzed

    by the Radius Server

    - Select Administrative Tools / Event Viewer

  • 8/4/2019 How to Configure Dot1x

    44/45

    3COM BRAZILAuthor: Juliano Forti ([email protected])

    - Select the TAB System under Event Viewer (Local)

  • 8/4/2019 How to Configure Dot1x

    45/45

    - Double-click on event to verify if the client was authenticated or reject