Enabling host-based eap – Cisco 340 User Manual

Page 49

Advertising
background image

5-49

Cisco Aironet 340, 350, and CB20A Wireless LAN Client Adapters Installation and Configuration Guide for Windows

OL-1394-08

Chapter 5 Configuring the Client Adapter

Setting Network Security Parameters

c.

Uncheck the Enable network access control using IEEE 802.1X or Enable IEEE 802.1x
authentication for this network
check box.

d.

Click OK to save your settings.

e.

If you are using Windows XP Service Pack 1, uncheck the Use Windows to configure my wireless
network settings
check box on the Wireless Networks screen and click OK.

Step 16

If you imported a PAC file in

Step 10

, you may want to consider deleting it from its original location,

depending on your organization’s policy. PAC files are similar to ID cards and should be protected from
unauthorized access. Such action would prevent exposure of the PAC by having multiple storage
locations. Contact your system administrator to determine your organization’s policy on PAC security.

Step 17

Refer to

Chapter 6

for instructions on authenticating using EAP-FAST.

Enabling Host-Based EAP

Before you can enable host-based EAP authentication, your network devices must meet the following
requirements:

Client adapters must support WEP and use the firmware, drivers, utilities, and security modules
included in the Install Wizard file.

The Microsoft 802.1X supplicant must be installed on your Windows device.

To use WPA, you must use a 350 series or CB20A client adapter with the software included in Install
Wizard version 1.2 or later on a computer running Windows 2000 or XP. Also, you must install
additional software with WPA support. You can download this software from the URLs provided:

Funk Odyssey Client supplicant version 2.2 (for Windows 2000)

http://www.funk.com/radius/wlan/wlan_c_radius.asp

Windows XP Service Pack 1 and Microsoft support patch 815485 (for Windows XP)

http://www.microsoft.com/WindowsXP/pro/downloads/servicepacks/sp1/default.asp

http://www.microsoft.com/downloads/details.aspx?FamilyID=009d8425-ce2b-47a4-abec-274
845dc9e91&DisplayLang=en

Note

Meetinghouse AEGIS Client supplicant version 2.1 or later is also supported for use with
Windows 2000 and XP; however, it was not tested with this client adapter software release.
You can download the Meetinghouse supplicant from the following URL:

http://www.mtghouse.com/support/downloads/index.shtml

Access points to which your client adapter may attempt to authenticate must use the following
firmware versions or later: 12.00T (340, 350, and 1200 series access points) or Cisco IOS Release
12.2(4)JA (1100 series access points).

Note

To use WPA or fast roaming, access points must use Cisco IOS Release 12.2(11)JA or later.

All necessary infrastructure devices such as access points, servers, gateways, and user databases
must be properly configured for the authentication type you plan to enable on the client.

Advertising