+ All Categories
Home > Documents > Configuring Windows 7 to do automatic 802 · PDF file · 2017-07-27Configuring...

Configuring Windows 7 to do automatic 802 · PDF file · 2017-07-27Configuring...

Date post: 19-Mar-2018
Category:
Upload: vohuong
View: 219 times
Download: 2 times
Share this document with a friend
13
Configuring Windows 7 to do automatic 802.1x Introduction This document covers how to configure Windows 7 PC’s to connect automatically to the Loughborough University 802.1x wired network at SportPark. Benefits of this configuration include the PC can connect to the 802.1x network before the user logs on to Windows, so the computer can talk to domain controllers before a user logs in. The user does not need to enter a University username/password themselves each time they logon to the PC. Drawbacks of this configuration include the password must be stored on the computer itself, which may not be desirable from a security point of view. The University credentials stored by Windows will always be used regardless of who is using the PC. Where more than one person uses a PC, this may not be desirable since the University would record all internet activity against the University credentials used.
Transcript

ConfiguringWindows7todoautomatic802.1x

IntroductionThisdocumentcovershowtoconfigureWindows7PC’stoconnectautomaticallytotheLoughboroughUniversity802.1xwirednetworkatSportPark.

Benefitsofthisconfigurationinclude

• thePCcanconnecttothe802.1xnetworkbeforetheuserlogsontoWindows,sothecomputercantalktodomaincontrollersbeforeauserlogsin.

• TheuserdoesnotneedtoenteraUniversityusername/passwordthemselveseachtimetheylogontothePC.

Drawbacksofthisconfigurationinclude

• thepasswordmustbestoredonthecomputeritself,whichmaynotbedesirablefromasecuritypointofview.

• TheUniversitycredentialsstoredbyWindowswillalwaysbeusedregardlessofwhoisusingthePC.WheremorethanonepersonusesaPC,thismaynotbedesirablesincetheUniversitywouldrecordallinternetactivityagainsttheUniversitycredentialsused.

Instructionsforconfiguringautomatic802.1xlogin

EnsuretheWiredAutoConfigServiceisenabled

• OpenServices(ControlPanel>SystemandSecurity>AdministrativeTools>Services)

• RightclickontheWiredAutoConfigserviceandchooseProperties

• SetStartuptypetoAutomatic.ClickonStartandwaitfortheservicetostart.ClickApply,thenclickOK.

InstalltheLoughboroughUniversitynetworkcertificate• Downloadthecertificatefromhttps://sportpark-portal.lboro.ac.uk/sportparkportal-files/lboro-

ca.derandsaveittoaconvenientlocation,suchasthedesktop.

FortheComputertoperformautomaticWired802.1x,ourcertificateneedstoininstalledtotheComputerAccount.Bydefault,certificatesareinstalledforUseraccounts,sowewillimportitusingtheCertificatessnap-in.

• Searchformmcfromthestartmenuandtherunclickonmmctoopenit.

• Notethatyoumustlaunchmmcwithadministrativeprivileges(otherwiseitcannotaccessthecertificatestorefortheComputerAccount).Ifyouarenotalreadyrunningwithadministrativerights,youcanrightclickontheentryformmcinthestartmenuandchooseRunasadministrator

• OntheFilemenuforConsole1–[ConsoleRoot],clickAdd/RemoveSnapIn.

• IntheAddStandaloneSnap-indialogbox,selectCertificatesandclickAdd

• IntheCertificatessnap-inwindow,chooseComputeraccountandclickNext.(IftheCertificatessnap-inwindowabovedidnotappear,doublecheckthatyouhaveadministrativeaccess).

• IntheSelectComputerwindow,chooseLocalcomputerandclickFinishandthenclickOKtoclosetheAddorRemoveSnap-inswindow

• EnsuringthatyouareintheCertificates(LocalComputer)tree,rightclickonTrustedRootCertificationAuthorities>CertificatesandchooseAllTasks>Import…

• IntheCertificateImportWizard,clickNext

• Providethelocationofthelboro-ca.cercertificatefileyousavedearlier,thenclickNext.

• IntheCertificateImportWizard,choosePlaceallcertificatesinthefollowingstoreandthenclickBrowse

• Fromthelist,chooseTrustedRootCertificationAuthoritiesandclickOK.

• BackattheCertificateImportWizard,clickNextandthenFinish

• Ifpromptedwiththeabovesecuritywarning,chooseYes

• ClickOK.(Youcannowclosethemmcconsole)

ConfiguretheNetworkAdaptorforWired802.1x

• OpentheControlPanel\NetworkandInternet\NetworkConnections,thenrightclicktheLocalAreaConnectionandchooseProperties

• IntheLocalAreaConnectionPropertieswindow,choosetheAuthenticationtab.Thenensure

thatEnableIEEE802.1Xauthenticationisticked.Forthenetworkauthenticationmethod,chooseMicrosoft:ProtectedEAP(PEAP).NowclicktheSettingsbutton.

• IntheProtectedEAPPropertieswindow:o EnsurethatValidateservercertificateandEnableFastReconnectareticked.o FromthelistofTrustedRootCertificationAuthoritiesticktheboxnextto

LoughboroughUniversityNetworkServicesCertificateAuthorityo SettheAuthenticationMethodtoSecuredPassword(EAP-MSCHAPv2).

Afteryouhaveconfirmedthesesettings,clicktheConfigurebutton

• IntheEAPMSCHAPv2Propertiesdialog,ensurethatAutomaticallyusemyWindowslogonnameandpassword(anddomainifany)isNOTtickedandclickOK.

• ThenclickOKtoclosetheProtectedEAPPropertieswindow.

• BackattheLocalAreaConnectionPropertieswindow,clicktheAdditionalSettingsbutton

• IntheAdvancedsettingswindow:

o TicktheboxnexttoSpecifyauthenticationmodeandchooseUserauthentication.o ClicktheSavecredentialsbutton

o IntheWindowsSecuritydialogthatappears,entertheLoughboroughUniversity

networkcredentialsfortheuserwhowillusethePCandclickOK

o BackattheAdvancedsettingswindow,ensurethatEnablesinglesignonforthisnetworkisNOTtickedandthenclickOK

o Finally,backattheLocalAreaConnectionPropertieswindow,clickOK.

OncetheLocalAreaConnectionPropertieswindowisclosed,Windowsshouldauthenticateusingthecredentialsprovidedandshouldbeconnectedtothecorrectnetwork.


Recommended