Implementing 802.1x on Wireless Networks with Cisco and Microsoft

Server Setup

    The radius authentication server for 802.1x must currently use the Microsoft Internet Authentication Server, since it is currently the only radius server that supports the eap-tls authentication method.  FreeRADIUS has support planned for future releases.  Successful 802.1x implementation requires the following services on the windows 2000 domain controller:

    Note that these services do not need to run on the domain controller itself with a given network, but a domain architecture is required. In a single server network or for testing purposes having all services on a single server is fine.  These instructions assume that you're starting from scratch with an all new network with a newly installed standard Windows 2000 Server - if you're adding support onto an existing network, verify that the settings contained below are compatible and set for your network. Note that some of the tasks must either be performed on a domain controller or using active directory management tools.

Step 1 - Install Windows 2000 Domain Controller

Step 2 - Install the required services

Step 3 - Configure DHCP server.

Step 4 - Setup Certificate Authority

When the Certificate Request Wizard comes up, select Next. Select the Computer certificate template, and click Next.

Step 5 - Setup Internet Authentication Service (radius)

Step 6 - Enable Remote Access Login for Users

 

Setup of the Authentication Server is finished, now set up your client ...


This how-to is still under development, comments, questions, problems and feedback welcomed at mvanopst@cs.umd.edu
Last updated January 28th, 2002 by Mike van Opstal