Back to Contents

Set Up Profile Security: Intel(R) PRO/Wireless 3945ABG Network Connection User Guide


Use Intel(R) PROSet/Wireless Software
Personal Security
Personal Security Settings
Set up Data Encryption and Authentication

Enterprise Security
Enterprise Security Settings


Use Intel(R) PROSet/Wireless Software

The following sections describe how to use Intel(R) PROSet/Wireless to set up the required security settings for your wireless adapter. Refer to Personal Security.

It also provides information about how to configure advanced security settings for your wireless adapter. This requires information from a systems administrator (corporate environment) or advanced security settings on your access point (for home users). Refer to Enterprise Security.

For general information about security settings, refer to Security Overview.


Personal Security

Use Personal Security if you are a home or small business user who can use a variety of simple security procedures to protect your wireless connection. Select from the list of security settings that do not require extensive infrastructure setup for your wireless network. A RADIUS or AAA server is not required.


Personal Security Settings

Personal Security Settings Description

None WEP CKIP TKIP AES-CCMP

Name

Setting

Personal Security

Select to open the Personal Security settings. The security settings that are available are dependent on the Operating Mode selected in the Profile Wizard: Device to Device (ad hoc) or Network (Infrastructure).

Data Encryption

If you configure a profile for a Device to Device (ad hoc) network, select

If you configure an profile for an Infrastructure network, select:

Advanced

Select to access the Advanced Settings to configure the following options:

Back

View the prior page in the Profile Wizard.

OK

Closes the Profile Wizard and saves the profile.

Cancel

Closes the Profile Wizard and cancels any changes made.

Help?

Provides the help information for the current page.


Set up Data Encryption and Authentication

In a home wireless network, you can use a variety of simple security procedures to protect your wireless connection. These include:

Wi-Fi Protected Access (WPA) encryption provides protection for your data on the network. WPA uses an encryption key called a Pre-Shared Key (PSK) to encrypt data before transmission. Enter the same password in all of the computers and access points in your home or small business network. Only devices that use the same encryption key can access the network or decrypt the encrypted data transmitted by other computers. The password automatically initiates the Temporal Key Integrity Protocol (TKIP) for the data encryption process.

Network Keys

WEP encryption provides two levels of security:

For improved security, use a 128-bit key. If you use encryption, all wireless devices on your wireless network must use the same encryption keys.

You can create the key yourself and specify the key length (64- or 128-bit) and key index (the location that a specific key is stored). The greater the key length, the more secure the key.

Key Length: 64-bit

Pass phrase (64-bit): Enter five (5) alphanumeric characters, 0-9, a-z or A-Z.
Hex key (64-bit): Enter 10 hexadecimal characters, 0-9, A-F.

Key Length: 128-bit

Pass phrase (128-bit): Enter 13 alphanumeric characters, 0-9, a-z or A-Z.
Hex key (128-bit):
Enter 26 hexadecimal characters, 0-9, A-F.

With 802.11, a wireless station can be configured with up to four keys (the key index values are 1, 2, 3, and 4). When an access point or a wireless station transmits an encrypted message that uses a key stored in a specific key index, the transmitted message indicates the key index that was used to encrypt the message body. The receiving access point or wireless station can then retrieve the key that is stored at the key index and use it to decode the encrypted message body.


Personal Security: Configure Profiles for Device to Device (Ad Hoc) Networks

Set up a Client with Open Authentication and No Data Encryption (None)

In device to device mode, also called ad hoc mode, wireless computers send information directly to other wireless computers. You can use ad hoc mode to network multiple computers in a home or small office, or to set up a temporary wireless network for a meeting.

On the Intel(R) PROSet/Wireless main window, select one of the following methods to connect to a device to device network:

NOTE: Device to Device (ad hoc) networks are identified with a notebook image () in the Wireless Networks and Profiles list.

To create a profile for a wireless network connection with no encryption:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Create Wireless Profile General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Device to Device (ad hoc).
  6. Click Next.
  7. Click Personal Security to open the Security Settings.
  8. Data Encryption: The default setting is None, which indicates that there is no security on this wireless network.
  9. Click OK. The profile is added to the Profiles list and connects to the wireless network.

Set up a Client with WEP 64-bit or WEP 128-bit Data Encryption

When WEP data encryption is enabled, a network key or password is used for encryption.

You must enter the key and specify the length (64- or 128-bit) and key index (the location that a specific key is stored). The more complex the key (mixed letters and numbers), the more secure the key.

To add a network key to a device to device network connection:

  1. On the Intel PROSet/Wireless main window, double-click a Device to Device (ad hoc) network in the Wireless Networks list or select the network and click Connect. When connected, a profile is added to the Profiles list.

NOTE: Device to Device (ad hoc) networks are identified with a notebook image () in the Wireless Networks and Profiles list.

  1. Click Profiles to access the Profiles list. Select the network that you connected to in Step 1.
  2. Click Properties to open the Wireless Profile Properties' General Settings. The Profile name and Wireless Network Name (SSID) display. Device to Device (ad hoc) should be selected as the Operating Mode.
  3. Click Next to access the Security Settings.
  4. Click Personal Security.
  5. Security Settings: The default setting is None, which indicates that there is no security on this wireless network.

To add a password or network key:

  1. Security Settings: Select either WEP 64-bit or WEP 128-bit to configure WEP data encryption with a 64- or 128-bit key.

When WEP encryption is enabled on a device, the WEP key is used to verify access to the network. If the wireless device does not have the correct WEP key, even though authentication is successful, the device is unable to transmit data.

  1. Password: Enter the Wireless Security Password (Encryption Key).
  1. Key Index: Up to four passwords may be specified by changing the Key Index.
  2. To add more than one password:
  3. Click OK to return to the Profiles list.

Personal Security: Configure Profiles for Infrastructure Networks

An infrastructure network consists of one or more access points and one or more computers with wireless adapters installed. Each access point must have a wired connection to a wireless network. For home users, this is usually a broadband or cable network.

Set up a Client with No (None) Data Encryption

On the Intel(R) PROSet/Wireless main window, select one of the following methods to connect to an Infrastructure network:


Set up a Client with WEP 64-bit or WEP 128-bit Data Encryption

When WEP data encryption is enabled, a network key or password is used for encryption.

A network key is provided for you automatically (for example, it might be provided by your wireless network adapter manufacturer), or you can enter it yourself and specify the key length (64- or 128-bit), key format (ASCII characters or hexadecimal digits), and key index (the location where a specific key is stored). The greater the key length, the more secure the key.

To add a network key for an Infrastructure network connection:

  1. On the Intel PROSet/Wireless main window, double-click an Infrastructure network in the Wireless Networks list or select the network and click Connect.

NOTE: Infrastructure networks are identified with an access point image () in the Wireless Networks and Profiles list.

  1. Click Profiles to access the Profiles list.
  2. Click Properties to open the Wireless Profile Properties' General Settings. The Profile name and Wireless Network Name (SSID) display. Network (Infrastructure) should be selected as the Operating Mode.
  3. Click Next to access the Security Settings.
  4. Security Settings: The default setting is None, which indicates that there is no security on this wireless network.

To add a password or network key:

  1. Security Settings: Select either WEP 64-bit or WEP 128-bit to configure WEP data encryption with a 64- or 128-bit key.

When WEP encryption is enabled on an access point, the WEP key is used to verify access to the network. If the wireless device does not have the correct WEP key, even though authentication is successful, the device is unable to transmit data through the access point or decrypt data received from the access point.

  1. Password: Enter the Wireless Security Password (Pass phrase) or Encryption Key (WEP key).
  2. Key Index: Change the Key Index to set up to four passwords.
  3. To add more than one password:

  4. Click OK to return to the Profiles list.

Set up a Client with WPA-Personal (TKIP) or WPA2-Personal (TKIP) Security Settings

WPA Personal Mode requires manual configuration of a pre-shared key (PSK) on the access point and clients. This PSK authenticates users a password or identifying code, on both the client station and the access point. An authentication server is not needed. WPA Personal Mode is targeted to home and small business environments.

WPA2 is the second generation of WPA security that provides enterprise and consumer wireless users with a high level of assurance that only authorized users can access their wireless networks. WPA2 provides a stronger encryption mechanism through Advanced Encryption Standard (AES), which is a requirement for some corporate and government users.

To configure a profile with WPA-Personal network authentication and TKIP data encryption:

  1. On the Intel PROSet/Wireless main window, double-click an Infrastructure network in the Wireless Networks list or select the network and click Connect.

NOTE: Infrastructure networks are identified with an access point image () in the Wireless Networks and Profiles list.

  1. Click Profiles to access the Profiles list.
  2. Click Properties to open the Wireless Profile Properties' General Settings. The Profile name and Wireless Network Name (SSID) display. Network (Infrastructure) should be selected as the Operating Mode.
  3. Click Next to access the Security Settings.
  4. Security Settings: Select WPA-Personal (TKIP) to provide security to a small business network or home environment. A password, called a pre-shared key (PSK), is used. The longer the password, the stronger the security of the wireless network.

If your wireless access point or router supports WPA2-Personal then you should enable it on the access point and provide a long, strong password. The longer the password, the stronger the security of the wireless network. The same password entered in the access point needs to be used on this computer and all other wireless devices that access the wireless network.

NOTE: WPA-Personal and WPA2-Personal are not interoperable.

  1. Wireless Security Password (Encryption Key): Enter a text phrase with eight to 63 characters. Verify that the network key matches the password in the wireless access point.
  2. Click OK to return to the Profiles list.

Set up a Client with WPA-Personal (AES-CCMP) or WPA2-Personal (AES-CCMP) Security Settings

Wi-Fi Protected Access (WPA) is a security enhancement that strongly increases the level of data protection and access control to a wireless network. WPA enforces 802.1x authentication and key-exchange and only works with dynamic encryption keys. For a home user or small business, WPA-Personal utilizes either Advanced Encryption Standard - Counter CBC-MAC Protocol (AES-CCMP) or Temporal Key Integrity Protocol (TKIP).

To configure a profile with WPA2-Personal network authentication and AES-CCMP data encryption:

  1. On the Profile page, select a profile.
  2. Click Properties to open the Wireless Profile Properties' General Settings. The Profile name and Wireless Network Name (SSID) display. Network (Infrastructure) should be selected as the Operating Mode.
  3. Click Next. The Security Settings page opens.
  4. Security Settings: Select WPA-Personal (AES-CCMP) to provide this level of security in the small network or home environment. It uses a password also called a pre-shared key (PSK). The longer the password, the stronger the security of the wireless network.

AES-CCMP (Advanced Encryption Standard - Counter CBC-MAC Protocol) is the new method for privacy protection of wireless transmissions specified in the IEEE 802.11i standard. AES-CCMP provides a stronger encryption method than TKIP. Choose AES-CCMP as the data encryption method whenever strong data protection is important.

If your Wireless access point or router supports WPA2-Personal then you should enable it on the access point and provide a long, strong password. The same password entered into access point needs to be used on this computer and all other wireless devices that access the wireless network.

NOTE: WPA-Personal and WPA2-Personal are not interoperable.

Some security solutions may not be supported by your computer's operating system. You may require additional software or hardware as well as wireless LAN infrastructure support. Contact your computer manufacturer for details.

Set Password:

  1. Wireless Security Password (Encryption Key). Enter a text phrase (length is between eight and 63 characters). Verify that the network key used matches the wireless access point key.
  2. Click OK to return to the Profiles list.

Back to Top

Back to Contents


Enterprise Security

From the Security Settings page you can enter the required security settings for the selected wireless network.

Use Enterprise Security if your network environment requires 802.1x authentication.


Enterprise Security Settings

Enterprise Security Settings Description

Name

Setting

Enterprise Security

Select to open the Enterprise Security settings. The security settings that are available are dependent on the Operating Mode selected: Device to Device (ad hoc) or Network (Infrastructure).

Network Authentication

If you configure a Device to Device (ad hoc) profile, the default is Open authentication.

If you configure an Infrastructure profile, select:

Data Encryption

Enable 802.1x (Authentication Type)

Click to open the following 802.11x authentication types:

Cisco Options

Click to view the Cisco Compatible Extensions.

NOTE: Cisco Compatible Extensions are automatically enabled for CKIP and LEAP profiles.

Advanced button

Select to access the Advanced Settings to configure the following options:

Back

View the prior page in the Profile Wizard.

Next

View the next page in the Profile Wizard. If more security information is required then the next Step of the Security page is displayed.

OK

Closes the Profile Wizard and saves the profile.

Cancel

Closes the Profile Wizard and cancels any changes made.

Help?

Provides the help information for the current page.


Enterprise Security: Configure Profiles for Device to Device (Ad Hoc) Networks

Set up a Client with Open Network Authentication and No (None) Data Encryption

When Open authentication is used, any wireless station can request authentication. The station that needs to authenticate with another wireless station sends an authentication management frame that contains the identity of the sending station. The receiving station grants any request for authentication. Open authentication allows any device network access. If no encryption is enabled on the network, any device that knows the SSID can gain access to the network.

In Device to Device (ad hoc) mode, wireless computers send information directly to other wireless computers. You can use ad hoc mode to network multiple computers in a home or small office, or to set up a temporary wireless network for a meeting.

  1. On the Intel(R) PROSet/Wireless main window, select one of the following methods to connect to a device to device network:

    NOTE: Device to Device (ad hoc) networks are identified with a notebook image () in the Wireless Networks and Profiles list.

To create a profile for a wireless network connection with no encryption:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Create Wireless Profile General Settings.
  3. Wireless Network Name (SSID): Enter the network identifier.
  4. Profile Name: Enter a descriptive profile name.
  5. Operating Mode: Click Device to Device (ad hoc).
  6. Click Next

  1. Click Enterprise Security to open the Security Settings.
  2. Network Authentication: Open (Selected).

When Open authentication is used, any wireless station can request authentication. The station that needs to authenticate with another wireless station sends an authentication management frame that contains the identity of the sending station. T he receiving station grants any request for authentication. Open authentication allows any device network access. If no encryption is enabled on the network, any device that knows the SSID can gain access to the network. Device to Device (ad hoc) networks always operate with Open authentication.

  1. Data Encryption: None is the default.
  2. Click OK. The profile is added to the Profiles list and connects to the wireless network.

Set up a Client with Open Network Authentication and WEP Data Encryption

On the Intel PROSet/Wireless main window, select one of the following methods to connect to a device to device network:

  1. Double-click a Device to Device (ad hoc) network in the Wireless Networks list.
  2. Select a Device to Device (ad hoc) network in the Wireless Networks list. Click Connect. The Intel PROSet/Wireless software automatically detects the security settings for the wireless adapter.

NOTE: Device to Device (ad hoc) networks are identified with a notebook image () in the Wireless Networks and Profiles list.

  1. If Data Encryption is required, you may select WEP. You are asked to select either a 64-bit or 128-bit encryption level Security Password (Encryption Key) and a Key Index. These values must match the various devices in your device to device (ad hoc) network, or data is not transferred.

    NOTE: If you need to edit or change the wireless network settings, refer to Profile Management for more information.

To create a profile for a wireless network connection with WEP encryption:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Create Wireless Profile Wizard's General Settings.
  3. Wireless Network Name (SSID): Enter the network identifier.
  4. Profile Name: Enter a descriptive profile name.
  5. Operating Mode: Click Device to Device (ad hoc).
  6. Click Next.
  7. Click Enterprise Security to open the Security Settings.
  8. Network Authentication: Open is selected (Default). Ad hoc networks only use Open authentication.
  9. Data Encryption: Select WEP. WEP data encryption can be configured with 64- or 128-bit key.If the wireless device does not have the correct WEP key, the device is unable to transmit or decrypt data.
  10. Encryption Level: Select 64- or 128-bit.
  11. Wireless Security Password (Encryption Key): Enter the wireless network Password (WEP Key). The Password is the same value used by the wireless access point or router. Contact your administrator for this password.
  1. Key Index: Select 1, 2, 3, or 4. Up to four passwords may be specified by changing the Key Index.

To change the security settings:

  1. Click Profiles on the Intel PROSet/Wireless main window. The network that you just connected to is listed in the Profiles list.
  2. Select the wireless network.
  3. Click Properties to open the Wireless Profile Properties General Settings. The Wireless Network Name (SSID) and Profile Name are already defined. Device to Device (ad hoc) is selected as the operating mode.
  4. Click Next to access the Security Settings.
  5. Click Enterprise Security.
  6. Network Authentication: Open is the default. No authentication is used.
  7. Data Encryption: WEP is selected. You can change the WEP key, key index or encryption level.
  8. Click OK to return to the Profiles list after you have completed your changes.

Enterprise Security: Configure Profiles for Infrastructure Networks

An infrastructure network consists of one or more access points and one or more computers with wireless adapters installed. Each access point must have a wired connection to a wireless network.

Set up a Client with No Authentication or Data Encryption (None)

On the Intel(R) PROSet/Wireless main page, select one of the following methods to connect to an Infrastructure network:

If there is no authentication required, the network connects without a prompt to enter any log-on credentials. Any wireless device with the correct network name (SSID) is able to associate with other devices in the network.

To create a profile for a wireless network connection with no encryption:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Create Wireless Profile General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Network (Infrastructure)
  6. Click Next.
  7. Click Enterprise Security to open the Security Settings.
  8. Network Authentication: Open (Selected).

Open authentication allows a wireless device access to the network without 802.11 authentication. If no encryption is enabled on the network, any wireless device with the correct network name (SSID) can associate with an access point and gain access to the network.

  1. Data Encryption: None is the default.
  2. Click OK. The profile is added to the Profiles list and connects to the wireless network .

Set up a Client with Shared Network Authentication

When Shared Key authentication is used, each wireless station is assumed to have received a secret shared key over a secure channel that is independent from the 802.11 wireless network communications channel. Shared key authentication requires that the client configure a static WEP or CKIP key. The client access is granted only if it passes a challenge-based authentication. CKIP provides stronger data encryption than WEP, but not all operating systems and access points support it.

NOTE: While shared key would appear to be the better option for a higher level of security, a known weakness is created by the clear text transmission of the challenge string to the client. Once an invader finds the challenge string, the shared authentication key can be easily reverse engineered. Therefore, open authentication is actually, and counter intuitively, more secure. To create a profile with shared authentication:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile Page, click Add to open the Create Wireless Profile General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Network (Infrastructure).
  6. Click Next to access the Security Settings.
  7. Click Enterprise Security.
  8. Network Authentication: Select Shared. Shared authentication is accomplished with a pre-configured WEP key.
  9. Data Encryption: Select None, WEP (64- or 128-bit), or CKIP (64- or 128-bit).
  10. Enable 802.1x: Disabled.
  11. Encryption Level: 64- or 128-bit: When switching between 64- and 128-bit encryption, the previous settings are erased and a new key must be entered.
  12. Key Index: Select 1,2, 3, or 4. Change the Key Index to specify up to four passwords.
  13. Wireless Security Password (Encryption Key): Enter the wireless network password (WEP Encryption Key). This password is the same value used by the wireless AP or router. Contact your administrator for this password.

Set up a Client with WPA-Personal or WPA2-Personal Network Authentication

Wi-Fi Protected Access (WPA) is a security enhancement that strongly increases the level of data protection and access control to a wireless network. WPA enforces key-exchange and only works with dynamic encryption keys. If your wireless AP or router supports WPA-Personal and WPA2-Personal then you should enable it on the AP and provide a long, strong password. For personal or home networks without a RADIUS or AAA server, use Wi-Fi Protected Access Personal.

NOTE: WPA-Personal or WPA2 Personal are not interoperable.

Some security solutions may not be supported by your computer's operating system and may require additional software or certain hardware as well as wireless LAN infrastructure support. Check with your computer manufacturer for details.

To add a profile with WPA-Personal or WPA2-Personal network authentication:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Profile Wizard's General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Network (Infrastructure).
  6. Click Next to access the Security Settings.
  7. Click Enterprise Security.
  8. Network Authentication: Select WPA-Personal or WPA2-Personal. See Security Overview.
  9. Data Encryption: Select one of the following:
  10. Password: Enter a text phrase from 8 to 63 characters. The longer the password, the stronger the security of the wireless network. The same password entered into an access points needs to be used on this computer and all other wireless devices that access the wireless network.

Set up a Client with WPA-Enterprise or WPA2-Enterprise Network Authentication

WPA2-Enterprise requires an authentication server.

NOTE: WPA-Enterprise and WPA2-Enterprise are not interoperable.

To add a profile that uses WPA - Enterprise or WPA2 - Enterprise authentication:

  1. Obtain a user name and password on the RADIUS server from your administrator.
  2. Certain Authentication Types require that obtain and install a client certificate. Refer to Setting up the Client for TLS authentication or consult your administrator.
  3. Click Profiles on the Intel PROSet/Wireless main window.
  4. On the Profile page, click Add to open the Profile Wizard's General Settings.
  5. Profile Name: Enter a descriptive profile name.
  6. Wireless Network Name (SSID): Enter the network identifier.
  7. Operating Mode: Click Network (Infrastructure).
  8. Click Next.
  9. Click Enterprise Security.
  10. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise.
  11. Data Encryption: Select one of the following:
  12. Enable 802.1x: Selected.
  13. Authentication Type: Select one of the following: EAP-SIM, LEAP, TLS, TTLS, PEAP, EAP-FAST.

Set up a Client with WEP Data Encryption and MD5 Network Authentication

MD5 authentication is a one-way authentication method that uses user names and passwords. This method does not support key management, but does require a pre-configured key if data encryption is used. To add WEP and MD5 authentication to a new profile:

NOTE: Before you begin, you need to know the user name and password on the RADIUS server that grants access to the network.

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Profile Wizard's General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Network (Infrastructure).
  6. Click Next.
  7. Click Enterprise Security.
  8. Network Authentication: Select Open (Recommended).
  9. Data Encryption: Select WEP.
  10. Click 802.1x Enabled.
  11. Authentication type: Select MD5.

Step 1 of 2: Password

  1. Encryption Level: Select either 64- or 128-bit.
  2. Wireless Security Password (Encryption Key): Enter your network key (wireless security password) for your wireless network. Verify that the network key matches the wireless AP.
  3. Key Index: Select 1, 2, 3 or 4. (Default key is 1.)
  4. Click Next.

Step 2 of 2: MD5 User

  1. Select one of the following credential methods:

    NOTE: This option is unavailable if Pre-Logon Connect is not selected during installation of the Intel PROSet/Wireless software. Refer to Install or Uninstall the Single Sign On Feature.

  1. Click OK to save the credentials.
  2. Click Connect to connect to the selected wireless network.

If you did not select Use Windows logon on the Security Settings page and also did not configure user credentials, an Enter Credentials message appears when you attempt to connect to this profile. Enter your user name, domain, and password. Click OK to access the profile.

  1. Click OK to close Intel PROSet/Wireless.

Set up a Client with WEP Data Encryption and EAP-SIM NetworK Authentication

EAP-SIM uses a dynamic session-based WEP key, which is derived from the client adapter and RADIUS server, to encrypt data. EAP-SIM requires you to enter a user verification code, or Personal Identification Number (PIN), for communication with the Subscriber Identity Module (SIM) card. A SIM card is a special smart card that is used by Global System for Mobile Communications (GSM) based digital cellular networks. To add a profile with EAP-SIM authentication:

  1. On the Profile page, click Add to open General Settings.
  2. Profile Name: Enter a profile name.
  3. Wireless Network Name (SSID): Enter the network identifier.
  4. Operating Mode: Click Network (Infrastructure).
  5. Click Next to access the Security Settings.
  6. Click Enterprise Security.
  7. Network Authentication: Select Open (Recommended).
  8. Data Encryption: Select WEP.
  9. Click Enable 802.1x.
  10. Authentication type: Select EAP-SIM.

EAP-SIM authentication can be used with:

EAP-SIM User (optional)

  1. Specify user name (identity): Click to specify the user name.
  1. Click OK.

Set up a Client with TLS Network Authentication

These settings define the protocol and the credentials used to authenticate a user. Transport Layer Security (TLS) authentication is a two-way authentication method that exclusively uses digital certificates to verify the identity of a client and a server.

To add a profile with TLS authentication:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Profile Wizard's General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Type the network identifier.
  5. Operating Mode: Click Network (Infrastructure).
  6. Click Next to access the Security Settings.
  7. Click Enterprise Security.
  8. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise.
  9. Data Encryption: Select AES-CCMP (Recommended).
  10. Enable 802.1x: Selected.
  11. Authentication Type: Select TLS to be used with this connection.

Step 1 of 2: TLS User

  1. Obtain and install a client certificate, refer to Set up the Client for TLS authentication or consult your system administrator.
  2. Select one of the following to obtain a certificate:
  3. Click Next.

Step 2 of 2: TLS Server

Select one of the following:

  1. Select one of the following options:

NOTE: These parameters should be obtained from the administrator.

  1. Click OK to save the setting and close the page.

Set up a Client with TTLS Network Authentication

TTLS authentication: These settings define the protocol and credentials used to authenticate a user. The client uses EAP-TLS to validate the server and create a TLS-encrypted channel between the client and server. The client can use another authentication protocol, typically password-based protocols (for example, MD5 Challenge over this encrypted channel to enable server validation). The challenge and response packets are sent over a non-exposed TLS encrypted channel. The following example describes how to use WPA with AES-CCMP encryption with TTLS authentication.

To set up a client with TTLS Network Authentication:

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Profile Wizard's General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Network (Infrastructure).
  6. Click Next to access the Security Settings.
  7. Click Enterprise Security.
  8. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise.
  9. Data Encryption: Select one of the following:
  10. Enable 802.1x: Selected.
  11. Authentication Type: Select TTLS to be used with this connection.

Step 1 of 2: TTLS User

  1. Authentication Protocol: This parameter specifies the authentication protocol operating over the TTLS tunnel. The protocols are: PAP (Default), CHAP, MD5, MS-CHAP and MS-CHAP-V2. See Security Overview for more information.
  2. User Credentials:

For PAP, CHAP, MD5, MS-CHAP, and MS-CHAP-V2 protocols, select one of these authentication methods:

NOTE: This option is unavailable if Pre-Logon Connect is not selected during installation of the Intel PROSet/Wireless software. Refer to Install or Uninstall the Single Sign On Feature.

  1. Roaming Identity: If the Roaming Identity is cleared, %domain%\%username% is the default.

When 802.1x MS RADIUS is used as an authentication server, the server authenticates the device that uses the Roaming Identity user name from Intel PROSet/Wireless software, and ignores the Authentication Protocol MS-CHAP-V2 user name. This feature is the 802.1x identity supplied to the authenticator. Microsoft IAS RADIUS accepts only a valid user name (dotNet user) for EAP clients. When 802.1x MS RADIUS is used, enter a valid user name. For all other servers, this is optional. Therefore, it is recommended to use the desired realm (for example, anonymous@myrealm) instead of a true identity.

Step 2 of 2: TTLS Server

NOTE: These parameters should be obtained from the administrator.

  1. Click OK to save the setting and close the page.

Set up a Client with PEAP Network Authentication

PEAP authentication: PEAP settings are required for the authentication of the client to the authentication server. The client uses EAP-TLS to validate the server and create a TLS-encrypted channel between client and server. The client can use another EAP mechanism (for example, Microsoft Challenge Authentication Protocol (MS-CHAP) Version 2), over this encrypted channel to enable server validation. The challenge and response packets are sent over a non-exposed TLS encrypted channel. The following example describes how to use WPA with AES-CCMP or TKIP encryption with PEAP authentication.

To set up a client with PEAP Authentication:

Obtain and install a client certificate. Refer to Set up the Client for TLS authentication or consult your administrator.

  1. Click Profiles on the Intel PROSet/Wireless main window.
  2. On the Profile page, click Add to open the Profile Wizard's General Settings.
  3. Profile Name: Enter a descriptive profile name.
  4. Wireless Network Name (SSID): Enter the network identifier.
  5. Operating Mode: Click Network (Infrastructure).
  6. Click Next to access the Security Settings.
  7. Click Enterprise Security.
  8. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise.
  9. Data Encryption: Select one of the following:
  10. Enable 802.1x: Selected.
  11. Authentication Type: Select PEAP to be used with this connection.

Step 1 of 2: PEAP User

PEAP relies on Transport Layer Security (TLS) to allow unencrypted authentication types (for example, EAP-Generic Token Card (GTC) and One-Time Password (OTP) support).