User's Manual

Specify Server or Certificate Name: The server name or domain to which the server
belongs, whichever of the following has been selected.
Server name must match exactly: When selected, the server name entered must
match exactly the server name found on the certificate. The server name should
include the complete domain name (for example, Servername.Domain name).
Domain name must end in specified name: When selected, the server name
identifies a domain and the certificate must have a server name belonging to this
domain or to one of its subdomains (for example, zeelans.com, where the server is
blueberry.zeelans.com)
NOTE: These parameters should be obtained from the administrator.
3. Click OK to save the setting and close the page.
Set up a Client with PEAP Network Authentication
PEAP authentication: PEAP settings are required for the authentication of the client to the
authentication server. The client uses EAP-TLS to validate the server and create a TLS-
encrypted channel between client and server. The client can use another EAP mechanism (for
example, Microsoft Challenge Authentication Protocol (MS-CHAP) Version 2), over this
encrypted channel to enable server validation. The challenge and response packets are sent
over a non-exposed TLS encrypted channel. The following example describes how to use WPA
with AES-CCMP or TKIP encryption with PEAP authentication.
To set up a client with PEAP Authentication:
Obtain and install a client certificate. Refer to
Set up the Client for TLS authentication or
consult your administrator.
1. Click Profiles on the Intel PROSet/Wireless main window.
2. On the Profile page, click Add to open the Profile Wizard's General Settings.
3. Profile Name: Enter a descriptive profile name.
4. Wireless Network Name (SSID): Enter the network identifier.
5. Operating Mode: Click Network (Infrastructure).
6. Click Next to access the Security Settings.
7. Click Enterprise Security.
8. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise.
9. Data Encryption: Select one of the following:
TKIP provides per-packet key mixing, a message integrity check and a rekeying
mechanism.
AES-CCMP (Advanced Encryption Standard - Counter CBC-MAC Protocol) is used as
the data encryption method whenever strong data protection is important.
AES-
CCMP is recommended.
10. Enable 802.1x: Selected.
11. Authentication Type: Select PEAP to be used with this connection.