User's Manual
● Specify Server or Certificate Name: The server name or domain to which the server
belongs, whichever of the following has been selected.
● Server name must match exactly: When selected, the server name entered must
match exactly the server name found on the certificate. The server name should
include the complete domain name (for example, Servername.Domain name).
● Domain name must end in specified name: When selected, the server name
identifies a domain and the certificate must have a server name belonging to this
domain or to one of its subdomains (for example, zeelans.com, where the server is
blueberry.zeelans.com)
NOTE: These parameters should be obtained from the administrator.
3. Click OK to save the setting and close the page.
Set up a Client with PEAP Network Authentication
PEAP authentication: PEAP settings are required for the authentication of the client to the
authentication server. The client uses EAP-TLS to validate the server and create a TLS-
encrypted channel between client and server. The client can use another EAP mechanism (for
example, Microsoft Challenge Authentication Protocol (MS-CHAP) Version 2), over this
encrypted channel to enable server validation. The challenge and response packets are sent
over a non-exposed TLS encrypted channel. The following example describes how to use WPA
with AES-CCMP or TKIP encryption with PEAP authentication.
To set up a client with PEAP Authentication:
Obtain and install a client certificate. Refer to
Set up the Client for TLS authentication or
consult your administrator.
1. Click Profiles on the Intel PROSet/Wireless main window.
2. On the Profile page, click Add to open the Profile Wizard's General Settings.
3. Profile Name: Enter a descriptive profile name.
4. Wireless Network Name (SSID): Enter the network identifier.
5. Operating Mode: Click Network (Infrastructure).
6. Click Next to access the Security Settings.
7. Click Enterprise Security.
8. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise.
9. Data Encryption: Select one of the following:
❍ TKIP provides per-packet key mixing, a message integrity check and a rekeying
mechanism.
❍ AES-CCMP (Advanced Encryption Standard - Counter CBC-MAC Protocol) is used as
the data encryption method whenever strong data protection is important.
AES-
CCMP is recommended.
10. Enable 802.1x: Selected.
11. Authentication Type: Select PEAP to be used with this connection.