User manual

Security
TPG User Manual 64
configure the TPG for the EAP-TLS network authentication. This
makes sure that the TPG gets access to protected networks.
Mode of Operation
EAP-TLS describes a certificate-based authentication method via a
RADIUS server. For this purpose, certificates are exchanged between
the TPG and the RADIUS server. An encrypted TLS connection
between the TPG and the RADIUS server is established in this
process. Both RADIUS server and TPG need a valid, digital certificate
signed by a CA. The RADIUS server and the print server must validate
the certificate. After the mutual authentication was successful, the
access to the network will be freed.
Since each device needs a certificate, a PKI (Public Key
Infrastructure) must be available. User passwords are not necessary.
If you want to use the EAP-TLS authentication, you must observe
the instructions below in the indicated order. If this procedure is not
adhered to, the TPG in the network may not be addressable. In this
case you have to reset the TPG parameters; see: Ö74.
Procedure
Create a certificate request on the TPG; see: Ö58.
Create a CA certificate using the certificate request and the
authentication server.
Install the CA certificate on the TPG; see: ’Saving the CA
Certificate in the TPG’ Ö59.
Install the root certificate of the authentication server on the
TPG; see: ’Saving the root certificate on the TPG’ Ö60.
Enable the authentication method 'EAP-TLS' on the TPG.
Proceed as follows:
1. Start the TPG Control Center.
2. Select SECURITY – Authentication.
3. Select TLS from the Authentication method list.
4. Click Save & Restart to confirm.
ª The settings are saved.