16.05.2014 Views

Wireless Security.pdf - PDF Archive

Wireless Security.pdf - PDF Archive

Wireless Security.pdf - PDF Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

570 Chapter 21<br />

There are a number of ways you can register the IAS server:<br />

●<br />

●<br />

●<br />

The IAS snap-in<br />

The Active Directory Users and Computers admin tool<br />

The netsh command<br />

NOTE<br />

Perhaps the simplest way to register the IAS server is through the netsh command.<br />

To do this, log on to the IAS server, open a command prompt, and type the<br />

command netsh ras add registeredserver. If the IAS server is in a different domain, you<br />

will have to add arguments to this command. For more information on registering<br />

IAS servers, see Windows Help.<br />

Once you have installed and, if necessary, registered the IAS server(s), you can configure<br />

the Remote Access Policy . Before configuring a Remote Access Policy , make sure that<br />

you apply the latest service pack and confirm that the IAS server has an X.509 computer<br />

certificate. In addition, you should create an Active Directory Global or Universal Group<br />

that contains your wireless users as members.<br />

The Remote Access Policy will need to contain a condition for NAS-Port-Type that<br />

contains values for <strong>Wireless</strong>-Other and <strong>Wireless</strong>-IEEE802.11 (these two values are<br />

used as logical OR for this condition) and a condition for Windows-Groups[the group<br />

created for wireless users]. Both conditions have to match (logical AND) for access to be<br />

granted by the policy.<br />

The Profi le of the Remote Access Policy will need to be configured to use the Extensible<br />

Authentication Protocol , and the Smart Card or Other Certifi cate EAP type. Encryption<br />

in the Profi le should be configured to force the strongest level of encryption, if supported<br />

by the AP. Depending on the AP you are using, you might have to configure vendor<br />

specific attributes (VSA) in the Advanced tab of the Profi le . If you have to configure a<br />

VSA, you will need to contact the vendor of the AP to find out the value that should be<br />

used, if you can’t find it in the documentation.<br />

www.newnespress.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!