0% found this document useful (0 votes)
17 views5 pages

Campus LAN 802.1X Setup Guide

Students joining the campus for the first time must connect to the campus LAN using 802.1x authentication, which involves generating a password and configuring their devices accordingly. Detailed steps for generating the password and configuring various operating systems (Ubuntu, Fedora, Windows, and Mac OS X) are provided. For assistance, students can contact help@iiit.ac.in with their room number and contact information if they encounter issues.

Uploaded by

tdstaniksh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views5 pages

Campus LAN 802.1X Setup Guide

Students joining the campus for the first time must connect to the campus LAN using 802.1x authentication, which involves generating a password and configuring their devices accordingly. Detailed steps for generating the password and configuring various operating systems (Ubuntu, Fedora, Windows, and Mac OS X) are provided. For assistance, students can contact help@iiit.ac.in with their room number and contact information if they encounter issues.

Uploaded by

tdstaniksh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Students who are joining in campus first time sould follow these steps

to connect the campus Lan

Campus LAN including hostel rooms are enabled with 802.1x authentication.

What is 802.1X Auth Mechanism clik here

You need to be follow two steps to achieve this.

First one is Generating 802.1x Password


Second one is change the settings on your laptop/desktop based on operating system.
Both steps are shown below.

Configure 802.1x Authentication based on various operating systems

In order to be able to authenticate yourself, you'll need to generate a 802.1x authentication


password at [Link] Please note that this is just an extra authentication
token which you will have to generate to authenticate yourself for using network resources.
This is one time only. In case you forget the generated password, you can reset it again by
visiting the above link. Use your students/research password in the field "Current LDAP
password:" and set a new password for network connectivity. Please note that this is not going
to affect your current mail/LDAP password that you use to log into portals, etc.

The videos below can be downloaded at [Link]

Generating 802.1X Password

Visit: [Link] and set your 802.1X password. You have to authenticate
yourself using your LDAP password (the one you used to login to [Link], [Link],
etc.).
Configure Ubuntu for 802.1x Authentication

[Link]

Right Click on Network icon on the top bar [ If it isn't there then try running "nm-applet"
command on terminal.] If it doesn't shows anything then, you might have to install Network
Manager Applet or equivalent, refer [Link]

Go to Edit Connections.

In section "Wired" click on "Add" tab.

Give Connection name as "Hostel Authentication", check the "Connect Automatically"


checkbox.

Click on 802.1 X Security tab, check the checkbox for "Use 802.1X security for this
connection.

Select Authentication type as PEAP (MSCHAPv2) and then enter your complete
students/research email address and use the password generated using the portal given above.

For CA Certificate, either choose 'None' (Not recommended), or download [Link]


[Link]/download/radius/IIIT-H_RADIUS_CA.pem and choose the location where it is kept
(Highly Recommended).

Click on Apply and then select this newly created connection by clicking once again on
Network icon at top.

And you are done.

The solution for the bug [Link]


1104476 has been presented as part of the video above.
Configure Fedora for 802.1x Authentication

[Link]

In case your are using Gnome3,

 Go to Network Settings

 Go to Wired connections, click add profile

 In the security tab, enable 802.1x and then follow from Step 6 onwards as mentioned
above.

If, every time every time you boot up, and it is asks for the 802.1x password, one can do
the following:

 Go to /etc/sysconfig/network-scripts/

 Open the file `ifcfg-`. The for the wired connection is mostly of the form 'enp5s0' or
'enp10s0'

 In that file, remove the line `IEEE_8021X_PASSWORD_FLAGS=user` and add the line
`IEEE_8021X_PASSWORD=`. The password should be without quotes.

 Reboot.

This method has been tested on Fedora22

Configure Windows for 802.1x Authentication

[Link]

Open explorer, right click on computer and click 'Manage'

Navigate to 'Services and Applications', open 'Services'

Open Wired AutoConfig, set the startup type to 'Automatic' and click on 'Start'

Go to 'Network and Sharing Center' and click on 'Change adapter settings'.

For your network adapter, right click, go to properties.

Select the tab Authentication. Make sure 'Enable IEEE 802.1X authentication' is ticked.
network authentication method should be 'Microsoft: Protected PEAP'

Click on settings. Make sure 'Validate server certificate' is either no ticked (Not
recommended) or download and install [Link]
H_RADIUS_CA.der and choose "IIIT-H Radius CA" (Highly Recommended)..

The authentication mechanism should be 'EAP-MSCHAPv2'. Click on Configure and make sure
that 'Automatically use my Windows logon name and password' is not ticked. Click OK.

Go to 'Additional Settings', under 'Specify authentication mode' select user authentication.
This is optional. Click on Save Credentials and enter your email id and LAN authentication
password.

Click OK.

Disable and re-enable your Network Adapter.

Note for WinXP Users: To delete cached username and password in Windows Xp follow the
instruction given at [Link]

Configure Mac OS X for 802.1x Authentication

Mac OS X should automatically detect 802.1x and display pop up window asking username and
password. Just use your IIIT email and **802.1x password** for the same.

If for some reasons (like you are in KCIS) it don't show you pop up box, then use following
steps:

Open the config in vim/emacs (I prefer vim) and update your email and password accordingly
and Save.

Double click to run/import it. In the popup (as shown below) select Continue and then Install.

Open Network Settings -> Ethernet -> Advanced and validate that you now have 802.1x
config named "Wi-Fi" in list.

You should have window like shown below, click on "Connect" next to 802.1x.
Once connected it should show "Authentication with EAP-PEAP (MSCHAPv2)".

Now again click Advanced and "Renew Lease". Enjoy!

 Note: Incase of any issues please write to help@[Link] with your room number and
cantact number along with description of the problem you are facing.

Common questions

Powered by AI

On Ubuntu, the process involves editing network connection settings via Network Manager, specifying the connection as 'Hostel Authentication', selecting PEAP (MSCHAPv2) as the authentication type, and configuring an optional CA certificate. On Windows, setup includes enabling Wired AutoConfig, setting startup type to automatic, configuring network adapter properties to enable IEEE 802.1X authentication, selecting Microsoft Protected PEAP as the network authentication method, and ensuring that the server certificate is validated with 'IIIT-H Radius CA' .

Disabling the option 'Automatically use my Windows logon name and password' is recommended to ensure that the specific 802.1X network credentials, which are distinct from the regular Windows logon credentials, are used for network authentication. This prevents the unintentional use of incorrect or unauthorized credentials, thereby enhancing security by using credentials specifically intended for network access .

The LDAP password is used as a current password to authenticate users when they generate the 802.1X authentication password. This linkage ensures that only authorized users can generate the network-specific authentication credentials. When resetting the 802.1X password, it's crucial that users verify their identity carefully using LDAP credentials, as incorrect handling may lead to unauthorized access or denial of network service. Additionally, resetting the 802.1X password does not affect the LDAP password used for other services, which ensures continuity in access to non-network related services .

Not using a CA certificate during 802.1X authentication can expose the network to man-in-the-middle attacks, as it allows an attacker to impersonate the authentication server and intercept credentials. The absence of a CA certificate verification creates risks as there is no assurance of the server's identity, potentially compromising the confidentiality and integrity of the login information transmitted over the network .

Renewing a DHCP lease is significant because it ensures that the device receives a new IP address from the network, which may be necessary after configuring the network settings or changing the authentication method. This action refreshes the network connection, helping to resolve connectivity issues and confirming that the changes in authentication settings have been successfully applied .

Using an automatically set up Wired AutoConfig service could simplify the process for users but may also introduce security risks if default configurations are not secure. Manual configuration allows custom security settings like specific authentication methods and server certificate validation, thus offering enhanced security by ensuring that all configurations align with best practices for network security and personal preferences .

On Windows XP, users must follow additional steps to delete cached usernames and passwords as detailed in Microsoft's support articles. This step is necessary to prevent old or incorrect credentials from causing authentication failures. In later Windows versions, the configuration is more integrated with network settings and includes GUI-based configuration options such as enabling and configuring Wired AutoConfig, which simplifies the process .

The primary function of 802.1X authentication in the campus network is to provide secure network access control for devices attempting to connect to the campus LAN, including hostel rooms. It ensures that only authorized users and devices can access the network by requiring a generated 802.1X password authentication step, in addition to the usual LDAP credentials, thus enhancing network security .

To configure Fedora for 802.1X authentication, a student needs to access Network Settings, add a profile under Wired connections, enable 802.1X in the security tab, and provide the necessary credentials starting from entering their email and generated password. Additionally, they might need to edit configuration files within '/etc/sysconfig/network-scripts/' to manually set the IEEE 802.1X password to prevent password prompts at every boot, and then reboot the system .

Challenges on Mac OS X might include the automatic pop-up for 802.1X authentication not appearing, especially in certain campus areas like KCIS. Resolution involves manually updating the network configuration file with the user's email and 802.1X password using a text editor. The user should then import and run this configuration, ensure 802.1X settings are properly listed in Network settings, and connect manually if needed .

You might also like