Security
TPR User Manual
78
certificate. After the mutual authentication was successful, the
access to the network will be freed.
Since each device needs a certificate, a PKI (Public Key
Infrastructure) must be available. User passwords are not necessary.
If you want to use the EAP-TLS authentication, you must observe
the instructions below in the indicated order. If this procedure is not
adhered to, the TPR in the network may not be addressable. In this
case you have to reset the TPR parameters; see:
Procedure
• Create a certificate request on the TPR; see:
• Create a certificate using the certificate request and the
authentication server.
• Install the CA certificate on the TPR; see:
• Install the root CA certificate of the certification authority that
has issued the certificate of the authentication server (RADIUS)
on the TPR; see: ’Installing a CA Certificate in the TPR’
• Enable the authentication method 'EAP-TLS' on the TPR.
Proceed as follows:
1. Start the TPR Control Center.
2. Select
SECURITY – Authentication
.
3. Select
TLS
from the
Authentication method
list.
4. Click
Save
& Restart
to confirm.
The settings are saved.
Configuring EAP-TTLS
Benefits and
Purpose
EAP-TTLS (Tunneled Transport Layer Security) validates the identity
of devices or users before they gain access to network resources. You
can configure the TPR for the EAP-TTLS network authentication. This
makes sure that the TPR gets access to protected networks.
Mode of Operation
EAP-TTLS consists of two phases: