Stony Brook University Hospital
& Health
Sciences Center

Wireless Networking

Home > Instructions > Windows XP SP2 >

Windows XP Service Pack 2 (SP2)
Wireless Network Setup Instructions

Microsoft 802.1x Authentication Client Configuration

NOTE: It is imperative that your computer has the latest Windows Updates from Microsoft in order to address known vulnerabilities, fix critical issues, and allow your machine to run with the most up-to-date software to ensure the best possible wireless network performance. For more information on Windows Updates and how you can update your machine, visit http://windowsupdate.microsoft.com and select the "Express" update method.

IMPORTANT: Before proceeding with the instructions below, you need to install a Microsoft Hotfix (KB885453) to resolve a known issue with Windows XP SP2 users and wireless authentication using PEAP. Click here to install the hotfix.


1. Provided you are currently in an area that has wireless network coverage, the "sbuh" wireless network should be automatically detected by Windows XP's Wireless Zero Configuration service. Look at your taskbar or the far right -- you'll see an information bubble pop up.  To continue, either click on the message that popped up or Double-Click on the Wireless Network Connection taskbar icon.

2. This menu will show you the wireless networks that are available in the current area.  Under Choose a wireless network:, select "sbuh" from the list and click the “Connect button to continue.

3. You may receive the message below.  Although the "sbuh" wireless network does not use encryption, it is safe to connect to it in order to obtain the necessary instructions and files to configure a secure wireless network environment for your computer.  Click the Connect Anyway button to continue.

4. You should see in the Choose a wireless network window that you are connected to the "sbuh" wireless network.  You can now click on the RED “X” to close this window.  Once you have confirmed that you are connected to the "sbuh" wireless network, continue to the next step.

5. Click here to download the UHSB Root Certificate on your wireless laptop computer. You will be prompted to either open or save this file. Click "Save" to continue.

 

6. In the “Save As” dialog box, click the Desktop button on the left to save the certificate to your desktop (as shown below).

6. After the file has been saved to the desktop, the Download Complete dialog will appear.  Please select Open from this window to install the certificate on your PC.

7. Click "Install Certificate..." in the Certificate dialog box.

8. You will be presented with the Certificate Import Wizard. Accept all the default settings by clicking on "Next," "Next," and "Finish."

 

9. You will then be prompted if you want to add the UHSB certificate to the Root Store. Click "Yes" to add and then click "OK" to continue.

10. The Certificate dialog box will still be open. Click "OK" to close it.

11. Open the Network Connections window by clicking on Start > Control Panel > Network Connections (inside Network and Internet Connections in "Category View"). Under the LAN or High-Speed Internet section of this window, right-click on your "Wireless Network Connection" icon and select "Properties" from the pop-up window.

12. In the Wireless Network Connection Properties window, click on the "Wireless Networks" tab on the top. Under the Preferred networks: section, click on the "Add" button.

13. For this new preferred network, in the "Association" tab screen, enter the following information:

Network name (SSID): [Enter UHSB-Wireless.]
Network Authentication: [Select Open from the drop-down list.]
Data encryption: [Select WEP from the drop-down list.]
Network key: [This should be grayed out.]
Confirm network key: [This should be grayed out.]
Key index (advanced): [This should be grayed out.]
The key is provided for me automatically: [This box should be checked.]
The key is computer-to-computer (ad hoc)...: [This box should NOT be checked.]

14. Click on the "Authentication" tab. Make sure the settings are as follows:

Enable IEEE 802.1x authentication for this network [This box should be checked.]
EAP type: [Select Protected EAP (PEAP) from the drop-down list.]
Authenticate as computer when computer information is available [This box should NOT be checked.]
Authenticate as guest when user or computer information is unavailable [This box should NOT be checked.]

Click on the "Properties" button to configure the EAP type.

15. In the Protected EAP Properties window, make sure the settings are as follows:

Validate server certificate [This box should be checked.]
Connect to these servers: [This box should NOT be checked.]
Trusted Root Certificate Authorities [Scroll down, select and check UHSB from the list.]
Select Authentication Method: [Select Secured password (EAP-MSCHAP v2) from the drop-down list.] Enable Fast Reconnet [This box should be checked.]

Click the "Configure..." button to configure the EAP-MSCHAP v2 properties.

16. Uncheck the box "Automatically use my Windows logon name and password..." and click "OK" to continue.

17. The Wireless network properties and Protected EAP Properties windows are still open. Click "OK" for both windows to close them.

18. You should now see again the Wireless Network Connection Properties window with the "Wireless Networks" tab selected. At this point, you'll see at least two (2) preferred networks: UHSB-Wireless and sbuh. Select sbuh and click the "Remove" button to remove this item as it is no longer needed.

Next, click the "Advanced" button and select "Access point (infrastructure) networks only" then click "Close" then "OK."

19. Look at your taskbar on the far right – within a few seconds you'll see an information bubble pop up. Click on the pop-up or the Wireless Network Connection taskbar to authenticate to the UHSB-Wireless network.

20. Enter your UHMC/HSLIB domain account username as "uhmc\[username]" or "hslib\[firstname.lastname]"and password in the fields below. (Leave the "Logon domain:" field blank.) Click "OK" to authenticate with the information you just entered.

   

21. Provided you entered your UHMC/HSLIB domain account information correctly, you should now get authenticated on the UHMC/HSLIB domain. In the Network Connections window, you should see your "Wireless Network Connection" icon connected and showing "Authentication succeeded." You may now close the Network Connections window.

 

The configuration of the Microsoft 802.1x Authentication Client is now complete.

Home > Instructions > Windows XP SP2 >

Last Updated: Sept. 28, 2006
By SBUH Network Services Dept.