User's Manual

authentication process. Use this option to enforce network access control (NAC) protections on the
network. If TLS is selected, Enforce Network Access Protection is not available.
l Enforce Cryptobinding – Cryptobinding is a process that protects the authentication protocol negotiation
against man-in-the-middle attacks. The cryptobinding request and response performs a two-way
handshake between the peer and the authentication server using key materials. If TLS is selected, Enforce
Cryptobinding is not available.
The Ubuntu EAP field lets you configure the authentication protocol to use when configuring an Ubuntu
device. Options include:
l TLS
l PEAP with MSCHAPv2
When you have completed your selections on this tab, do one of the following:
l Click Previous to return to the Access tab.
l Click Next to continue to the Authentication tab.
l Click Save Changes to make the new network configuration settings take effect.
l Click Cancel to discard your changes and return to the main Onboard configuration user interface.
For information about the list of network settings, see "Network Settings " on page 130. For more information
about configuration profiles, see "Configuration Profiles" on page 165
Configuring Device Authentication Settings
On the Onboard > Configuration >Network Settings form, click the Authentication tab to display the
Enterprise Authentication form.
1. Select one of these options in the iOS & OS X Credentials drop-down list:
l Certificate – A device certificate will be provisioned and used for EAP-TLS client authentication. When
this option is selected, EAP-TLS must be selected on the Protocols tab.
l Username & Password – A device certificate will be provisioned, but the client authentication will use
unique device credentials (as for Onboard devices). When this option is selected, EAP-TTLS or PEAP must
be selected on the Protocols tab.
2. The Windows Authentication area is included on this tab if TLS was chosen for Windows EAP on the
Protocols tab.
The Certificate Store field in this area lets you specify the certificate store where the client certificate will
be provisioned. Options available for this field are:
l User – Use user-only credentials. This is the default.
l Machine – Use computer-only credentials.
Dell Networking W-ClearPass Guest 6.4 | User Guide Onboard | 135