Checklist: Implementing 802.1X Authenticate Wired Access

Applies To: Windows Server 2008, Windows Server 2008 R2

Multiple tasks in this deployment require that specific components are in place before you can complete the task. Use this checklist to complete all tasks in the order listed.

Checklist: Implementing 802.1X Authenticated Wired Access

     Task Reference

Install and configure the following required fundamental network services: Active Directory Domain Services (AD DS), the Domain Name System (DNS) server role, the Dynamic Host Configuration Protocol (DHCP) server role. Install the Network Policy Server (NPS) component of the Network Policy and Access Services server role, and then authorize NPS in AD DS.

See Windows Server 2008 Foundation Network Guide online in the Windows Server 2008 Technical Library at https://go.microsoft.com/fwlink/?LinkId=106252. Or download Windows Server 2008 Foundation Network Guide in Word format at the Microsoft Download Center at https://go.microsoft.com/fwlink/?LinkId=105231.

Purchase, and then physically install 802.1X-capable Ethernet switches on your network.

See your switch hardware documentation.

Join computers to the domain and create user accounts in AD DS for all your domain users.

See Windows Server 2008 Foundation Network Guide online in the Windows Server 2008 Technical Library at https://go.microsoft.com/fwlink/?LinkId=106252. Or download Windows Server 2008 Foundation Network Guide in Word format at the Microsoft Download Center at https://go.microsoft.com/fwlink/?LinkId=105231.

If you are using PEAP-MS-CHAP v2, auto enroll a server certificate to NPS servers or purchase and install server certificates on your NPS servers.

See Foundation Network Companion Guide: Deploying Server Certificates online in the Windows Server 2008 Technical Library at https://go.microsoft.com/fwlink/?LinkId=108258. Download Obtaining and Installing a VeriSign Server Certificate for PEAP-MS-CHAP v2 Authentication in Word format at the Microsoft Download Center at https://go.microsoft.com/fwlink/?LinkId=33675.

If you are using EAP-TLS or PEAP-TLS without smart cards, auto enroll a server certificate to NPS servers, and auto enroll client or computer certificates to domain member client computers.

See Foundation Network Companion Guide: Deploying Server Certificates and see Foundation Network Companion Guide: Deploying Computer and User Certificates online in the Windows Server 2008 Technical Library at https://go.microsoft.com/fwlink/?LinkId=113884.

Follow the steps in this guide to deploy 802.1X authenticated wired access.

Deploying 802.1X Authenticated Wired Access