Nokia E61 Wireless: 802.1x with EAP-PEAP and EAP-MSCHAPv2

I’m using 802.1x authentication with EAP-PEAP and EAP-MSCHAPv2 for wireless access at home which can pose a unique challenge in getting a myriad of devices to work within my network. I’m using the box standard Active Directory on Windows Sever 2003 with the Internet Authentication Service coupled to a Linksys WRT54G running custom firmware. I’m also self-signing Digital Certificates with the Certificate Authority (CA) service in Windows Server 2003. The following is what I did to get the Nokia E61 working:

Installing a CA Certificate:

  1. Point your browser to http://IPofCA/CertSrv/.
  2. Click Download a CA certificate, certificate chain, or CRL.
  3. Select the proper CA Certificate.
  4. Pick DER under Encoding method.
  5. Click Download CA Certificate.
  6. Save the certificate file (.cer extension) to any location on your PC.
  7. Connect the Nokia E61 to the PC and copy the download certificate file to any location on the phone.
  8. On the Nokia E61, browse to the location of the certificate file with the file browser and click on it to install.

Configuring Wireless on the Nokia E61:

  1. Navigate to Tools -> Settings -> Connections -> Access points. Press the Options (soft-key) -> New access point -> Use default settings.
  2. Connection name: (Pick an appropriate name)
  3. Data bearer: Wireless LAN
  4. WLAN netw. name: (Your WLAN)
  5. Network status: Public
  6. WLAN netw. mode: Infrastructure
  7. WLAN security mode: 802.1x
  8. Select WLAN security sett.
    1. WPA mode: EAP
    2. Select EAP plug-in settings
      1. Highlight EAP-PEAP and press Options (soft key) -> Enable
      2. Raise the priority of EAP-PEAP via Options (soft key) -> Raise priority until it is in position #1
      3. Uncheck everything else by pressing Options (soft key) -> Disable
      4. Go back to EAP-PEAP then press Options (soft key) -> Configure
        1. General tab:

        2. User certificate: (not defined)
        3. CA certificate: (Pick the certificate you installed above)
        4. User name in use: User-configured
        5. User name: (Your Active Directory user name ONLY! No reference to the Domain should be here. For example, “MyDomain\BobJones” or “BobJones@MyDomain” are wrong. Only “BobJones” should go in this field.
        6. Realm in use: User-configured
        7. Realm: (Your Active Directory Domain)
        8. Allow PEAPv0: Yes
        9. Allow PEAPv1: No
        10. Allow PEAPv2: No
          EAP tab:

        1. As before, select EAP-MSCHAPv2 and move it to the #1 position via Options (soft key) -> Raise priority and unselect everything else via Options (soft key) -> Disable.
        2. Select EAP-MSCHAPv2 then press Options (soft key) -> Configure
          1. User name: (Your Active Directory domain and username in the format: “MyDomain\BobJones”)
          2. Prompt password: No
          3. Password: (Your Active Directory password)
          Encryption tab:

        1. Enable all

Now go to the web browser and select your new access point to test it out. If everything went as expected, then you’ll see both the Nokia wireless icon with a little lock in the status bar and be able to browse the internet.

Comments

5 Responses to “Nokia E61 Wireless: 802.1x with EAP-PEAP and EAP-MSCHAPv2”

  1. Hannibalector on December 29th, 2006 3:34 pm

    Hi,
    that blog-entry helped me alot. thanx!

  2. Nicolas on February 16th, 2007 7:27 am

    Hello!
    Thanks for these settings, but that’s what I entered and I can’t get mine to work..
    What’s your firmware version on your Nokia e61?
    mine is a Nokia e70 and the firmware is:
    1.0610.05.07
    30-05-06
    RM-10
    Nokia E70

    Cheers,
    Nico

  3. Bacon on April 9th, 2007 12:37 am

    Mine is N80 Internet edition. Settings are quite similar but it don’t work on my environment.

    V4.0632.0.38
    13-10-2006
    RM-92
    Nokia N80 (11)

    Glad that u managed to get yours (E61) working.

  4. Dave on April 11th, 2007 5:59 am

    Thanks… downloading a certificate is one step that hadn’t occured to me… thanks!

    Note for N80 Internet Edition person… that is what I have also, and some poster in the Nokia forums claims that now EAP-PEAP and LEAP work with the latest firmware that just was realeased.

    I just upgraded yesterday and my phone now shows:

    V4.0707.0.7
    28-03-2007
    RM-92
    Nokia N80 (12)

    I still can’t get it to work though with EAP-PEAP.

  5. Marc on July 3rd, 2007 4:18 am

    Thanks. Working great on an N95 (11.00.26) also.