background image

HP iPAQ supported wireless authentication protocols 

HP iPAQ series with either Microsoft Pocket PC 2003 ROM Upgrade or Microsoft Pocket PC 2002 
Operating System 

Protocol model 

h5400 
(PPC 2002)

 

h5400 
(PPC 2003)

 

 
h5500

 

 
h4100

 

 
h4300

 

 
rx3000 

 
hx4700 

 
h6300 

WEP 64* 

 

 

 

 

 

 

 

 

WEP 128* 

 

 

 

 

 

 

 

 

LEAP* 

 

 

 

 

 

X

 

 

 

EAP-TLS*  

 

 

 

 

 

 

 

PEAP* X 

 

 

 

 

 

 

 

WPA* ** 

 

 

 

 

 

 

*h5400 with Microsoft Widows Pocket PC 2003 ROM upgrade 

**h5500 component of WPA supported with ROM, WLAN firmware, and driver updates 

 

LEAP 

Cisco Compatible Extensions (CCXs) are a collection of authentication protocol features that include 
some security enhancements. One part of this Cisco collection is LEAP. LEAP is not a true EAP type 
protocol, as such LEAP authentication is not supported in networks using WPA/WPA-PSK encryptions; 
support for LEAP is found only in Cisco access points and infrastructure. All HP iPAQ handheld 
devices that ship with Wi-Fi radios support LEAP. Another aspect of CCX is Cisco Key Integrity 
Protocol (CKIP), which is a Cisco proprietary implementation of temporal key support. 

A LEAP-based network authenticates user credentials before allowing access to the network; inner and 
outer authentications are not required. While this does reduce the overall infrastructure load, there are 
some security concerns surrounding this implementation. 

For additional information about the LEAP authentication protocol, refer to the Cisco web site: 

www.cisco.com

.

 

PEAP 

802.1X EAP type PEAP uses digital certificates for network server authentication and passwords for 
client authentication. PEAP requires an EAP user name, EAP password, and a Certificate of Authority 
(CA). Dynamic encryption keys are also used in this authentication type. 

Microsoft, Cisco, and RSA Security created this EAP type to reduce the certificate requirements found 
in EAP-TLS. This EAP type uses a root server certificate in setting up the secure tunnel to the 
authentication server. This allows user credentials to then be obtained and transmitted to the 
authentication server. Unlike EAP-TLS, this protocol will authenticate the user, but not necessarily the 
device. 

EAP-TLS 

802.1X EAP type Transport Layer Security (EAP-TLS) ensures Internet privacy between communicating 
applications and their users. When a server and user communicate, TLS prevents a third party from 
eavesdropping or tampering with the transmissions. A TLS connection uses an encryption method. TLS 
allows the server and user to authenticate each other and to negotiate for an encryption algorithm 
and cryptographic keys before data is exchanged. 

6

 

Summary of Contents for H4150 - iPAQ Pocket PC

Page 1: ...otocols 5 Then and now HP iPAQ wireless implementation 7 ROM and driver updates 7 rx3000 series 8 h4100 and h4300 series 13 hx4700 series 22 h5400 series with Microsoft Pocket PC 2002 27 h5400 series with Microsoft Pocket PC 2003 ROM upgrade 32 h5500 series 39 h6300 series 46 Typical WLAN setup and installation scenarios 54 The HP lab setup 55 Troubleshooting problems 56 For more information 57 ...

Page 2: ... wireless network is enabled by a collection of wireless access points residing within a small geographic area such as in an office building or wireless fidelity Wi Fi public hotspot WLANs enable a variety of mobile transactions such as Internet and e mail access and sophisticated tasks such as allowing sales people to access customer records from customer locations The signal strength of a WLAN c...

Page 3: ...entitled secure wireless local area networks with hp mobile devices located at http www hp com sbso wireless secure_wlan_mobile pdf What s the difference between wireless and mobile A mobile device is a portable device A desktop could be a mobile device if it could be easily carried around A wireless device such as the HP iPAQ rx3000 h4100 h4300 hx4700 h5400 h5500 or h6300 series handheld device p...

Page 4: ...o subnets allows it to be connected to the Internet with a single shared network address WLAN standards IEEE wireless standards such as 802 11 have undergone many improvements and addendums since they were first defined The following list offers a high level description of each of the better known standards 802 11 which operates in the 2 4 GHz frequency band and offers only 2 megabits per second M...

Page 5: ... transition roaming technique is best suited to networks that have access points on different subnetworks with different address ranges The HP iPAQ h5500 series supports this type of roaming The location transition roaming algorithm enables a handheld device to move seamlessly between access points without disconnecting from the network Using this roaming algorithm a given device will not change i...

Page 6: ...this does reduce the overall infrastructure load there are some security concerns surrounding this implementation For additional information about the LEAP authentication protocol refer to the Cisco web site www cisco com PEAP 802 1X EAP type PEAP uses digital certificates for network server authentication and passwords for client authentication PEAP requires an EAP user name EAP password and a Ce...

Page 7: ...mobile devices to help customers expand their working world Today HP engineering works continuously to provide enhancements new functionality and evolving products that will keep customers on the cutting edge of the still emerging wireless technology A key component in enabling the HP wireless vision involves the process of roaming Roaming is discussed in more detail in the next section but it is ...

Page 8: ...From the Today screen tap the wireless icon and then tap the Wi Fi button When Wi Fi is on the wireless LED on the top left corner of your HP iPAQ turns blue and the Wi Fi button turns amber Once you connect to a wireless network the Wi Fi button turns green Note Before accessing your wireless network you must turn on Wi Fi When the blue wireless LED is on and the arrows at the top of the screen s...

Page 9: ...orking with HP supported wireless authentication protocols Instructions for configuring an HP iPAQ with a high security authentication protocol vary between product series and the selected protocol Other affecting issues are ROM releases operating systems and protocol specific requirements to name a few The following instructions are intended as a roadmap to help you get started Actual implementat...

Page 10: ...ings Wireless Networks list box You can choose whether to connect only to preferred networks or to have your HP iPAQ search for and connect to any available network preferred or not To search for networks to access From the iPAQ Wireless screen tap Settings Wireless tab In the Networks to access box tap the type of network you want to connect to All Available Only access points or Only computer to...

Page 11: ...r ISP or private network does not use dynamically assigned IP addresses If you are not sure check with your network administrator To change TCP IP settings 1 Contact your ISP or network administrator to determine your IP address subnet mask and default gateway if needed 2 Be sure Wi Fi is powered on 3 Tap the iPAQ Wireless icon 4 From the iPAQ Wireless screen tap Settings Network Adapters tab 5 In...

Page 12: ...r for the proxy server name server type port type of Socks protocol used and your user name and password 2 Be sure Wi Fi is powered on 3 Tap the Connectivity icon in the Navigation bar and then Settings Tasks tab 4 Under My Work Network tap Set up my proxy server Proxy Settings tab 5 Tap the This network connects to the Internet and This network uses a proxy server to connect to the Internet check...

Page 13: ...n or in the Navigation bar at the top of the device or tap Start and then tap iPAQ Wireless 2 If you tapped the Connectivity icon in the Navigation bar then tap Turn Wireless On or Turn off flight mode when the Connectivity box appears Or tap Start iPAQ Wireless and then tap the WLAN icon the iPAQ Wireless screen appears with the message Tap a button to turn an individual wireless feature ON OFF T...

Page 14: ...ut the network key then contact the network administrator Manually entering new network settings A wireless network can be added either when the network is detected the Network Indicator icon is showing in the Navigation bar or manually by entering setting information To manually add a wireless network perform the following steps 1 Turn on the WLAN 2 Tap the Connectivity icon or at the top tap Set...

Page 15: ...P iPAQ Pocket PC h4100 or h4300 series devices in a CISCO LEAP environment ROM version 1 10 Perform the following steps to begin setting up an HP supported authentication protocol on an HP iPAQ Pocket PC h4100 or h4300 series handheld device with ROM version 1 10 1 After the wireless network has been added then on the Configure Wireless Network screen tap the Network Key tab If in doubt about poss...

Page 16: ...upports the 802 1x protocol then contact the network administrator 6 Tap OK twice to exit the Configure Network Authentication window and Configure wireless networks window 7 Tap the Select Networks box to open the Network Management window Under Programs that automatically connect to the Internet should connect using tap the down arrow and select My Work Network Tap OK three times to return to th...

Page 17: ...ld down the stylus for a few seconds until the Connect Remove Settings drop down box appears Tap Remove Settings Or on the Start menu tap Settings the Connections tab the Connections icon the Advanced tab and then Network Card Tap the Wireless tab highlight the desired connection to delete and hold the stylus down a few seconds until the drop down box appears 5 Tap Remove Settings Monitoring signa...

Page 18: ...e no change If unsure about TCP IP settings using dynamically assigned IP addresses then contact the network administrator Perform the following steps to change the TCP IP settings on an HP iPAQ Pocket PC h4100 or h4300 series handheld device 1 If the IP address subnet mask and default gateway are not known then contact the system administrator 2 Turn on the WLAN 3 Tap the Connectivity icon Settin...

Page 19: ...ote If connecting to the ISP at home then tap The Internet If connecting to a private network such as a corporate network at work then tap Work 5 In the Tap an adapter to modify settings box tap iPAQ WLAN Wireless Adapter 6 Tap the Name Servers tab and enter the appropriate information 7 Tap OK to save the new settings Configuring ISP settings To add edit or delete the ISP settings on an HP iPAQ h...

Page 20: ...orporate network via the Internet If the name password domain name TCP IP settings and host name or IP address of the VPN server are not known then contact the network administrator Perform the following steps to set up a VPN server connection Note At this point you may use the New Connection wizard to set up a VPN connection or continue with the steps below The New Connection wizard provides onli...

Page 21: ...settings should be changed only if one of the following situations exists The server to which the connection is made does not use dynamically assigned IP addresses so the TCP IP settings must be entered The DNS or WINS settings on the server must be changed 13 Tap Finish Starting a VPN connection If an HP iPAQ Pocket PC h4100 or h4300 series handheld device is connected to the ISP or private netwo...

Page 22: ...cess point If Wi Fi is off the Wi Fi icon turns from amber or green to gray Battery saving tip Turn Wi Fi off when you are not using it Connecting to a network Perform the following steps to connect to a WLAN 1 If one or more broadcast networks are present the Network Indicator icon appears in the navigation bar Tap the network you want to connect to then tap whether the network connects to The In...

Page 23: ...site www cisco com Perform the following steps to set up an HP supported authentication protocol on an HP iPAQ Pocket PC hx4700 series handheld device 1 After the wireless network has been added then on the Configure Wireless Network screen tap the Network Key tab If in doubt about possible required authentication information then contact the system administrator Note To determine whether authenti...

Page 24: ... access box tap the type of network you want to connect to All Available Only access points or Only computer to computer 4 To connect only to networks that have already been configured clear the Automatically connect to non preferred networks checkbox Note If the Automatically connect to non preferred networks checkbox is checked then the HP iPAQ will detect any new networks and provide the opport...

Page 25: ...l not need to change TCP IP settings unless your ISP or private network does not use dynamically assigned IP addresses If you are not sure check with your network administrator To change TCP IP Settings 1 Contact your ISP or network administrator to determine your IP address subnet mask and default gateway if needed 2 Be sure Wi Fi is powered on 3 From the iPAQ Wireless screen tap Wi Fi Settings N...

Page 26: ...y icon in the Navigation bar and then tap Settings Tasks tab 4 Under your work network tap Set up my proxy server Proxy Settings tab 5 Tap the This network connects to the Internet and This network uses a proxy server to connect to the Internet checkboxes 6 In the Proxy server box enter the proxy server name 7 If you need to change port number or proxy server type settings tap the Advanced button ...

Page 27: ...n If you are using A pre shared key enter the key provided by your network administrator and then tap Next Note If you selected PPTP in the previous screen this step is skipped 10 Enter the user name password and domain name provided by your network administrator Note If a domain name was not provided you may be able to connect without entering one 11 To change advanced settings tap the Advanced b...

Page 28: ...e Connections screen tap the Work Settings or another network from the drop down list in the box next to the network handheld device icon 3 Tap the Connect box beneath the connection Note If in doubt about whether the network uses proxy settings or if the display prompts for a WEP then contact the system administrator Manually entering new network settings To manually add settings to a wireless ne...

Page 29: ...an HP supported authentication protocol on an HP iPAQ Pocket PC h5400 series with Microsoft Pocket PC 2002 handheld device 1 Follow steps 1 through 7 in the preceding section Manually entering new network settings 2 Select either 64 bit or 128 bit encryption from the Wireless Encryption WEP drop down list 3 Select whether they keys are alphanumeric or hexadecimal 4 Enter the key in the appropriate...

Page 30: ...list 4 Tap the Delete button 5 Tap Yes to confirm Monitoring signal strength and status Perform the steps in either of the following scenarios to view the signal strength between the HP iPAQ Pocket PC h5400 series with Microsoft Pocket PC 2002 handheld device and the access point WLAN connection Note The signal strength icon will only display when a connection is present 1 On the Today screen tap ...

Page 31: ...o change If unsure whether the TCP IP settings use dynamically assigned IP addresses then contact the network administrator Perform the following steps to change the TCP IP settings on the HP iPAQ Pocket PC h5400 series with Microsoft Pocket PC 2002 handheld device 1 Turn on the WLAN 2 On the Today screen tap Start iPAQ Wireless iPAQ WLAN 3 Select the desired profile from the Profile drop down lis...

Page 32: ...ction includes the following topics Turning on and off the WLAN Connecting to a network Manually entering new network settings Working with HP supported wireless authentication protocols Searching for networks to access Managing wireless networks Network settings VPN server connections Turning on and off the WLAN Perform the following steps to turn on or off the WLAN 1 On the Today screen tap Star...

Page 33: ...es with Microsoft Pocket PC 2003 perform the following steps 1 Turn the WLAN on see instructions under Turning on and off the WLAN 2 Tap the Connectivity icon or at the top tap Settings tap the Advanced tab and then tap Network Card 3 On the Configure Wireless Networks screen tap the Wireless tab at the bottom 4 Still on the Configure Wireless Networks screen in the Wireless networks box tap Add N...

Page 34: ...nt then tap the Enable network access using IEEE 802 1x checkbox and then tap the appropriate authentication protocol TLS PEAP LEAP 802 1x provides an increased level of security If unsure whether the network environment supports the 802 1x protocol then contact the network administrator 3 Tap OK twice to exit the Configure Network Authentication window and Configure Wireless Networks window 4 Tap...

Page 35: ...e Today screen tap Settings Connections tab Connections icon Advanced Network Card Give the connection a name tap the Wireless tab highlight the desired connection to delete and hold the stylus down a few seconds until the drop down box appears 4 Tap Remove Settings Monitoring signal strength and status Perform the following steps to view the signal strength between the HP iPAQ Pocket PC h5400 ser...

Page 36: ...ps to change the TCP IP settings on the HP iPAQ Pocket PC h5400 series with Microsoft Pocket PC 2003 ROM upgrade handheld device 1 If the IP address subnet mask or default gateway are not known then contact the system administrator 2 Turn on the WLAN 3 Tap the Connectivity icon Settings Advanced tab Network Card On the Configure Wireless Networks screen tap Network Adapters Or on the Today screen ...

Page 37: ... tap Work 6 In the Tap an adapter to modify settings box tap iPAQ WLAN Wireless Adapter 7 Tap the Name Servers tab and enter the appropriate information 8 Tap OK to save the new settings Changing ISP settings To add edit or delete the ISP settings on an HP iPAQ h5400 series with Microsoft Pocket PC 2003 ROM upgrade handheld device perform the following steps 1 On the Today screen tap Start Setting...

Page 38: ...n screen enter a name for the connection in the Name box Enter the appropriate information provided by the network administrator in the Host name IP box 5 Tap the appropriate VPN type received from the network administrator and then tap Next 6 On the My VPN screen tap either A certificate on this device or A pre shared key If you tapped A pre shared key enter the key number in the box 7 On the My ...

Page 39: ...ngs perform the following steps 1 Contact the ISP or network administrator to obtain the following Proxy server name Server type Port Type of Socks protocol used and the user name and password 2 Turn on the WLAN 3 On the Today screen tap Start Settings Connections tab Connections icon Tasks tab 4 On the Connections screen under My Work Network tap Edit my proxy server and then the Proxy Settings t...

Page 40: ...he Navigation bar Tap the icon when the Multiple Networks Detected pop up box appears tap the desired network Figure 9 The network indicator pop up box 2 In the same pop up box under This network connects me to tap the Internet button if the network connects to the Internet without using proxy settings or the Work button if the network uses proxy settings If doubt exists about the whether the netw...

Page 41: ...llowing steps to set up an HP supported authentication protocol on an HP iPAQ Pocket PC h5500 series handheld device 1 After the wireless network has been added then on the Configure Wireless Networks box highlight the appropriate default setting or create a new setting and then tap the Network Key tab Note The HP iPAQ Pocket PC h5500 series handheld device has one of two ROM releases The setup st...

Page 42: ...the Automatically connect to non preferred networks checkbox is checked then the HP iPAQ will detect any new networks and provide the opportunity to configure them Managing wireless networks Viewing or editing a network 1 Turn on the WLAN 2 Tap Start Settings Connections tab Connections icon Advanced tab Network Card 3 In the Configure Wireless Networks box tap the name of the desired network to r...

Page 43: ...f unsure whether the TCP IP settings use dynamically assigned IP addresses then contact the network administrator Perform the following steps to change the TCP IP settings on an HP iPAQ Pocket PC h5500 series handheld device 1 If the IP address subnet mask or default gateway are not known then contact the system administrator 2 Turn on the WLAN 3 Tap Start Settings Connections tab Connections icon...

Page 44: ...r to modify settings box tap iPAQ USB Wireless Adapter 6 Tap the Name Servers tab and enter the appropriate information Changing ISP settings To add edit or delete the ISP settings on an HP iPAQ h5500 series handheld device perform the following steps 1 Tap Start Settings Connections tab Connections icon 2 Under your ISP connection tap Add a new modem connection to establish a new modem connection...

Page 45: ...ng the keyboard question mark 1 Turn on the WLAN 2 On the Today screen tap Start Settings the Connections tab the Connections icon and the Tasks tab 3 Under My Work Network tap Add a new VPN server connection 4 On the Make New Connection screen enter a name for the connection in the Name box Enter the appropriate information provided by the network administrator in the Host name IP box 5 Tap the a...

Page 46: ...s 1 Contact the ISP or network administrator to obtain the following Proxy server name Server type Port Type of Socks protocol used and the user name and password 2 Turn on the WLAN 3 On the Today screen tap Start Settings the Connections tab the Connections icon and then the Tasks tab 4 On the Connections screen under My Work Network tap Set up my proxy server 5 Tap the This network connects to t...

Page 47: ...resent the Network Indicator icon appears in the Navigation bar Tap the network you want to connect to and then tap whether the network connects to the Internet does not use proxy settings or Work uses proxy settings 2 If you are prompted for a network key enter it and tap Connect If you are not sure contact your network administrator Manually entering new network settings A wireless network can b...

Page 48: ...be available Differences in functionality among non CCX wireless devices with CCX certification features enabled should be expected Table 1 Cisco proprietary features that are officially supported non supported or incompatible with the h6300 series Officially supported features Non supported compatible features Incompatible features Non EAP Open WEP Shared WEP WPA PSK TKIP only ad hoc Optional Cis...

Page 49: ...hree times to return to the Today screen 8 Perform a soft reset of the HP iPAQ When the wireless card associates with an access point the Logon Window pop up box appears Select the appropriate keyboard and enter the user name and the password to be used Leave the domain field blank and tap the Save Password box Connectivity Issues with non supported features for h6300 series Note While the h6300 s...

Page 50: ...ave changes 3 From a console telnet session configure for each interface ap config if no dot11 qos mode wmm if no QoS features are required used Searching for networks to access Networks that you have already configured are preferred networks and are listed in Wireless Networks You can choose whether to connect only to preferred networks or to have your HP iPAQ search for and connect to any availa...

Page 51: ... access point connections 1 Tap the Connectivity icon in the navigation bar 2 When the drop down Connectivity box displays you are able to view the name SSID of the network the HP iPAQ is connected to and an icon displaying the signal strength Note The signal strength icon will not be displayed if a connection is not present Figure 11 Signal strength indicator Network settings Locating an IP addre...

Page 52: ... network at work you should select Work 5 In the Tap an adapter to modify settings box tap iPAQ Wi Fi Wireless Adapter 6 Tap the IP Address tab 7 Tap Use specific IP address and enter the requested information 8 Tap OK to save your settings Changing DNS and WINS settings Note Most ISPs and private networks now use dynamically assigned IP addresses You will not need to change DNS and WINS settings ...

Page 53: ...r the U S area code and telephone number to be dialed for the connection tap Next 7 Type the desired user name and password for the connection 8 Type the domain if a domain was provided by the ISP or network administrator 9 Tap Finish To change an existing connection 1 Tap Start Settings the Connections tab and then the Connections icon 2 On the Connections screen tap Manage existing connections 3...

Page 54: ...ou selected A pre shared key enter the key provided by your network administrator then tap Next 10 Enter the user name password and domain name provided by your network administrator Note If a domain name was not provided you may be able to connect without entering one 11 To change advanced settings tap the Advanced button Note You will not need to change advanced settings unless the server to whi...

Page 55: ...P Cisco 1200 Series Internet Operating System IOS Windows 2003 Server Operating System Performance Throughput Cisco Aironet1200 Series Access Point NetIQ Chariot Software WEP Cisco Aironet1200 Series Access Point with IOS firmware and Cisco Aironet 1200 Series Access Point with Vx Works firmware HP WL410 Wireless SMB Access Point HP WL510 Wireless Enterprise Access Point RoamAbout Access Point 64 ...

Page 56: ...imeout to increase the timeout between sending the WPA key packets from the default value 100 ms to a value between 101 and 200 ms Check the access point settings ensure that the security setting allows third party or non Cisco devices to associate and authenticate on the network If a Cisco LEAP access point is being used and the WLAN connection does not work check to make sure of the following Th...

Page 57: ...5 Hewlett Packard Development Company L P The information contained herein is subject to change without notice The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services Nothing herein should be construed as constituting an additional warranty HP shall not be liable for technical or editorial errors or omissions contain...

Reviews: