User's Guide for 802.11g Radios
from Summit Data Communications, Inc.

XP Software Version 1.04


Table of Contents

1.0 Introduction
    1.1 Product Overview
    1.2 Security Capabilities
2.0 Getting Started
   
2.1 Install the Summit Software
    2.2 Install the Radio
    2.3 Configure the Manner of Obtaining an IP Address
    2.4 Connect to Your WLAN
        2.2.1 Preferred Method: Use SCU
        2.4.2 Alternative: Use Windows Zero Config

    2.5 Interact with the Radio
3.0 Using the Summit Client Utility
    3.1 Initializing SCU
    3.2 Main Window
    3.3 Profile Window
        3.3.1 Using Scan To Create a Profile
        3.3.2 EAP Credentials
        3.3.3 Encryption
        3.3.4 ThirdPartyConfig
        3.3.5 EAP-FAST

    3.4 Status Window
    3.5 Diags Window
    3.6 Global Window
Appendix: FCC Information
 


1.0 Introduction

Thank you for choosing one of the following wireless LAN radio modules or cards from Summit Data Communications, Inc.:

Your Summit WLAN radio, or WLAN client adapter, enables a computing device to communicate to a computing network using the IEEE 802.11g and IEEE 802.11b protocols.

This manual is a user’s guide for a Summit radio that is installed on a computing device that is running Windows XP Professional or Windows XP Embedded.

The hardware components and software for all Summit radios are the same. A 20G version is a 10G version with integrated antennas. (In fact, if you look at the back of a CF20G, you'll see a label for the CF10G.) A PCMCIA version is a CF version in a specially designed CF-to-PCMCIA carrier. The miniature CF version is essentially the CF version with a different layout and a different (Molex) connector. The software that Summit provides for its radios includes:

Your Summit radio is Wi-Fi CERTIFIED®.  The Wi-Fi Alliance certifies that Summit radios support 802.11b and 802.11g with WPA and WPA2, both Personal and Enterprise. The EAP type tested by the Wi-Fi Alliance was PEAP-MSCHAPv2. For details, visit the Wi-Fi Alliance Web site at http://www.wi-fi.com, click on the “Wi-Fi CERTIFIED® Products” link, and search for Summit Data Communications.

On Windows CE and Windows Mobile, your Summit radio is certified to Version 3 of the Cisco Compatible Extensions (CCX) specification for application-specific devices (ASDs). For an overview of CCX, go to http://www.cisco.com/web/partners/pr46/pr147/partners_pgm_concept_home.html. For details on the features in CCX V3 for ASDs, go to http://www.cisco.com/warp/public/765/ccx/versions_and_features.shtml.

1.1 Product Overview

For an overview of Summit WLAN radios, go to http://www.summitdatacom.com/product.htm.

1.2 Security Capabilities

Summit radios typically are used in business-critical mobile devices that transmit sensitive information, such as inventory data and patient information, over the air that separates the mobile devices from the network. To protect transmitted data as well as the mobile devices and network infrastructure that transmit and receive the data, an organization’s IT department often imposes on mobile devices the same strict security standards imposed on other client devices. Summit’s integrated approach to security simplifies the task of enforcing a consistent security policy on all devices.

A foundational element of the IEEE 802.11i WLAN security standard is IEEE 802.1X, and a critical application on a mobile device is an 802.1X supplicant. Such a supplicant provides an interface between the radio and the operating system and supports the authentication and encryption elements required for 802.11i, also known as Wi-Fi Protected Access 2 or WPA2, as well as predecessors such as WPA and WEP. Summit software includes an integrated supplicant that supports a broad range of security capabilities, including:

The following EAP types are supported by the Summit software integrated supplicant and can be configured in SCU:

PEAP and EAP-TLS require the use of Windows facilities for the configuration of digital certificates.

With each of the EAP types supported by SCU, if authentication credentials are not stored in the active configuration profile, then the user is prompted to enter those credentials the first time the radio tries to associate to an AP that supports 802.1X (EAP).

2.0 Getting Started

Before you can use a Summit radio, you or your device manufacturer must install Summit software and the radio in your computing device. If you are doing the software and hardware installation, then you will need the following:

It is recommended that you install the software before you install the hardware. If you insert the card in your device before you install the software, then the "Found New Hardware Wizard" screen will appear, and you must select "Cancel" to cancel the Hardware Wizard.

2.1 Install the Summit Software

On Windows XP, the process for installing Summit software is managed by a setup wizard named SummitInstall.msi. When you run this program, a sequence of screens guides you through the installation process.

After you click the Next button on the initial welcome screen, you advance to a screen, shown below, on which you specify the folder in which Summit software will be installed.

Once you click the Next button on this screen, you advance to a third screen where you click the Install button to complete the installation process.

You can use the same setup wizard to uninstall or upgrade Summit software.

2.2 Install the Radio

Once you have installed the Summit software, you must install the Summit radio in a CF or PCMCIA slot. Instructions on installing a Summit radio module in an internal slot (within a device) are available only to device manufacturers.

To install a 20G Series radio card, you simply insert the card in an external card slot. To install a 10G Series radio module in an external slot, you must complete two types of connections:

The standard approach is to insert the module in the external slot first and then connect the antenna(s). If the antenna connectors on the radio module are not visible when the module is inserted, however, then you will need to connect the antenna(s) before inserting the module in the external slot.

On Windows XP, when you insert the radio module or card into a CF or PCMCIA external slot for the first time, the operating system will recognize that a new hardware device is being installed and display a series of screens so that you can associate a device driver to that device. On the initial screen, select “No, not this time” for the question on whether or not Windows should connect to Windows Update to search for the driver. On the next screen, you can choose to install the software automatically. Windows will locate the driver and begin to install it.

Because the Summit driver has not been signed as a part of Windows Logo (also known as WHQL) testing, Windows displays a warning message, shown on the next page, when it starts to install the driver. Tap or click the “Continue Anyway” button so that Windows continues with driver installation.

To connect the antennas, take each antenna and its cable, which is fitted with a Hirose U.FL connector, and attach the antenna cable to the radio module by mating the U.FL connector on the antenna cable with a U.FL connector on the radio module. If you have a single antenna, connect it to the main antenna connector, which is located to the right of the auxiliary connector, and set the Rx Diversity and Tx Diversity global settings to Main Only (see Section 3.6). If you have two antennas for diversity, connect the primary antenna to the main antenna connector and the secondary antenna to the auxiliary antenna connector, which is located to the left of the main connector.

2.3 Configure the Manner of Obtaining an IP Address

Here are the steps required to use facilities on Windows XP to configure the manner of obtaining an IP address:

You can configure DNS servers statically, but if you use DHCP for IP address assignment then DNS usually is supplied by the same server that assigns IP addresses.

2.4 Connect to Your WLAN

Two methods exist for configuring the radio for operation on a wireless network. The first and preferred method is to use SCU, which is described in detail in the next section of this guide. The other method is to use WZC, which is the Microsoft program for configuring any WLAN card.

2.4.1 Preferred Method: Use SCU

To use SCU to connect to your wireless network, first initialize SCU (see Section 3.1) and go to the Profile window by tapping the Profile tab. The Default configuration profile, if not modified, does not specify an SSID, an EAP type, or a method of data encryption. As a result, if the Default profile is the active profile, then the radio will associate only to an access point that broadcasts its SSID and requires no EAP type and no encryption. If no profile has been created for the WLAN to which you want to connect, then use the following steps to create and select a profile for your WLAN:

To assist with troubleshooting of any connectivity issues, the Status window reflects the current state of the device and the Diag window allows for DHCP renewal and ICMP Echo Requests, also known as Pings, to be sent by the device. You can learn more about using these SCU windows in Section 3.

2.4.2 Alternative: Use Windows Zero Config

Another method of configuring the radio is through the operating system’s WZC feature. If the radio is inserted and the SCU is not configured, then WZC will attempt to use the card to attach to an available WLAN. A pop-up box will appear that indicates which networks (SSIDs) have been located and asks the user which network the device should use. Selecting an SSID that requires security will prompt the user for security keys or credentials. If the correct credentials are entered, then the WZC process will attempt to associate, authenticate, and run the appropriate encryption required to connect the user to the network.

If you want the Summit radio in your client device to connect not to a WLAN infrastructure but to a WLAN radio in another client device using ad hoc (or peer-to-peer) mode, then WZC is your only option. Ad hoc mode is not supported by SCU.

2.5 Interact with the Radio

You can configure radio and security settings, monitor performance and activity, and troubleshoot issues with the radio using any of the following:

The rest of this guide assumes that you are using SCU for all interactions with the radio.

3.0 Using the Summit Client Utility

The Summit Client Utility (SCU) is an application designed for end users and administrators of mobile devices that use a Summit radio. Using SCU, an end user can:

After completing an administrator login to the utility, a user can perform these additional tasks:

The SCU provides a graphical user interface (GUI) for access to all of its functions. Access to these functions also is available through an application programming interface (API) that is defined in a software developer's kit (SDK). Through the API, an application such as Wavelink Avalanche can manage Summit radios.

3.1 Initializing SCU

To initialize SCU on Windows XP, go to the Start menu, locate the SCU icon, and click it.

The SCU has five windows: Main, Profile, Status, Diags (or Troubleshooting), and Global. SCU displays one tab for each window. To view a window, simply tap its tab. Each window is described in more detail in this section.

3.2 Main Window

Figure 1 below is an example of a Main window:


Figure 1: Main Window

Here are the highlights of the Main window, beginning at the top of the window:

3.3 Profile Window

Profile settings are radio and security settings that are stored in the registry as part of a configuration profile. When a profile is selected as the active profile on the Main window, the settings for that profile become active.  When the profile named ThirdPartyConfig is selected, a power cycle also must be performed.

If it is not modified, then the Default profile does not specify an SSID, an EAP type, or a method of data encryption. As a result, if the Default profile is the active profile, then the radio will associate only to an access point that broadcasts its SSID and requires no EAP type and no encryption.

On the Profile window, an administrator can:

Profile changes made on the window are saved to the profile only when the Commit button is pressed.

Figure 2 below is an example of a Profile window:


Figure 2: Profile Window

Here are the highlights of the Profile window:

Here are the radio settings available on the Profile window:

Here are the security settings available on the Profile window:

3.3.1 Using Scan To Create a Profile

When you tap the Scan button on the Profile window, SCU opens a window that lists APs that are broadcasting their SSIDs. Figure 3a below is an example of a Scan window:


Figure 3a: Scan Window

Each row shows an AP's SSID, its received signal strength indication (RSSI), and whether or not data encryption is in use (true or false). You can sort the list by clicking on the column headers. If the scan finds more than one AP with the same SSID, the list displays the AP with the strongest RSSI and the least security. Every five seconds, the Scan window updates the RSSI value for each of the APs in the list. To scan for new APs and view an updated list, tap the Refresh button.

If you are authorized as an administrator in SCU, you can create a profile for any SSID in the list. To do so, double-click the row for the SSID or tap the row and tap the Configure button. SCU will display a dialog box such as the one shown in Figure 3b below:


Figure 3b: Create a Profile?

If you tap the Yes button on the dialog box, then you will return to the Profile window to create a profile for that SSID, with the profile name being the same as the SSID (or the SSID with a suffix such as "_1" if a profile with the SSID as its name exists already). SCU will fill in the encryption type and EAP type; you can change those and other profile settings as well as enter authentication credentials and static encryption keys.

3.3.2 EAP Credentials

Figure 4 below is an example of a PEAP credentials window:


Figure 4: PEAP Credentials Window

The 802.1X authentication type PEAP relies upon information in digital certificates that are created by a certificate authority, or CA. To enable a client device to validate (or authenticate) the server used for PEAP authentication, you must provision a root CA certificate, distribute it to that client, and store it in a directory with a path that you specify as the value for Certs Path on the SCU Global window. If you don't specify a Certs Path value, then SCU uses for the Certs Path value the path to the certs directory that is off the SCU folder.

Instead of using digital certificates, EAP-FAST relies upon strong shared-secret keys that are unique to users. These secrets are called protected access credentials (PACs) and can be created automatically or manually.  With automatic or in-band provisioning, the PAC is created and distributed to the client device in one operation. With manual or out-of-band provisioning, the PAC is created in one step and then must be distributed to the client device separately. SCU supports PACs created automatically or manually. When you create a PAC manually, you must load it to the directory identified by the Certs Path global setting. Be sure that the PAC file does not have read-only permissions set, or SCU will not be able to use the PAC.

Here are the credentials for each EAP type:

There are no default values for credentials. Here are some important notes on entering credentials for EAP authentication:

Alternatively, the user can select another profile as the active profile and then switch back to the profile for which EAP authentication was canceled.

3.3.3 Encryption

Cisco TKIP
If the active profile has an Encryption setting of CKIP Manual or CKIP Auto, then the Summit radio will associate or roam successfully to an AP is configured with:

WPA Migration Mode and WPA2 Mixed Mode
Summit radios support two special access point (AP) settings: WPA Migration Mode and WPA2 Mixed Mode. WPA Migration Mode is a setting on Cisco APs that enables both WPA and non-WPA clients to associate to an AP using the same SSID, provided that the AP is configured for Migration Mode (WPA optional with TKIP+WEP128 or TKIP+WEP40 cipher). In other words, WPA Migration Mode means WPA key management with TKIP for the pairwise cipher and TKIP, 128-bit WEP, or 40-bit WEP for the group cipher. When WPA Migration Mode in use, you can select WPA TKIP or Auto WEP for your Summit radio encryption type.

WPA2 Mixed Mode operation enables both WPA and WPA2 clients to associate to an AP using the same SSID. WPA2 Mixed Mode is defined by the Wi-Fi Alliance, and support for the feature is a part of Wi-Fi certification testing. When WPA2 Mixed Mode is configured, the AP advertises the encryption ciphers (TKIP, CCMP, other) that are available for use, and the client selects the encryption cipher it wants to use. In other words, WPA Mixed Mode means WPA key management with AES for the pairwise cipher and AES or TKIP for the group cipher. When WPA2 Mixed Mode in use, you can select WPA2 AES or WPA TKIP for your Summit radio encryption type.

3.3.4 ThirdPartyConfig

If the profile named “ThirdPartyConfig” is selected as the active profile, then SCU works in tandem with WZC or another third-party application for configuration of all radio and security settings for the radio.  The third-party application must be used to define the SSID, Auth Type, EAP Type, and Encryption settings. SCU can be used to define the Client Name, Power Save, Tx Power, Bit Rate, and Radio Mode settings. Those SCU profile settings, all SCU global settings, and the third-party application settings are applied to the radio when ThirdPartyConfig is selected as the active profile and a power cycle is performed.

On some devices that run Pocket PC or Windows Mobile, the radio will not associate if WPA with pre-shared keys, or WPA-PSK, is used with WZC. If that is the case for your device, then to use WPA-PSK you must use an SCU profile other than ThirdPartyConfig.

3.3.5 EAP-FAST

The 802.1X authentication types PEAP and EAP-FAST use a client-server security architecture that encrypts EAP transactions within a TLS tunnel. PEAP relies on the provisioning and distribution of a digital certificate for the authentication server. With EAP-FAST, tunnel establishment is based upon strong shared-secret keys that are unique to users. These secrets are called protected access credentials (PACs) and can be created automatically or manually.  With automatic or in-band provisioning, the PAC is created and distributed to the client device in one operation. With manual or out-of-band provisioning, the PAC is created in one step and then must be distributed to the client device separately.

SCU supports PACs created automatically or manually. When you create a PAC manually, you must load it to the certs directory on the device that runs SCU. Be sure that the PAC file does not have read-only permissions set, or SCU will not be able to use the PAC.

3.4 Status Window

The Status window provides status information on the radio. A sample Status window is shown in Figure 4 below:


Figure 4: Status Window

Here is the information on the Status window:

One status item, the radio association state, is shown on both the Status window and the Main window.  A few status items are shown on the Main window and not the Status window. Those items are:

When a ping initiated on the Diags window is active, the Status window displays a ping indicator consisting of two "lights" that alternative in "flashing" green (for a successful ping) or red (for an unsuccessful ping).

3.5 Diags Window

A sample Diags, or troubleshooting, window is shown in Figure 5 below:


Figure 5: Diags Window

Here are the functions available on the Diags window:

3.6 Global Window

Global settings include radio and security settings that apply to all profiles and settings that apply to SCU itself. An administrator can define and change most global settings on the Global window in SCU. A sample Global window is shown in Figure 6 below:


Figure 6: Global Window

The following radio global settings, which apply to all configuration profiles, can be changed in SCU:

If SCU displays a value of "Custom" for a global setting, then the operating system registry has been edited to include a value that is not available for selection on the Global window. Selecting "Custom" has no real effect. If SCU displays a value other than "Custom" and you select the value of "Custom" and tap the Commit button, then SCU reverts to the value that it displayed before you selected "Custom".

The following SCU global settings, which apply to SCU itself, can be changed in SCU:

When a global setting is changed on the window and the Commit button is tapped, the change may not take effect until the device is power cycled. If you make changes without tapping Commit and attempt to move to a different SCU window, SCU will display a warning message and give you the option of saving your changes before you leave the Global window.

A few global settings can be defined or set only through a separate utility such as the Summit Manufacturing Utility, which Summit makes available only to device manufacturers and not to their customers.

Appendix: FCC Information

FCC information is provided to device manufacturers in the appendix to the user’s guide for the Summit Manufacturing Utility, which is made available only to device manufacturers.

------------------------------------------------------------------------

[1] See http://www.cisco.com/warp/public/102/wlan/leapserver.html#NetEAP for a Cisco explanation of 802.11 authentication using Open and Network-EAP.  The Summit Client Utility refers to Network-EAP as “LEAP”.

[2] See http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo1100/accsspts/i12213ja/i12213sc/s13rf.htm#wp1044425

[3] See http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo1100/accsspts/i12213ja/i12213sc/s13rf.htm#wp1037656

[4] The device manufacturer should use the Summit manufacturing utility to ensure that the “Tx Power” value reported by SCU is EIRP, or the total effective transmit power of the radio, including gains that the antenna provides and losses from the antenna cable.