The most important in WLAN security is the process
of authentication. There are several techniques in
authentication process such as Internet Authentication
intention that Wireless Client can be known by the NPS
Server. To be more understood about the process of
authentication, a flowchart of authentication process
based on PEAP MSCHAP is shown in Fig. 2. PEAP
MSCHAP V2 authentication process occurs in two
phases. The first phase uses the protocol EAP to open
channel TLS. The second phase uses the protocol EAP to
do authentication mechanism of username and password
who want to connect to the Wireless LAN through SSID
Internal.
The steps of authentication between Wireless Client
and Wireless access point that utilize NPS Server to
perform processing packages are as follows:
1. Request Identity. The Wireless Client will request to
connect to the wireless access point. Wireless Client
sends EAP-start packet. Wireless access point then sends
the request for the identity used packet EAPResponse/
Identity
2. Authentication using a username and password. At this
stage the Wireless access point will send the message
Response / Identity to NPS server which is RADIUS
Access Request form.
3. EAP-Request NPS Server. At this stage the NPS server
will sends a RADIUS Access-Challenge message
containing an EAP-Request message with the EAP type
used in the TLS process. The request indicates that the
TLS authentication process begins.
4. EAP-Response Wireless Client. Wireless Client will
send an EAP Response. This is known as the hello packet
delivery. Wireless access point will then forward the EAP
wireless access point, or when opening a website in the
browser, visitor notification will appear to type in the
username and password for authentication. It will be
redirected to the Captive Portal login page. Users simply
enter the username and password to gain access to the
Internet network. Username is prepared is a guest. Once,
the username and password recognized by the server,
then the web page will be redirected back to the page that
will be addressed in advance.