Configuring Access Point Security
6-65
Default
Authentication Type
Specify a PEAP and/or TTLS Authentication Type for EAP to use
from the drop-down menu to the right of each checkbox item. PEAP
options include:
•
GTC
-
EAP Generic Token Card
(GTC) is a challenge
handshake authentication protocol using a hardware token
card to provide the response string.
•
MSCHAP-V2
-
Microsoft CHAP
(MSCHAP-V2) is an encrypted
authentication method based on Microsoft's challenge/
response authentication protocol.
TTLS options include:
•
PAP
-
Password Authentication Protocol
sends a username
and password over a network to a server that compares the
username and password to a table of authorized users. If the
username and password are matched in the table, server
access is authorized. WatchGuard products do not support
the PAP protocol because the username and password are
sent as clear text that a hacker can read.
•
MD5
- This option enables the MD5 algorithm for data
verification. MD5 takes as input a message of arbitrary
length and produces a 128- bit fingerprint. The MD5
algorithm is intended for digital signature applications, in
which a large file must be compressed in a secure manner
before being encrypted with a private (secret) key under a
public-key cryptographic system.
•
MSCHAP-V2
-
Microsoft CHAP
(MSCHAP-V2) is an encrypted
authentication method based on Microsoft's challenge/
response authentication protocol.
Server Certificate
If you have a server certificate from a CA and wish to use it on the
Radius server, select it from the drop-down menu. Only certificates
imported to the access point are available in the menu. For
information on creating a certificate, see
Creating Self Certificates
for Accessing the VPN on page 4-18
.
CA Certificate
You can also choose an imported CA Certificate to use on the
Radius server. If using a server certificate signed by a CA, import
that CA's root certificate using the CA certificates screen (for
information, see
Importing a CA Certificate on page 4-16
). After a
valid CA certificate has been imported, it is available from the CA
Certificate drop-down menu.
Summary of Contents for AP-51 Series
Page 1: ...AP 51xx Access Point Product Reference Guide ...
Page 3: ...AP 51xx Access Point Product Reference Guide 72E 124688 01 May 2009 ...
Page 4: ......
Page 16: ...AP 51xx Access Point Product Reference Guide xiv ...
Page 80: ...AP 51xx Access Point Product Reference Guide 2 32 ...
Page 96: ...AP 51xx Access Point Product Reference Guide 3 16 ...
Page 158: ...AP 51xx Access Point Product Reference Guide 4 62 ...
Page 238: ...AP 51xx Access Point Product Reference Guide 5 80 ...
Page 318: ...AP 51xx Access Point Product Reference Guide 6 80 ...
Page 636: ...AP 51xx Access Point Product Reference Guide 9 22 3 Define a mesh supported WLAN ...
Page 649: ...Configuring Mesh Networking 9 35 3 Determine the Radio MAC Address and BSSID MAC Addresses ...
Page 679: ...Adaptive AP 10 25 line con 0 line vty 0 24 end ...
Page 680: ...AP 51xx Access Point Product Reference Guide 10 26 ...
Page 692: ...AP 51xx Access Point Product Reference Guide A 12 ...
Page 716: ...AP 51xx Access Point Product Reference Guide C 4 ...
Page 722: ...AP 51xx Access Point Product Reference Guide IN 10 ...
Page 723: ......