Appendix D Wireless LANs
VMG1312-B10A User’s Guide
346
EAP-TTLS (Tunneled Transport Layer Service)
EAP-TTLS is an extension of the EAP-TLS authentication that uses certificates for only the server-
side authentications to establish a secure connection. Client authentication is then done by sending
username and password through the secure connection, thus client identity is protected. For client
authentication, EAP-TTLS supports EAP methods and legacy authentication methods such as PAP,
CHAP, MS-CHAP and MS-CHAP v2.
PEAP (Protected EAP)
Like EAP-TTLS, server-side certificate authentication is used to establish a secure connection, then
use simple username and password methods through the secured connection to authenticate the
clients, thus hiding client identity. However, PEAP only supports EAP methods, such as EAP-MD5,
EAP-MSCHAPv2 and EAP-GTC (EAP-Generic Token Card), for client authentication. EAP-GTC is
implemented only by Cisco.
LEAP
LEAP (Lightweight Extensible Authentication Protocol) is a Cisco implementation of IEEE 802.1x.
Dynamic WEP Key Exchange
The AP maps a unique key that is generated with the RADIUS server. This key expires when the
wireless connection times out, disconnects or reauthentication times out. A new WEP key is
generated each time reauthentication is performed.
If this feature is enabled, it is not necessary to configure a default encryption key in the wireless
security configuration screen. You may still configure and store keys, but they will not be used while
dynamic WEP is enabled.
Note: EAP-MD5 cannot be used with Dynamic WEP Key Exchange
For added security, certificate-based authentications (EAP-TLS, EAP-TTLS and PEAP) use dynamic
keys for data encryption. They are often deployed in corporate environments, but for public
deployment, a simple user name and password pair is more practical. The following table is a
comparison of the features of authentication types.
Table 124
Comparison of EAP Authentication Types
EAP-MD5
EAP-TLS
EAP-TTLS
PEAP
LEAP
Mutual Authentication
No
Yes
Yes
Yes
Yes
Certificate – Client
No
Yes
Optional
Optional
No
Certificate – Server
No
Yes
Yes
Yes
No
Dynamic Key Exchange
No
Yes
Yes
Yes
Yes
Credential Integrity
None
Strong
Strong
Strong
Moderate
Deployment Difficulty
Easy
Hard
Moderate
Moderate
Moderate
Client Identity Protection
No
No
Yes
Yes
No
Summary of Contents for VWG1312-B10A
Page 2: ......
Page 8: ...Contents Overview VMG1312 B10A User s Guide 8 Troubleshooting 291 ...
Page 18: ...Table of Contents VMG1312 B10A User s Guide 18 ...
Page 19: ...19 PART I User s Guide ...
Page 20: ...20 ...
Page 34: ...Chapter 2 The Web Configurator VMG1312 B10A User s Guide 34 ...
Page 39: ...Chapter 4 Tutorials VMG1312 B10A User s Guide 39 7 Click Apply to save your settings ...
Page 79: ...79 PART II Technical Reference ...
Page 80: ...80 ...
Page 168: ...Chapter 9 Routing VMG1312 B10A User s Guide 168 ...
Page 186: ...Chapter 10 Quality of Service QoS VMG1312 B10A User s Guide 186 ...
Page 212: ...Chapter 13 Interface Group VMG1312 B10A User s Guide 212 ...
Page 228: ...Chapter 15 Firewall VMG1312 B10A User s Guide 228 ...
Page 234: ...Chapter 17 Parental Control VMG1312 B10A User s Guide 234 ...
Page 244: ...Chapter 19 Certificates VMG1312 B10A User s Guide 244 ...
Page 248: ...Chapter 20 Log VMG1312 B10A User s Guide 248 ...
Page 252: ...Chapter 21 Traffic Status VMG1312 B10A User s Guide 252 ...
Page 258: ...Chapter 24 IGMP Status VMG1312 B10A User s Guide 258 ...
Page 262: ...Chapter 25 xDSL Statistics VMG1312 B10A User s Guide 262 ...
Page 264: ...Chapter 26 User Account VMG1312 B10A User s Guide 264 ...
Page 270: ...Chapter 29 TR 064 VMG1312 B10A User s Guide 270 ...
Page 274: ...Chapter 30 Time Settings VMG1312 B10A User s Guide 274 ...
Page 280: ...Chapter 32 Logs Setting VMG1312 B10A User s Guide 280 ...
Page 298: ...Chapter 36 Troubleshooting VMG1312 B10A User s Guide 298 ...
Page 338: ...Appendix C Pop up Windows JavaScripts and Java Permissions VMG1312 B10A User s Guide 338 ...
Page 352: ...Appendix D Wireless LANs VMG1312 B10A User s Guide 352 ...
Page 368: ...Appendix G Legal Information VMG1312 B10A User s Guide 368 ...
Page 376: ...VMG1312 B10A User s Guide 376 Index ...