3.5.2.3. IEEE 802.1x
IEEE 802.1x
Port-Based Network Access Control
is a new standard for solving some security issues
associated with IEEE 802.11, such as lack of user-based authentication and dynamic encryption key
distribution. With IEEE 802.1x and the help of a RADIUS (Remote Authentication Dial-In User Ser-
vice) server and a user account database, an enterprise or ISP (Internet Service Provider) can manage
its mobile users’ access to its wireless LANs. Before granted access to a wireless LAN supporting
IEEE 802.1x, a user has to issue his or her
user name
and
password
or
digital
certificate
to the
backend RADIUS server by EAPOL (Extensible Authentication Protocol Over LAN). The RADIUS
server can record accounting information such as when a user logs on to the wireless LAN and logs
off from the wireless LAN for monitoring or billing purposes.
The IEEE 802.1x functionality of the wireless access gateway is controlled by the
security mode
(see
Section 3.5.2.1). So far, the wireless access gateway supports two authentication mecha-
nisms—EAP-MD5 (Message Digest version 5) and EAP-TLS (Transport Layer Security) for IEEE
802.1x. If EAP-MD5 is used, the user has to give his or her
user name
and
password
for authentica-
tion. If EAP-TLS is used, the wireless client computer automatically gives the user’s
digital certifi-
cate
that is stored in the computer hard disk or a smart card for authentication. And after a successful
EAP-TLS authentication, a session key is automatically generated for wireless packets encryption
between the wireless client computer and its associated wireless access gateway. To sum up,
EAP-MD5 supports only user authentication, while EAP-TLS supports user authentication as well as
dynamic encryption key distribution.
Fig. 77. IEEE 802.1x and RADIUS.
TIP:
Go to the
Authentication, RADIUS
section of the Web management UI to configure RADIUS
settings (see Section 3.6.2).
TIP:
Refer to the IEEE 802.1x-related white papers on the accompanying CD-ROM for more infor-
mation about deploying secure WLANs with IEEE 802.1x support.
55
Содержание IWE1200A-G
Страница 1: ...USER S MANUAL...
Страница 14: ...7...
Страница 72: ...Fig 95 Advertisement links settings Fig 96 Advertisement links in action 65...