![Cisco DX650 Скачать руководство пользователя страница 105](http://html.mh-extra.com/html/cisco/dx650/dx650_administration-manual_64128105.webp)
list of users. Communication between the wireless device and AP could be nonencrypted or devices can
use Wired Equivalent Privacy (WEP) keys to provide security. Devices that use WEP only attempt to
authenticate with an AP that is using WEP.
•
Shared Key Authentication: The AP sends an unencrypted challenge text string to any device that attempts
to communicate with the AP. The device that is requesting authentication uses a preconfigured WEP
key to encrypt the challenge text and sends it back to the AP. If the challenge text is encrypted correctly,
the AP allows the requesting device to authenticate. A device can authenticate only if the device WEP
key matches the WEP key on the APs.
Shared key authentication can be less secure than open authentication with WEP because someone can
monitor the challenges. An intruder can calculate the WEP key by comparing the unencrypted and
encrypted challenge text strings.
•
Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST)
Authentication: This client server security architecture encrypts EAP transactions within a Transport
Level Security (TLS) tunnel between the AP and the RADIUS server, such as the Cisco Access Control
Server (ACS).
The TLS tunnel uses Protected Access Credentials (PACs) for authentication between the client (phone)
and the RADIUS server. The server sends an Authority ID (AID) to the client (phone), which in turn
selects the appropriate PAC. The client (phone) returns a PAC-Opaque to the RADIUS server. The
server decrypts the PAC with the master key. Both endpoints now contain the PAC key and a TLS tunnel
is created. EAP-FAST supports automatic PAC provisioning, but you must enable it on the RADIUS
server.
In the Cisco ACS, by default, the PAC expires in one week. If the phone has an expired
PAC, authentication with the RADIUS server takes longer while the phone gets a new
PAC. To avoid PAC provisioning delays, set the PAC expiration period to 90 days or
longer on the ACS or RADIUS server.
Note
•
Light Extensible Authentication Protocol (LEAP): Cisco proprietary password-based mutual authentication
scheme between the client (phone) and a RADIUS server. Cisco Desktop Collaboration Experience can
use LEAP for authentication with the wireless network.
•
Auto (AKM): Selects the 802.11 Authentication mechanism automatically from the configuration
information that the AP, WPA-PSK, or WPA exhibits.
•
WPA (Wi-Fi Protected Access)
•
WPA2 (Wi-Fi Protected Access 2)
•
WPA-PSK (Wi-Fi Protected Access-Pre-Shared Key)
•
WPA2-PSK (Wi-Fi Protected Access 2-Pre-Shared Key)
•
EAP-FAST (Extensible Authentication Protocol
–
Flexible Authentication via Secure Tunneling)
•
PEAP (Protected Extensible Authentication Protocol)
EAP-FAST and PEAP are the 802.x options when choosing WPA/WPA2 through
802.1X EAP selection.
Note
Cisco Desktop Collaboration Experience DX650 Administration Guide, Release 10.1(1)
87
Security for Voice Communications in WLANs
Содержание DX650
Страница 12: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 xii Contents ...
Страница 20: ......
Страница 64: ......
Страница 116: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 98 Wireless LAN Setup ...
Страница 172: ......
Страница 182: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 164 Application Dial Rules ...
Страница 184: ......
Страница 196: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 178 Status Menu ...
Страница 212: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 194 Streaming Statistics ...
Страница 220: ......
Страница 228: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 210 User Voice Messaging System Access ...
Страница 230: ...Cisco Desktop Collaboration Experience DX650 Administration Guide Release 10 1 1 212 International Call Logging Support ...