NPort W2150A-W4/W2250A-W4 Series User Manual
59
There are two parts to WPA and WPA2 security, authentication, and data encryption.
•
Authentication occurs before access is granted to a WLAN. Wireless clients such as the NPort W2150A-
W4/W2250A-W4 Series are first authenticated by the AP according to the authentication protocol used
by the RADIUS server. Depending on the WLAN security settings, an EAP tunnel can scramble the
username and password that is submitted for authentication purposes.
•
Encryption occurs after WLAN access has been granted. For all wireless devices, data is first encrypted
before wireless transmission, using mutually agreed-upon encryption protocol.
EAP Method
Default
PEAP
Options
TLS, PEAP, TTLS, LEAP
Description
This field specifies the EAP method to use for authentication. Four methods are supported.
TLS: Transport Layer Security (TLS) was created by Microsoft and accepted by the IETF as
RFC 2716: PPP EAP TLS Authentication Protocol. Passwords and tunneled authentication
are not used. A user certificate and user private key are used to identify the NPort. The
NPort’s user certificate and user private key must already be installed on the RADIUS
server.
PEAP: Protected Extensible Authentication Protocol (PEAP) is a proprietary protocol which
was developed by Microsoft, Cisco, and RSA Security.
TTLS: Tunneled Transport Layer Security (TTLS) is a proprietary protocol which was
developed by Funk Software and Certicom, and is supported by Agere Systems, Proxim,
and Avaya. TTLS is being considered by the IETF as a new standard. For more information
on TTLS, read the draft RFC EAP Tunneled TLS Authentication Protocol.
LEAP: Lightweight Extensible Authentication Protocol (LEAP) is a proprietary protocol which
was developed by Cisco. LEAP doesn’t check certificate during the authentication process.
Tunneled Authentication
Default
PAP (when using TTLS)
GTC (when using PEAP)
Options
GTC, MD5, MSCHAP V2 (when using PEAP)
PAP, CHAP, MSCHAP, MSCHAP V2, EAP-MSCHAP V2, EAP-GTC,
EAP-MD5 (when using TTLS)
Description
This field specifies the encryption method to use during the authentication process.
Different methods are available, depending on the EAP Method setting.
Username
Default
Options
free text (e.g., “Smith_John”)
Description
This field specifies the username that will gain access to the WLAN. The correct username
and password must be provided for access to be granted.