Security
myUTN User Manual Windows
106
7. Click
Save & Restart
to confirm.
The settings are saved.
Configuring EAP-FAST
Benefits and
Purpose
EAP-FAST (Flexible Authentication via Secure Tunneling) validates
the identity of devices or users before they gain access to network
resources. You can configure the UTN server for the EAP-FAST net-
work authentication. This ensures that the UTN server gets access to
protected networks.
Mode of Operation
EAP-FAST uses (as in the case of EAP-TTLS, see
order to protect the data transfer. The main difference is that
EAP-FAST does not require certificates for authentication purposes.
(The use of certificates is optional).
PACs (Protected Access Credentials) are used to build the channel.
PACs are credentials that comprise up to three components.
• A shared secret key that contains the preshared key between the
UTN server and the RADIUS server.
• An opaque part that is provided to the UTN server and presented
to the RADIUS server when the UTN server wishes to obtain
access to network resources.
• Other information that may be useful to the client. (Optional)
EAP-FAST uses two methods to generate PACs:
• The manual delivery mechanism can be every mechanism that
the administrator configures and considers to be safe for the
network.
• In the case of the automatic delivery, an encrypted channel is
established in order to protect the UTN server authentication as
well as the delivery of the PACs.