Appendix D Wireless LANs
VMG1312-B10A User’s Guide
346
EAP-TTLS (Tunneled Transport Layer Service)
EAP-TTLS is an extension of the EAP-TLS authentication that uses certificates for only the server-
side authentications to establish a secure connection. Client authentication is then done by sending
username and password through the secure connection, thus client identity is protected. For client
authentication, EAP-TTLS supports EAP methods and legacy authentication methods such as PAP,
CHAP, MS-CHAP and MS-CHAP v2.
PEAP (Protected EAP)
Like EAP-TTLS, server-side certificate authentication is used to establish a secure connection, then
use simple username and password methods through the secured connection to authenticate the
clients, thus hiding client identity. However, PEAP only supports EAP methods, such as EAP-MD5,
EAP-MSCHAPv2 and EAP-GTC (EAP-Generic Token Card), for client authentication. EAP-GTC is
implemented only by Cisco.
LEAP
LEAP (Lightweight Extensible Authentication Protocol) is a Cisco implementation of IEEE 802.1x.
Dynamic WEP Key Exchange
The AP maps a unique key that is generated with the RADIUS server. This key expires when the
wireless connection times out, disconnects or reauthentication times out. A new WEP key is
generated each time reauthentication is performed.
If this feature is enabled, it is not necessary to configure a default encryption key in the wireless
security configuration screen. You may still configure and store keys, but they will not be used while
dynamic WEP is enabled.
Note: EAP-MD5 cannot be used with Dynamic WEP Key Exchange
For added security, certificate-based authentications (EAP-TLS, EAP-TTLS and PEAP) use dynamic
keys for data encryption. They are often deployed in corporate environments, but for public
deployment, a simple user name and password pair is more practical. The following table is a
comparison of the features of authentication types.
Table 124
Comparison of EAP Authentication Types
EAP-MD5
EAP-TLS
EAP-TTLS
PEAP
LEAP
Mutual Authentication
No
Yes
Yes
Yes
Yes
Certificate – Client
No
Yes
Optional
Optional
No
Certificate – Server
No
Yes
Yes
Yes
No
Dynamic Key Exchange
No
Yes
Yes
Yes
Yes
Credential Integrity
None
Strong
Strong
Strong
Moderate
Deployment Difficulty
Easy
Hard
Moderate
Moderate
Moderate
Client Identity Protection
No
No
Yes
Yes
No
Содержание VWG1312-B10A
Страница 2: ......
Страница 8: ...Contents Overview VMG1312 B10A User s Guide 8 Troubleshooting 291 ...
Страница 18: ...Table of Contents VMG1312 B10A User s Guide 18 ...
Страница 19: ...19 PART I User s Guide ...
Страница 20: ...20 ...
Страница 34: ...Chapter 2 The Web Configurator VMG1312 B10A User s Guide 34 ...
Страница 39: ...Chapter 4 Tutorials VMG1312 B10A User s Guide 39 7 Click Apply to save your settings ...
Страница 79: ...79 PART II Technical Reference ...
Страница 80: ...80 ...
Страница 168: ...Chapter 9 Routing VMG1312 B10A User s Guide 168 ...
Страница 186: ...Chapter 10 Quality of Service QoS VMG1312 B10A User s Guide 186 ...
Страница 212: ...Chapter 13 Interface Group VMG1312 B10A User s Guide 212 ...
Страница 228: ...Chapter 15 Firewall VMG1312 B10A User s Guide 228 ...
Страница 234: ...Chapter 17 Parental Control VMG1312 B10A User s Guide 234 ...
Страница 244: ...Chapter 19 Certificates VMG1312 B10A User s Guide 244 ...
Страница 248: ...Chapter 20 Log VMG1312 B10A User s Guide 248 ...
Страница 252: ...Chapter 21 Traffic Status VMG1312 B10A User s Guide 252 ...
Страница 258: ...Chapter 24 IGMP Status VMG1312 B10A User s Guide 258 ...
Страница 262: ...Chapter 25 xDSL Statistics VMG1312 B10A User s Guide 262 ...
Страница 264: ...Chapter 26 User Account VMG1312 B10A User s Guide 264 ...
Страница 270: ...Chapter 29 TR 064 VMG1312 B10A User s Guide 270 ...
Страница 274: ...Chapter 30 Time Settings VMG1312 B10A User s Guide 274 ...
Страница 280: ...Chapter 32 Logs Setting VMG1312 B10A User s Guide 280 ...
Страница 298: ...Chapter 36 Troubleshooting VMG1312 B10A User s Guide 298 ...
Страница 338: ...Appendix C Pop up Windows JavaScripts and Java Permissions VMG1312 B10A User s Guide 338 ...
Страница 352: ...Appendix D Wireless LANs VMG1312 B10A User s Guide 352 ...
Страница 368: ...Appendix G Legal Information VMG1312 B10A User s Guide 368 ...
Страница 376: ...VMG1312 B10A User s Guide 376 Index ...
Страница 377: ...Index VMG1312 B10A User s Guide 377 ...
Страница 378: ...VMG1312 B10A User s Guide 378 Index ...