Cisco AIR-CB21AG-W-K9 Configuration Guide - Page 55

Configuring EAP Types, Overview of EAP-FAST

Page 55 highlights

3 C H A P T E R Configuring EAP Types This chapter explains the EAP types that are used for authenication to wireless networks. The following topics are covered: • Overview of EAP-FAST, page 3-1 • How EAP-FAST Works, page 3-2 • Configuring EAP-FAST, page 3-4 • Overview of LEAP, page 3-17 • How LEAP Works, page 3-17 • Configuring LEAP, page 3-18 • Overview of PEAP-GTC, page 3-21 • How PEAP-GTC Works, page 3-22 • Configuring PEAP-GTC, page 3-23 Overview of EAP-FAST Note For additional information about EAP-FAST, see RFC4851. EAP-FAST is an EAP method that enables secure communication between a client and an authentication server by using Transport Layer Security (TLS) to establish a mutually authenticated tunnel. Within the tunnel, data in the form of type, length, and value (TLV) objects are used to send further authentication-related data between the client and the authentication server. EAP-FAST supports the TLS extension as defined in RFC 4507 to support the fast re-establishment of the secure tunnel without having to maintain per-session state on the server. EAP-FAST-based mechanisms are defined to provision the credentials for the TLS extension. These credentials are called Protected Access Credentials (PACs). EAP-FAST provides the following: • Mutual authentication An EAP server must be able to verify the identity and authenticity of the client, and the client must be able to verify the authenticity of the EAP server. • Immunity to passive dictionary attacks Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista OL-16534-01 3-1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

CHAPTER
3-1
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista
OL-16534-01
3
Configuring EAP Types
This chapter explains the EAP types that are used for authenication to wireless networks.
The following topics are covered:
Overview of EAP-FAST, page 3-1
How EAP-FAST Works, page 3-2
Configuring EAP-FAST, page 3-4
Overview of LEAP, page 3-17
How LEAP Works, page 3-17
Configuring LEAP, page 3-18
Overview of PEAP-GTC, page 3-21
How PEAP-GTC Works, page 3-22
Configuring PEAP-GTC, page 3-23
Overview of EAP-FAST
Note
For additional information about EAP-FAST, see RFC4851.
EAP-FAST is an EAP method that enables secure communication between a client and an authentication
server by using Transport Layer Security (TLS) to establish a mutually authenticated tunnel. Within the
tunnel, data in the form of type, length, and value (TLV) objects are used to send further
authentication-related data between the client and the authentication server.
EAP-FAST supports the TLS extension as defined in RFC 4507 to support the fast re-establishment of
the secure tunnel without having to maintain per-session state on the server. EAP-FAST-based
mechanisms are defined to provision the credentials for the TLS extension. These credentials are called
Protected Access Credentials (PACs).
EAP-FAST provides the following:
Mutual authentication
An EAP server must be able to verify the identity and authenticity of the client, and the client must
be able to verify the authenticity of the EAP server.
Immunity to passive dictionary attacks