Security - Avaya Communication Server 1000 Installation And Commissioning Manual

Wlan ip telephony
Hide thumbs Also See for Communication Server 1000:
Table of Contents

Advertisement

Security

The following security methods are supported by the handset.
WPA2 Enterprise
The handset supports WPA2 Enterprise, as defined by the WiFi Alliance. WiFi Protected
Access2, which is based on the 802.11i standard, provides government-grade security by
implementing the Advanced Encryption Standard (AES) encryption algorithm. The Enterprise
version of WPA2 uses 802.1X authentication, which is a port-based network access control
mechanism using dynamic encryption keys to protect data privacy. Two 802.1X authentication
methods are supported on the Wireless Telephone, EAP-FAST and PEAPv0/MSCHAPv2.
Both of these methods require a RADIUS authentication server to be available on the network
and accessible to the phone. For more information, see
Handset specifications
Normal 802.1X authentication requires the client to renegotiate its key with the authentication
server on every AP handoff, which is a time-consuming process that negatively affects time-
sensitive applications such as voice mail. Fast AP-handoff methods allow for the part of the
key derived from the server to be cached in the wireless network, thereby shortening the time to
renegotiate a secure handoff. The Wireless Telephone supports two fast AP handoff
techniques, Cisco Client Key Management (CCKM) (only available on Cisco APs) or
Opportunistic Key Caching (OKC). You must configure these methods for support on the WLAN
to ensure proper performance of the handset.
WPA and WPA2 Personal
The handset supports WPA and WPA2 Personal, as defined by the WiFi Alliance. WiFi
Protected Access2, which is based on the 802.11i standard, provides government-grade
security by implementing the Advanced Encryption Standard (AES) encryption algorithm. WiFi
Protected Access, which is based on a draft version of the 802.11i standard before it was
ratified, uses Temporal Key Integrity Protocol (TKIP) encryption. The Personal version uses
an authentication technique called preshared key (PSK) that allows the use of manually
entered keys to initiate security.
Cisco Fast Secure Roaming
Cisco Fast Secure Roaming (FSR) mechanism uses a combination of standards-based and
proprietary security components including Cisco Client Key Management (CCKM), LEAP
authentication, Michael message integrity check (MIC), and Temporal Key Integrity Protocol
(TKIP). Fast Secure Roaming provides strong security measures for authentication, privacy,
and data integrity on Cisco APs.
Avaya WLAN IP Telephony Installation and Commissioning
WLAN Handset 2210/2211/2212 and Avaya 6120/6140 WLAN Handset
on page 25.
Table 1: Avaya 6120/6140 WLAN
November 2010
37

Advertisement

Table of Contents
loading

Table of Contents