Ieee 802.1X Extensible Authentication Protocol Types - Nortel 2360 Configuration Manual

Wlan-security switch 2300 series
Hide thumbs Also See for 2360:
Table of Contents

Advertisement

480 Configuring AAA for network users

IEEE 802.1X Extensible Authentication Protocol types

Extensible Authentication Protocol (EAP) is a generic point-to-point protocol that supports multiple authenti-
cation mechanisms. EAP has been adopted as a standard by the Institute of Electrical and Electronic Engineers
(IEEE). IEEE 802.1X is an encapsulated form for carrying authentication messages in a standard message
exchange between a user (client) and an authenticator.
Table 1
summarizes the EAP protocols (also called types or methods) supported by WSS Software.
Table 1: EAP Authentication Protocols for local processing
EAP Type
EAP-MD5
(EAP with
Message Digest
Algorithm 5)
EAP-TLS
(EAP with
Transport Layer
Security)
PEAP-MS-
CHAP-V2
(Protected EAP
with Microsoft
Challenge
Handshake
Authentication
Protocol
version 2)
1. EAP-MD5 does not work with Microsoft wired authentication clients.
NN47250-500 (320657-F Version 02.01)
Description
Authentication
algorithm that uses a
challenge-response
mechanism to
compare hashes
Protocol that provides
mutual
authentication,
integrity-protected
encryption algorithm
negotiation, and key
exchange. EAP-TLS
provides encryption
and data integrity
checking for the
connection.
The wireless client
authenticates the
server (either the
WSS or a RADIUS
server) using TLS to
set up an encrypted
session. Mutual
authentication is
performed by
MS-CHAP-V2.
Use
Wired authentication
only 1
Wireless and wired
authentication.
All authentication is
processed on the
WSS.
Wireless and wired
authentication:
The PEAP portion is
processed on the WSS.
The MS-CHAP-V2
portion is processed on
the RADIUS server or
locally, depending on the
configuration.
Considerations
This protocol
provides no
encryption or
key
establishment.
This protocol
requires X.509
public key
certificates on
both sides of
the connection.
Requires use of
local database.
Not supported
for RADIUS.
Only the server
side of the
connection
requires a
certificate.
The client
needs only a
username and
password.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

23502361Wlan 2382

Table of Contents