User's Manual

A sim plifie d de scription of 802 .1x a uth e ntica tion is:
A clie n t se nds a "re que st to a cce ss" m e ssa ge to a n a cce s s point.
The a cce ss point re que s ts the ide ntity of the clie n t.
The clie nt re plies with its ide n tity pa cke t wh ich is pa sse d a long to
th e a uthe n tica tion se rve r.
The a u the ntica tion s e rve r s e nds a n "a cce pt" pa cke t to the a cce ss
point.
The a cce ss point pla ce s th e clie n t port in the a uthorize d s ta te a n d
da ta tra ffic is a llowe d to proce e d.
8 0 2 .1 x Fe a t u re s
802 .1x s u pplica nt protocol support
Support for the Extensible Au the ntica tion Protocol (EAP) - RFC
228 4
Supporte d Auth e ntica tion Me thods:
EAP TLS Au the ntica tion Protocol - RFC 2 716 a nd RFC 2 246
EAP Tunne le d TLS (TTLS)
PEAP
Supports Microsoft Windows XP a nd Windows 2000
W P A o r W P A2
Wi-Fi Prote cte d Acce ss (WPA or WPA2) is a se curity e n h a nce m e n t th a t
stron gly in cre a s e s the le ve l of da ta prote ction a nd a cce ss control to a
wire le ss ne twork. WPA e nforce s 802 .1x a uth e ntica tion a nd ke y-
e xcha nge a nd only works with dyna m ic e ncryption ke ys. To s tre ngthe n
da ta e n cryption, WPA utilize s Te m pora l Ke y In te grity Protocol (TKIP).
TKIP provide s im porta nt da ta e ncryption e n h a nce m e n ts th a t in clu de a
pe r-pa cke t ke y m ixing fu n ction , a m e s s a ge integrity che ck (MIC) ca lle d
Mich a e l a n e xte n de d initia liza tion ve ctor (IV) with se que n cing rules, a nd
a re ke yin g m e cha n is m . With these im prove m e nt e n h a nce m e n ts, TKIP
prote cts a ga in s t WEP's kn own we a kne sse s.

Summary of content (88 pages)