3.4 Wireless Authentication Protocols Flashcards

1
Q

What is the framework that many wireless networks built upon?

A

EAP in conjunction with 802.1x

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is 802.1x

A

Port-based network access control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is NAC?

A

Network access control. You don’t get to connect to the network until you authenticate yourself.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What type of central database is NAC used with?

A

RADIUS, LDAP, TACACS+

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 systems that make up 802.1x and EAP?

A

The client - known as supplicant
Authenticator - The device that provides access
Authentication Server - Validation of client credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is EAP-FAST?

A

EAP Flexible Authentication via Secure Tunneling

Authentication server and supplicant have a Protected Access Credential (PAC) (its just a shared secret)

Supplicant receives the PAC and establishes a TLS tunnel and then authentication occurs. Requires a RADIUS server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is PEAP?

A

Created by Cisco, MS, RSA

Also uses TLS. Uses digital certificate instead of PAC. Client does not use certificate.

User authenticates with MSCHAPv2. Alternatively user can authenticate with GTC or Hardware token generator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is EAP-TLS?

A

This one requires digital certificate from Authentication Server and Supplicant. Once both parties exchange certificates, TLS tunnel is created.

Requires PKI because of certificates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is EAP-TTLS?

A

Supports other authentication protocols in TLS tunnel. Only the AS requires a digital certificate. The TLS tunnel is created via the AS certificate.

Authentication can be done via any other method such as MSCHAPv2, other EAP, or Federations like RADIUS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does RADIUS federation commonly use as their authentication method?

A

802.1x and EAP for authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly