Securing Your Network Flashcards
EAP
Extensible Authentication Protocol. Provides a method for two systems to create a secure encryption key, also known as a Pairwise Master Key (PMK).
EAP-FAST
EAP-Flexible Authentication vis Secure Tunneling. Cisco designed EAP-FAST as a replacement for Lightweight EAP (LEAP). Supports certificates, but they are optional.
PEAP
Protected EAP. Provides extra layer of protection for EAP. PEAP encapsulates and encrypts the EAP conversation in a Transport Layer Security (TLS) tunnel. Requires a certificate on the server, but not on the clients. Commonly implemented through MS-CHAPv2
EAP-TTLS
EAP-Tunneled TLS. Extension of PEAP. Allows systems to use. some older authentication protocols such as PAP. Requires a certificate on the 802.1x server, but not on the clients.
RADIUS Federation
Possible to create a federation using 802.1x and RADIUS servers.
IPSec Tunneling Protocol
Provides security through Authentication and Encryption.
TLS Tunneling Protocol
Use TLS to secure the VPN channel. Good option when IPSec is not feasible.
Split Tunnel VPN
Administrator determines what traffic should use the encrypted tunnel.
Full Tunnel VPN
All traffic goes through the encrypted tunnel.