Wireless Access Flashcards
Open authentication
Requires MAC address
Shared Key
Who needs the key
What type of network
Is it secure
All clients and devises have the same key
Small/private network
Relatively insecure
802.1x
What type of authentication
Uses usernames/passwords, certificates or devices to authenticate
NAC (Network Access Control)
Uses RADIUS server
LDAP
TACACS+
WPA
(Wi-Fi Protected Access)
Encryption
Supports
Uses TKIP for encryption (Temporal Key Integrity Protocal)
Supports WPA-PSK (Pre-Shared Key) and 802.1x (WPK enterprise)
Can use dynamic or pre-shared keys
WPA 2 or 80211i
Wi-Fi Protected Access 2
Uses AES (Advanced Encryption Standards). And upgrade to TKIP.
Uses CCMP (Counter Mode with CBC-MAC Protocol) aka AES-CCMP.
Supports pre-shared key (WPA2-PSK or WPA2 Personal) and 802.1x (WPA2 Enterprise) authentication
Can use dynamic or pre-shared keys
Captive Portal
Used to authenticate to network
Username/password pop up
EAP
Extensible Authentication Protocol
Authentication framework
EAP-FAST
EAP Flexible Authentication via Secure Tunneling
CISCO
Replaces LEAP
EAP-TLS
EAP Transport Layer Security
Strong Security
Wide adoption
Provides encryption to authentication
EAP-TTLS
EAP Tunneled Transport Layer Security
Supports other authentication types by making a secure tunnel
PEAP
Protected Extensible Authentication Protocol
Protected EAP
Creates secure tunnel to send EAP across
PEAP v2
EAP-MSCHAPv2