
45
V 2.2 Copyright SystemExperts 2001,2002,2003
89
ESN: The Wireless Security Future?
n Defined in the 802.11 Security Baseline
n Depends on 802.1X
n Protocol definitions between client and bridge and bridge and
authentication server
n Provides
n Enhanced authentication
n Key management algorithms
n Dynamic, association-specific WEP keys
n Open authentication method
n Looks like many vendors are using RADIUS
n Uses EAP encapsulated in 802.11b Frames
n EAP is defined in RFC 2284
V 2.2 Copyright SystemExperts 2001,2002,2003
90
Wireless EAP: Cisco’s Version
n Lightweight EAP (LEAP)
n EAP Type 17: EAP-Cisco Wireless
n Based on EAP and IEEE 802.1X
n Provides authentication service for clients
whose host OSs do not support EAP
n LEAP distinguishes between authentication
provided by the client firmware from that provided
by the host OS
n Backend RADIUS server
(Access Control Server 2000 V2.6)
n Uses MS-CHAP as Authentication Protocol
Commentaires sur ces manuels