Dolphin 9950 Guía de usuario Pagina 163

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 314
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 162
Dolphin® 9500 Series Mobile Computer User’s Guide 7 - 47
Cisco LEAP
The message exchange used by Cisco LEAP is proprietary. This protocol is not a standard EAP type, but is supported by the
Client through a licensing arrangement with Cisco.
Relative Merits of Authentication Protocols
MD5 is the least secure of the EAP protocols as it only does a one-way authentication, and does not support automatic
distribution and rotation of WEP keys, increasing the administrative burden of manual WEP key maintenance.
TLS, while the most secure EAP protocol, requires client certificates to be installed on each wireless client. Establishing and
maintaining this PKI infrastructure is normally a burden most administrators do not feel is worth the extra level of security gained.
TTLS and PEAP bypassed the certificate issue by tunneling TLS, and thus eliminating the need for a certificate on the client side.
PEAP supports only EAP-compliant authentication protocols within the tunnel structure, and is rapidly becoming the most widely
supported of the EAP methods. TTLS supports pre-EAP authentication protocols within the tunnel structure, and should be used
in those circumstances when pre-EAP interior protocols are desirable.
LEAP is a pre-EAP, Cisco-proprietary protocol, with many of the features of EAP protocols. Cisco controls the ability of other
vendors to implement this protocol, so it should be selected for use only when limited vendor choice for client, access-point, and
server products is not a concern.
Differences Between Protocols
Security Feature MD5
Challenge
TLS TTLS PEAP LEAP
Client -side certificate required? No Yes No No No
Server-side certificate required? No Yes No Yes No
Dynamic WEP Re-keying No Yes Yes Yes Yes
Mutual or One-way Authentication? One-way Mutual Mutual Mutual Mutual
Support of non-EAP protocols within
a secure tunnel?
N/A N/A Yes No N/A
Relative Deployment Complexity Simple Difficult Moderate Moderate Moderate
Relative Security Poorest Highest High High High
Vista de pagina 162
1 2 ... 158 159 160 161 162 163 164 165 166 167 168 ... 313 314

Comentarios a estos manuales

Sin comentarios