Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Please tell me the Answer

This thread has been viewed 0 times
  • 1.  Please tell me the Answer

    Posted Oct 15, 2019 06:39 AM

    A network administrator wants to use unique digital certificates installed on user devices to authenticate wireless users. Which EAP method should the RADIUS server and clients support?

     

    1. PEAP and MS-CHAPv2

     

    1. EAP-TLS

     

    1. EAP-TTLS and MS-CHAPv2

     

    1. LEAP


  • 2.  RE: Please tell me the Answer
    Best Answer

    Posted Oct 15, 2019 06:58 AM

    Info regarding EAP  , read more info here:

     

    https://community.arubanetworks.com/t5/Community-Tribal-Knowledge-Base/EAP-The-Basics/ta-p/25380

     

    EAP Summary

     Based on this table, we can draw some reasonably clear conclusions:

    • TLS, while very secure, requires client certificates to be installed on each wireless workstation. Installing and maintaining a PKI infrastructure must be part of any TLS installation and does create more administrative overhead. If a working PKI already exists, TLS is a very good option
    • TTLS addresses the certificate issue by tunneling TLS, and thus eliminating the need for a certificate on the client side. If a working PKI structure does not exist, this is an option worth considering
    • LEAP is one of the earliest EAP implementations; however inherent security flaws have now made it less popular and it is not recommended
    • EAP-FAST promises to be as easy as LEAP but as secure as PEAP, however it has different implementation and operational modes that, ultimately, offer a compromise. The highest security, ultimately, ends up looking very similar to PEAP – without the widespread client support that PEAP enjoys
    • PEAP works similarly to EAP-TTLS in that it does not require a certificate on the client side and is natively supported by many client operating systems. PEAP is the protocol of choice when client-side certificates are not required. When deploying PEAP, EAP-MSChapv2 is likewise the protocol of choice as compared to EAP-GTC. This is primarily due to the fact that EAP-GTC it is not supported by Microsoft’s IAS RADIUS server or the native Windows supplicant


  • 3.  RE: Please tell me the Answer

    Posted Oct 15, 2019 07:12 AM

    So EAP-TLS is answer