Sunday 13 April 2008

802.1x, Encryption and Authentication - Cisco LEAP

Lightweight Extensible Authentication Protocol (LEAP), is an 802.1x authentication type.

+ supported by WiFi WPA/WPA2.
+ Strong mutual authentication between client and RADIUS server
+ Supported on all Cisco products
+ Fast secure roaming between Cisco or Cisco compatible clients at layer 2 and 3
+ Single login with existing userid/password from Microsoft AD
+ Supported on range of OS

Client OS include: MS 98/XP/CE, OS X 9.x/10.x, Linux, DOS
RADIUS servers include: Cisco ACS, Meetinghouse Aegis, Interlink Merit, Funk Odyssey server
Wireless devices include: Cisco WAP/LWAP, WLAN controllers, Cisco unified wireless phone 7920, wireless bridges/repeaters, many Cisco and Cisco compatible WLAN clients

Cisco LEAP process:
1. No traffic permitted except EAP until authenticated
2. AP request/identify message, or start message from client
3. Client responds with userid, which is sent by AP to RADIUS server
4. Radius server authenticates the client via AP
5. Client authenticates the RADIUS server via AP
6. Authentication uses challenge/response, response uses MD5, when authenticated a RADIUS success message is sent to each party.
7. The radius server sends a Pair-wise Master Key (PMK) to the AP, a four-way handshake takes place, then the client can transmit and receive data through a protected session.

No comments: