<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is LEAP that secure?? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64284#M18540</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't figured it out yet.  I'll let you know.  But I believe it has to do with reducing the level of trust on the wireless side, and treating it as any other foreign network access point, and requiring strong user authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-brkn!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jan 2002 22:52:17 GMT</pubDate>
    <dc:creator>brok3n</dc:creator>
    <dc:date>2002-01-17T22:52:17Z</dc:date>
    <item>
      <title>Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64278#M18534</link>
      <description>&lt;P&gt;I am currently testing LEAP with an AP350 and Funk's Stealbelt RADIUS server. When I first looked at LEAP it looked like a pretty secure solution. But then I noticed that I could authenticate with LEAP when the client had no shared WEP key. I have a 128-bit key set in the AP and it is configured for both LEAP and shared key authentication, but I'm able to authenticate with just a username and password. &lt;/P&gt;&lt;P&gt;The reason this is a problem is that all a hacker would need to break into a LEAP system is a username and password. The SSID and MAC addresses would also be needed, but are extreamly easy to get. That may be sufficient for some enterprises, but my security team wouldn't allow it. I hope that I am just missing something in my configuration, but it looks as though once you have LEAP enabled, you don't need an initial shared key between the client and AP. Is this true??&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 05:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64278#M18534</guid>
      <dc:creator>daveman</dc:creator>
      <dc:date>2021-07-05T05:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64279#M18535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something you could do to enhance the security of the solution is to have the username/password go through a ACE Server (SecurID cards).  I don't know a lot about the 802.1x security, I'm evaluating it right now, but I keep in mind that a laptop could be stolen (with the 802.1x card and preshared key!).  The token based authentication considerably reduces the odds of having unauthorized accesses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2001 14:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64279#M18535</guid>
      <dc:creator>omartin</dc:creator>
      <dc:date>2001-11-23T14:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64280#M18536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tad late on the followup -- but currently using SecurID w/LEAP requires you to re-authenticate with the token each time the key changes.  Not good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-brkn!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2002 22:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64280#M18536</guid>
      <dc:creator>brok3n</dc:creator>
      <dc:date>2002-01-08T22:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64281#M18537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So what do you recommend &lt;A href="mailto:brok3n@hotmail.com"&gt;brok3n@hotmail.com&lt;/A&gt; for securing wireless network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2002 18:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64281#M18537</guid>
      <dc:creator>emil</dc:creator>
      <dc:date>2002-01-15T18:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64282#M18538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're not missing anything.  LEAP will generate a session key based on the username/password, you don't need (or want) a fixed key in the client.  You should disable the shared key authentication because that really is not secure. Someone could derive the fixed key and continue to use it until it's changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as only having a name/password pair for access, I don't understand why you perceive risk in that-- a strong password policy with minimum password length, expiration, etc. will mitigate any exposure there-- It's the best you can do short of some sort of biometric device or smartcard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2002 18:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64282#M18538</guid>
      <dc:creator>drynkowski</dc:creator>
      <dc:date>2002-01-15T18:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64283#M18539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security begins with everyone in your company. U can be broken into even if u have the most high tech gears by having your users writing down their password and stick it on their monitor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable your LEAP, Disable shared key (U dun need this on LEAP as the shared key will be distributed to the clients upon successful authentication) and educate your users on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) their choice of password for including special characters like "!@#%^&amp;amp;*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) your policy on password like ageing and minimum password length ( this can be done on the CISCO ACS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2002 01:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64283#M18539</guid>
      <dc:creator>krdl88</dc:creator>
      <dc:date>2002-01-16T01:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64284#M18540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't figured it out yet.  I'll let you know.  But I believe it has to do with reducing the level of trust on the wireless side, and treating it as any other foreign network access point, and requiring strong user authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-brkn!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2002 22:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64284#M18540</guid>
      <dc:creator>brok3n</dc:creator>
      <dc:date>2002-01-17T22:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is LEAP that secure??</title>
      <link>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64285#M18541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to force LEAP and WEP, don't allow association to mixed cells, and set the authentication to "open" instead of "shared". Also, on the WEP page set encryption to "full encryption" It's working great for me. i'm also using MAC address filtering.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2002 02:13:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/is-leap-that-secure/m-p/64285#M18541</guid>
      <dc:creator>James Strong</dc:creator>
      <dc:date>2002-01-31T02:13:12Z</dc:date>
    </item>
  </channel>
</rss>

