<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: best security method to use for authentication and encryptio in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576892#M20482</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use Microsoft CA to generate a free cert.  Then you can configure the ACS for PEAP that is compatible with XP.  Depending if your XP users support WPA2 AES or WPA TKIP, Either one will be secure, of course WPA2 would be the better choice.  I know if xp doesnt have the WPA2 option, there is a hotfix out ther for that.  You then crate a policy on the ACS to authenticate users to AD.  There is a lot of information on how to set this up int ACS or even Microsoft IAS... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/ed80211.mspx" target="_blank"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/ed80211.mspx&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Jun 2006 23:05:35 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2006-06-29T23:05:35Z</dc:date>
    <item>
      <title>best security method to use for authentication and encryption</title>
      <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576890#M20480</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have implemented a Cisco ACS, and have a Microsoft Active Directory implementation.&lt;/P&gt;&lt;P&gt;I would like to know what is the best security method to use for authentication and encryption&lt;/P&gt;&lt;P&gt;without the need to buy any Certificate or client software?&lt;/P&gt;&lt;P&gt;We would like to use the standard Microsoft Windows XP features, without installing any WLAN Clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jorge Sousa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 18:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576890#M20480</guid>
      <dc:creator>jorge.s</dc:creator>
      <dc:date>2021-07-04T18:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: best security method to use for authentication and encryptio</title>
      <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576891#M20481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;WPA-PSK is what you are looking for, but it does not use AD. For that you will probably need to use a third party client. I have yet been able to get any of my cards, including the Cisco ABG card to work using username and password against AD using the XP client, but works like a charm with the Cisco client software. I can connect quickly and easily with the XP client using WPA-PSK though. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2006 22:03:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576891#M20481</guid>
      <dc:creator>tahequivoice</dc:creator>
      <dc:date>2006-06-29T22:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: best security method to use for authentication and encryptio</title>
      <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576892#M20482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use Microsoft CA to generate a free cert.  Then you can configure the ACS for PEAP that is compatible with XP.  Depending if your XP users support WPA2 AES or WPA TKIP, Either one will be secure, of course WPA2 would be the better choice.  I know if xp doesnt have the WPA2 option, there is a hotfix out ther for that.  You then crate a policy on the ACS to authenticate users to AD.  There is a lot of information on how to set this up int ACS or even Microsoft IAS... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/ed80211.mspx" target="_blank"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/ed80211.mspx&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2006 23:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576892#M20482</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2006-06-29T23:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: best security method to use for authentication and encryptio</title>
      <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576893#M20483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isnt the WPA2 or AD authentication card dependant? Some cards dont support AES, or WPA for that matter. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2006 11:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576893#M20483</guid>
      <dc:creator>tahequivoice</dc:creator>
      <dc:date>2006-06-30T11:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: best security method to use for authentication and encryptio</title>
      <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576894#M20484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go with PEAP and WPA.  Users can authenticate against the AD adn be done with it.  As for what, the native Windows Client will do PEAP, and if you find a client that can't do WPA, upgrade the drivers.  WPA is a standard and should be there.  WPA2 on the other hand is not standard yet, but with WPA2 you get a stronger encryption, WPA you get rotating key.  I'd personally go with rotating key, any encryptio can be broken given enough time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  my 2cents&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2006 13:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576894#M20484</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2006-06-30T13:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: best security method to use for authentication and encryptio</title>
      <link>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576895#M20485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, IEEE ratified 802.11i in June 2004 and the WIFI alliance started certifying WPA2 devices in September 2004, so there is plenty of support for WPA2.  Just got back from Networkers 2006 and they were recommending WPA2 in the following order:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Platinum 	- WPA2-AES&lt;/P&gt;&lt;P&gt;Gold		- WPA-TKIP&lt;/P&gt;&lt;P&gt;Lead		- WEP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The big player's (Cisco, Intel, Broadcom) AG cards will do WPA2-AES and CCX3 or better just fine with the latest drivers.  Don't forget the MS WPA2 patch KB893357 if you are going to use the MS PEAP client.  IAS or ACS will work equally well, just don't forget the MS fast reconnect patch when used with ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WPA2 provides better encryption and PMK caching, which is a standards based fast roaming similar to Cisco CCKM.  The only drawback that I know is WPA2 XP client configuration is not yet available to be pushed out via AD group policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Jul 2006 02:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/best-security-method-to-use-for-authentication-and-encryption/m-p/576895#M20485</guid>
      <dc:creator>Darren Ramsey</dc:creator>
      <dc:date>2006-07-01T02:49:07Z</dc:date>
    </item>
  </channel>
</rss>

