<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help - security issue in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/need-help-security-issue/m-p/339533#M22729</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure if I can give you an answer you would like. In general, you want to use one of the 802.1x for authentication. Then, you use WPA (TKIP) for key management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco APs support almost all 802.1x types. The real problem is that not all clients support every 802.1x types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEAP and EAP-FAST are 802.1x types from Cisco. You either have Cisco wireless adapters (i.e. 350 and CB21AG, but CB21AG does not support EAP-FAST yet),  CCXv1 complaint adapter for LEAP support, or CCXv3 complaint adapter for EAP-FAST. You also need to upgrade the ACS for LEAP or EAP-FAST support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use PEAP MS-CHAP v2, but you need to install certificates on the ACS and make the wireless clients  trust the CA issuing the certificate. On top of it, I do not think that low end wireless adapters support PEAP MS-CHAP v2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I rule out EAP-TLS because you need to install certificate on every single PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another possibility is PEAP-GTC. Only Cisco wireless adapter and CCX v2 complaint adapters support PEAP-GTC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WPA-PSK is another possibility outside 802.1x and not as secured as 802.1x. However, not all wireless adapter support it. At least Cisco 350 wireless adapter does not support it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short, you need to find out what wireless adapter you want to support. Then, pick one of the above.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Nov 2004 20:23:38 GMT</pubDate>
    <dc:creator>dixho</dc:creator>
    <dc:date>2004-11-04T20:23:38Z</dc:date>
    <item>
      <title>Need help - security issue</title>
      <link>https://community.cisco.com/t5/wireless/need-help-security-issue/m-p/339532#M22728</link>
      <description>&lt;P&gt;Hello, we have a WLAN with 25 Cisco ap's. We use only a static wep and need to strengthen our security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco 350 and 1200 ap's&lt;/P&gt;&lt;P&gt;Cisco ACS 3.0 radius server&lt;/P&gt;&lt;P&gt;A lot of different client cards, most of then running XP sp1/sp2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to configure the clients as little as possible. Does anyone have a suggestion on how we can do things to increase the security ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Johann Folkestad&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 17:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-security-issue/m-p/339532#M22728</guid>
      <dc:creator>johannf</dc:creator>
      <dc:date>2021-07-04T17:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Need help - security issue</title>
      <link>https://community.cisco.com/t5/wireless/need-help-security-issue/m-p/339533#M22729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure if I can give you an answer you would like. In general, you want to use one of the 802.1x for authentication. Then, you use WPA (TKIP) for key management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco APs support almost all 802.1x types. The real problem is that not all clients support every 802.1x types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEAP and EAP-FAST are 802.1x types from Cisco. You either have Cisco wireless adapters (i.e. 350 and CB21AG, but CB21AG does not support EAP-FAST yet),  CCXv1 complaint adapter for LEAP support, or CCXv3 complaint adapter for EAP-FAST. You also need to upgrade the ACS for LEAP or EAP-FAST support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use PEAP MS-CHAP v2, but you need to install certificates on the ACS and make the wireless clients  trust the CA issuing the certificate. On top of it, I do not think that low end wireless adapters support PEAP MS-CHAP v2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I rule out EAP-TLS because you need to install certificate on every single PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another possibility is PEAP-GTC. Only Cisco wireless adapter and CCX v2 complaint adapters support PEAP-GTC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WPA-PSK is another possibility outside 802.1x and not as secured as 802.1x. However, not all wireless adapter support it. At least Cisco 350 wireless adapter does not support it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short, you need to find out what wireless adapter you want to support. Then, pick one of the above.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Nov 2004 20:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-security-issue/m-p/339533#M22729</guid>
      <dc:creator>dixho</dc:creator>
      <dc:date>2004-11-04T20:23:38Z</dc:date>
    </item>
  </channel>
</rss>

