cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
775
Views
3
Helpful
4
Replies

Wireless Security?

jorge.s
Level 4
Level 4

Hi,

we have an implementation of Wlan distributed throughout several plant's, where there security implemented is:

1. SSID Hidden

2. 128 Fixed WEP Key

3. Cisco ACS with registration of MacAddress's

And we are then doing authentication based on Mac-Address.

We know that this is really a not safe solution, but what you would recommend, considering that we are Running Microsoft Active Directory, but avoiding the use of Certificates.

Thanks for any recomendation,

Best Regards,

Jorge Sousa

4 Replies 4

Stephen Rodriguez
Cisco Employee
Cisco Employee

well you could do LEAP. You get AD authentication, can do WPA instead of WEP, and there is no need for a certificate.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

This will have to be driven by your clients and what they support. I have been focusing on WPA2/PEAP lately, for broad client support. PEAP uses a certificate, but only for the ACS server. If your clients support it you could do EAP-FAST, but some clients do not support it.

If you post more info about your client base (OS and hardware) we could probably give more specific reponses.

-Eric

Please remember to rate all helpful posts.

My clients are basically Windows XP (sp1 and sp2), still some Windows 95, and some Intermec Scanners.

m.sir
Level 11
Level 11

If you dont want use certificates EAP-FAST is best , fast and secure solution - its 802.1X EAP type authentication without using CA

check following Q&A

http://www.cisco.com/en/US/products/hw/wireless/ps430/products_qanda_item09186a00802030dc.shtml

ACS setting for EAP-FAST

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00804b9d57.shtml

EAP-FAST Deployment Guide (PDF)

http://www.cisco.com/application/pdf/en/us/guest/products/ps4076/c1067/ccmigration_09186a00802623a2.pdf

M.

Hope that helps rate if it does

Review Cisco Networking for a $25 gift card