Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-31
Introduction
ProCurve Wireless Edge Services xl Module
Table 1-1 compares EAP methods and the support that the Wireless Edge
Services xl Module provides for them.
Table 1-1. EAP Methods and the Wireless Edge Services xl Module
EAP authentication also requires that the RADIUS server authenticate itself
to wireless stations with a server certificate. For more information about how
the Wireless Edge Services xl Module uses and acquires certificates, see “PKI
and Digital Certificates” on page 1-43.
Encryption Options for WLANs
A wireless network is an open medium. Anyone with a wireless network
interface card (NIC) can intercept traffic and attempt to read it. Encryption,
therefore, is required for any degree of security.
The Wireless Edge Services xl Module can enforce one of the following
encryption standards on a WLAN:
Wired Equivalent Privacy (WEP) with 64-bit or 128-bit keys
Wi-Fi Protected Access (WPA)/WPA2 with Temporal Key Identity Protocol
(TKIP)
WPA2 with Advanced Encryption Standard (AES)
WPA/WPA2 with both TKIP and AES (802.11i Mixed Mode)
A detailed analysis of encryption is beyond the scope of this guide. Briefly,
however, the security of an encryption scheme often stands on the number
of times an encryption key is reused. Each of the above standards attempts
to create per-frame keys—that is a key that is used only one to encrypt a
single frame.
EAP Type Requirement Module Support
EAP-TLS digital certificate on both the server and the
wireless stations
authenticator or the authentication server
EAP-TTLS with PAP or
MD6
digital certificate on the server
user-entered name and password
the authenticator or the authentication
server
PEAP MS-CHAP v2 digital certificate on the server
user-entered name and password
the authenticator or the authentication
server
EAP-SIM Global System for Mobile communications
(GSM) smartcard on the wireless station
(phone)
the authenticator
EAP-GTC user-entered token card information or
password
the authenticator