Header
Home | Sitemap  
Sections
Archive
Su Mo Tu We Th Fr Sa
1
2345678
9101112131415
16171819202122
23242526272829
30
Syndication



Security

by

image

 

Security

In 2000, during the initial deployment, the Cisco security architecture was based upon a combination of Cisco LEAP, for authentication, and Cisco Key Integrity Protocol (CKIP), for data integrity (encryption). However, as the industry, solutions, and threats evolved, Cisco further strengthened the security of its internal WLAN.

In 2005, Cisco replaced LEAP with Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST). EAP-FAST further secures authentication by ensuring that all user credentials and passwords are passed from the client to the authenticators via a strongly encrypted tunnel. For more information about EAP-FAST, visit http://www.cisco.com/en/US/netsol/ns339/ns395/ns176/ns178/netqa09186a00802030dc.html or visit Cisco.com and search for the keyword EAP-FAST.

Additionally, and in line with Cisco IT's policy of adopting open, cross-industry standards (where applicable and where Cisco does not provide enhanced value-added alternatives), WiFi Protected Access (WPA) was adopted as the encryption protocol for data integrity.

The Wireless LAN Solution Engine (WLSE) provides radio-based rogue AP detection and has been integrated into Cisco IT's help desk case generation system. Additionally, an internally developed tool is used for network-based (that is, wired) scanning. This tool regularly scans Class C IP subnets, searching for devices that satisfy certain criteria and may be rogue access points. Based upon so-called "TCP port fingerprinting" and other holistic logic, the tool compares all devices it detects with the database of Cisco IT installed access points. Where a device is not already listed as a Cisco IT device, it is flagged as "interesting," and a case is automatically generated. This case, in turn, is routed to the Tier 2 support team for investigation.

253 times read

Related news

» Wireless Domain Services for IEEE 802.1X Local Authentication Service and Fast Secure Roaming Support
by admin posted on Dec 10,2006
» What is a Wireless-aware LAN?
by admin posted on Dec 10,2006
» Integrated Wired and WLAN Services using the Cisco Infrastructure and Cisco IOS Software
by admin posted on Dec 10,2006
» CiscoWorks WLAN Solution Engine
by admin posted on Dec 10,2006
» What the Future Holds
by admin posted on Jan 20,2007


More Top News
Cisco Wireless Networking
Most Popular
Featured Author