6: Network Settings
PremierWave® XN Intelligent Gateway User Guide
58
IEEE 802.1X
Select the protocol to use to authenticate the WLAN client.
LEAP
= Lightweight Extensible Authentication Protocol. A derivative of the
original
Cisco
LEAP
, which was a predecessor of 802.1X. Real
Cisco
LEAP
uses a special MAC layer authentication (called
Network
EAP
) and cannot work
with
WPA/WPA2
. The PremierWave XN intelligent gateway uses a more generic
version to be compatible with other major brand Wi-Fi equipment. The
authentication back end is the same.
EAP-TLS =
Extensible Authentication Protocol - Transport Layer Security. Uses
the latest incarnation of the
Secure Sockets Layer
(SSL)
standard and is the
most secure because it requires authentication certificates on both the network
side and the PremierWave XN side.
EAP-TTLS =
Extensible Authentication Protocol - Tunneled Transport Layer
Security.
PEAP
= Protected Extensible Authentication Protocol.
EAP-TTLS
and
PEAP
have been developed to avoid the requirement of
certificates on the client side (PremierWave XN unit), which makes deployment
more cumbersome. Both make use of
EAP-TLS
to authenticate the server
(network) side and establish an encrypted tunnel. This is called the outer-
authentication. Then a conventional authentication method (
MD5
,
MSCHAP
,
etc.) is used through the tunnel to authenticate the PremierWave XN device. This
is called inner authentication.
EAP-TTLS
and
PEAP
have been developed by
different consortia and vary in details, of which the most visible is the supported
list of inner authentications.
Note:
When using
EAP
-
TLS
,
EAP
-
TTLS
or
PEAP
authority, at least one authority
certificate will have to be installed in the
SSL
configuration that is able to verify the
RADIUS server’s certificate. In case of
EAP
-
TLS
, also a certificate and matching
private key need to be configured to authenticate the PremierWave XN device to the
RADIUS server. For more information about SSL certificates see
. The IEEE 802.1X options will be available only if the IEEE 802.1X
authentication is selected.
EAP-TTLS Option
Select the inner authentication method to be used with EAP-TTLS, if the EAP-TTLS
IEEE 802.1X is selected.
EAP-MSCHAPV2
MSCHAPV2
MSCHAP
CHAP
PAP
EAP-MD5
PEAP Option
Select the inner authentication method to be used with EAP-PEAP, if the PEAP
IEEE 802.1X is selected.
EAP-MSCHAPV2
EAP-MD5
Username
User ID for identifying the PremierWave XN unit to the RADIUS server in the
network
Password
Select the password for identifying the PremierWave XN intelligent gateway to the
RADIUS server in the network.
Validate Certificate
Select to
Enable
or
Disable
, if the EAP-TLS IEEE 802.11X is selected. If enabled,
the PremierWave XN unit will attempt to validate the certificate received from the
RADIUS server.
WLAN Profile WPA
& WPA2 Settings
(continued)
Description