Cisco 1231G - Aironet - Wireless Access Point Specifikace Strana 120

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 272
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 119
Chapter 4 Security Setup
Security Overview
4-8
Cisco Aironet 1200 Series Access Point Software Configuration Guide
OL-2159-01
During shared key authentication, the access point sends an unencrypted
challenge text string to any device attempting to communicate with the access
point. The device requesting authentication encrypts the challenge text and
sends it back to the access point. If the challenge text is encrypted correctly,
the access point allows the requesting device to authenticate. Both the
unencrypted challenge and the encrypted challenge can be monitored,
however, which leaves the access point open to attack from an intruder who
calculates the WEP key by comparing the unencrypted and encrypted text
strings. Because of this weakness, shared key authentication can be less
secure than open authentication. Like open authentication, shared key
authentication does not rely on a RADIUS server on your network.
Figure 4-5 shows the authentication sequence between a device trying to
authenticate and an access point using shared key authentication. In this
example the devices WEP key matches the access points key, so it can
authenticate and communicate.
Figure 4-5 Sequence for Shared Key Authentication
Protecting the Access Point Configuration with User Manager
The access points user manager feature prevents unauthorized entry to the access
point management system. You create a list of administrators authorized to view
and adjust the access point settings; unauthorized users are locked out. See the
Setting Up Administrator Authorization section on page 4-38 for instructions
on using the user manager.
Access point
or bridge
with WEP key = 123
Client device
with WEP key = 123
1. Authentication request
2. Unencrypted challenge
3. Encrypted challenge response
4. Authentication response
54584
Zobrazit stránku 119
1 2 ... 115 116 117 118 119 120 121 122 123 124 125 ... 271 272

Komentáře k této Příručce

Žádné komentáře