ZyXEL AG-200 User’s Guide

LEAP

LEAP (Lightweight Extensible Authentication Protocol) is a Cisco implementation of IEEE802.1x.

For added security, certificate-based authentications (EAP-TLS, EAP-TTLS and PEAP) use dynamic keys for data encryption. They are often deployed in corporate environments, but for public deployment, a simple user name and password pair is more practical. The following table is a comparison of the features of five authentication types.

Comparison of EAP Authentication Types

 

EAP-MD5

EAP-TLS

EAP-TTLS

 

 

 

 

Mutual

No

Yes

Yes

Authentication

 

 

 

Certificate – Client

No

Yes

Optional

 

 

 

 

Certificate – Server

No

Yes

Yes

 

 

 

 

Dynamic Key

No

Yes

Yes

Exchange

 

 

 

Credential Integrity

None

Strong

Strong

 

 

 

 

Deployment

Easy

Hard

Moderate

Difficulty

 

 

 

Client Identity

No

No

Yes

Protection

 

 

 

PEAP

Yes

Optional

Yes

Yes

Strong

Moderate

Yes

LEAP

Yes

No

No

Yes

Moderate

Moderate

No

ii

Appendix A

Page 60
Image 60
ZyXEL Communications AG-200 manual Leap, Comparison of EAP Authentication Types