ZyAIR G-110 User’s Guide

LEAP

LEAP (Lightweight Extensible Authentication Protocol) is a Cisco implementation of IEEE802.1x.

For added security, certificate-based authentications (EAP-TLS, EAP-TTLS and PEAP) use dynamic keys for data encryption. They are often deployed in corporate environments, but for public deployment, a simple user name and password pair is more practical. The following table is a comparison of the features of five authentication types.

Comparison of EAP Authentication Types

 

EAP-MD5

EAP-TLS

EAP-TTLS

PEAP

LEAP

 

 

 

 

 

 

Mutual

No

Yes

Yes

Yes

Yes

Authentication

 

 

 

 

 

Certificate – Client

No

Yes

Optional

Optional

No

 

 

 

 

 

 

Certificate – Server

No

Yes

Yes

Yes

No

 

 

 

 

 

 

Dynamic Key

No

Yes

Yes

Yes

Yes

Exchange

 

 

 

 

 

Credential Integrity

None

Strong

Strong

Strong

Moderate

 

 

 

 

 

 

Deployment

Easy

Hard

Moderate

Moderate

Moderate

Difficulty

 

 

 

 

 

Client Identity

No

No

Yes

Yes

No

Protection

 

 

 

 

 

B

Types of EAP Authentication