Which EAP Type to choose for 802.1x Wireless Policy?

Hi everyone,
i have a question about recommendation for EAP Type in a wireless policy:
Which configuration is more secure/recommendet?
a)
Authentication Type: PEAP
EAP Type: EAP-MSCHAP v2
b)
Authentication Type: EAP
EAP Type: Certificate
We have a working configuration with a) and could Change to b).
Thanks,
Andy

Hi,
Project a uses PEAP cooperate with EAP(EAP-MSCHAP v2) is more security/recommended.
PEAP is a new member of the family of EAP protocols. To enhance both the EAP protocols and network security, PEAP provides:
1. Protection for the EAP method negotiation that occurs between client and server through a TLS channel. This helps prevent an attacker from injecting packets between the client and the network access server (NAS) to cause the negotiation of a less secure
EAP method. The encrypted TLS channel also helps prevent denial of service attacks against the IAS server.
2. Support for the fragmentation and reassembly of messages, allowing the use of EAP types that do not provide this.
3. Wireless clients with the ability to authenticate the IAS or RADIUS server. Because the server also authenticates the client, mutual authentication occurs.
4. Protection against the deployment of an unauthorized wireless access point (WAP) when the EAP client authenticates the certificate provided by the IAS server. In addition, the TLS master secret created by the PEAP authenticator and client is not shared
with the access point. Because of this, the access point cannot decrypt the messages protected by PEAP.
5. PEAP fast reconnect, which reduces the delay in time between an authentication request by a client and the response by the IAS or RADIUS server, and allows wireless clients to move between access points without repeated requests for authentication.
This reduces resource requirements for both client and server.
You can choose between two EAP types for use with PEAP: EAP-MS-CHAPv2 or EAP-TLS. EAP-MS-CHAPv2 uses credentials (user name and password) for user authentication. EAP-TLS uses either certificates installed in the client computer certificate store or a smart
card for user and client computer authentication. Comparatively, the second one is more security because public Key certificates provide a much stronger authentication method than those that use password-based credentials.
Best Regards,           
Eve Wang 

Similar Messages

  • Which service type to use for Proxy Service

    I have a question regarding a Proxy service.
    I have a need for a local (transport local) Proxy service which is called by another proxy service.
    It is a synchronous service which has an XML incoming message and an XML outgoing message.
    I have the following questions:
    - Does it make a difference in performance when I choose a WSDL webservice or a Messaging service?
    - Which one would you choose and why?
    Thanx

    Does it make a difference in performance when I choose a WSDL webservice or a Messaging service?Hardly there would be any difference.
    Which one would you choose and why?I would choose XML type messaging type proxy because input and output are XML messages. I won't choose WSDL web-service because it should be used in case of SOAP packagaing only (in web-service context, to enable SOAP and WS support) to mock a web-service which has a WSDL (and a XSD) associated with it.
    Regards,
    Anuj

  • Which Model Type to choose BPMN or EPC

    Hi
    I am trying to create Oracle's Standard Business Flows in ERP Application into BPA.
    Like Procure to Pay etc.,
    For this which Model Type is better (BPMN or EPC)?
    What are the things to be considered while choosing the Model type?
    Any direction is helpful...
    Regds
    Ravi

    Hi Ravi,
    The threads below should give you some hints:
    * EPC or BPMN: EPC or BPMN
    * BPMN in BPA 10.1.3.3: Re: BPMN  in BPA 10.1.3.3
    * EPC or BPMN at business process level: EPC or BPMN at business process level
    Basically there is a comment in one of the threads, which does conclude the question regarding EPC or BPMN in a nice way:
    "Use both diagram types in their strongest domains"
    Best, Danilo

  • Which user type to user for RFC receiver channel

    Hi Forum,
    I m developing XI scenarios which include RFC receiver chhanel (in IB: Integration Directory), to call a function moule in a R/3,
    which kind of user should i use for this purpose, i mean to say,
    which user type:
                    SYSTEM
                    Dialog
                    Communication
                    System
                    Reference
    and what should be the roles of that user,
    which type of the user doesnt gets locked, on wrong attempts

    Hi,
    Generally S_RFC and S_SERVICE authorizations  are nedded while calling RFC module from R3. Also check for role S_RFC_ADM
    The backend should have the authorization to execute the RFC on the backend.
    You can test the module in R3 and create a role using PFCG assign the tcode - SU53 (authorization check) and also assign the S_RFC and S_SERVICE to role.
    Refer
    RFC Logon user authorizations
    Question on service userid - for RFC call
    End User Authorizations and Roles
    Calling R3 RFC via http
    For RFC different authorization object is requried. You can ask your basis team to add the relevant authorization object in a new role and then add the new role to any existing service user or better create a new system user and add the role.
    Thanks
    swarup

  • Speed Tests Results for 802.11ac Wireless Connections

    Using the new Apple MacBook Air with 802.11ac wireless, I tested copying a file and a folder to both the new 802.11ac AirPort Extreme router housing a USB-connected hard disk and the less recent 802.11n Apple AirPort Extreme router housing a similar USB-connected hard disk.
    The results of the tests are summarized in the table below. The movie file was ripped from a DVD movie, and the Microsoft folder is simply the Microsoft Office 2011 folder in my Applications folder containing 14,231 items.
    The MacBook Air computer was located 6–8 feet away from each router with no intervening obstructions. While this was not a scientific test, it demonstrated to me that 802.11ac wireless is clearly superior to 802.11n in a real world setting. I assume that the lower relative performance of 802.11ac versus 802.11n for the large folder containing many files is due to overhead in copying and writing files from and to the hard disks. Ditto for the Gigabit Ethernet test.

    Great resource for speedtesting: www.speedtest.net
    Will show you ping speed, upload/download speeds for your connection. Try for each then post results.

  • RV220W - Wrong NAS Port-Type using RADIUS for 802.11

    Hi everyone
    I am attempting to configure the RV220W (Firmware 1.0.6.6) for dot1x authentication over a Windows 2008 based RADIUS Server (using Remote Access Services).
    The RADIUS settings on the RV220W are pointing towards that W2008 Server. The SSID has been set up for "WPA2 Enterprise" Security.
    All the authentication attempts arrive at the server, but they fail to get authenticated because the Cisco RV220W is not transmitting a "NAS Port-Type" and therefore, the RADIUS Server will reject the requests.
    This is what the request from the RV220W looks like on the server:
    And this is a request from a similar Zyxel Router:
    How can I enable the Cisco RV220W to send a NAS Port-Type (19, Wireless 802.11)?
    Thank you for your support!

    The RADIUS server in OS X Server is a standard FreeRADIUS implementation with Apple's own custom GUI frontend for configuring it and which only allows adding AirPort base-stations. In Mountain Lion Server it is even limited to a specific configuration for the AirPort base-station.
    However if you follow the normal command-line instructions and steps for configuring FreeRADIUS then it will be possible to add any type of RADIUS client.
    While as far as I can see by manually configuring the FreeRADIUS server in OS X Server should enable you to do what you want, most people chose to configure Squid to use either a PAM or the LDAP modules for Squid to in this case authenticate directly to Open Directory (which is of course based on LDAP).
    I myself have used a PAM in the past with Squid to successfully configure Squid to authenticate users via Open Directory. I was even able to specific an Open Directory group and only allow members of that group access via the Squid Proxy Server. I then went a bit OTT and set up another open-source tool (which was discontinued and I had to fix to get working) to process the Squid logs and store them in MySQL, and then setup FileMaker Pro to connect to the MySQL database via ODBC to allow producing reports.
    Unfortunately the AFP458 website had a major redesign a while ago and many previous technical articles on it are now hard to find. I had used two articles on that site to guide me through setting up Squid and the PAM on a Mac server. I believe the two articles I used are the ones listed below.
    http://afp548.com/2004/09/08/using-os-x-open-directory-to-authenticate-squid-pro xy-server/
    http://afp548.com/2004/12/13/squid-server-using-ldap-authentication/

  • Need Help regarding which Material Type to use for the Scenario

    Hi,
    Here we are configuring the service scenario.
    Suppose Electric Switch of customer flat is not working.
    Here in this case I will purchase the switch. And along with service order
    I will do the delivery of the Material. Then will raise the Invoice to the customer
    with service charge as well as material cost.
    Here I will have to run the MRP also for that material  to raise the PR if stock goes below
    the reorder point.
    So I will have to maintain the Purchase view, Sales View & MRP view to that Material.
    So in this case which standard material Type can I use for this material? Or I have to create
    our own material Type for this material.
    Regards,
    Pradip

    ROH is usually a material type that is supposed to be consumed in production.
    HALB is a semifinished good, own produced and meant to consumed in production.
    Both are usually not forseen to be sold.
    A material that you buy yourself and sell to a customer is a trading good, which is HAWA in SAP.

  • Which file type to use for editing

    I recently filmed a school talent show to create DVDs for the parents. I'll be using PrE 9 to edit. I understand the output for the movie will need to be MPEG2 for the DVD. We used three different cameras (I know this is a bad thing to do with PrE), but we used what we have available. Though, we did use a GoPro Hero2 mounted on the piano to give a unique perspective. Consequently I need to convert the video files into a common format for editing. Is there a "best" file format to edit in or is there a file format that is easiest to work with in Premiere Elements while maintaining the best quality for the DVD output?
    Here is what we used:
    Camera 1 (with the audio track from the sound board) was a Canon Vixia HF300. It exported in the dreaded .mts format (half the show at 24mbps and half at 17mbps)
    Camera 2 was a Nikon 5100 as .mov files, 1920x1080, H.264, Linear PCM, Total bit rate 19k
    Camera 3 was a GoPro Hero 2 recorded .mp4 1280x780 H.264 Total bit Rate 15k
    Since the aspect ratios are not equivalent, I plan on using black bars as opposed to cropping.
    I'm editting on an Apple MacBookPro 2.66GHz Intel Core 2 Duo with 8gb RAM running OSX 10.7
    Also, should I use Quicktime to convert these files into the common format I choose? Ironically, all this footage is editable in iMovie, but iMovie is horrible for multi-camera.
    Thanks,
    Ed

    Over on the Windows side of the aisle where I am, I would say convert all to DV AVI since the end will be a DVD, not a BluRay
    For Mac, I guess the SD version of DV AVI in the MOV wrapper
    I have some saved discussions & links, but have NO idea if any of these places have Mac versions
    Tools to Convert to DV-AVI http://forums.adobe.com/thread/415317
    Convert http://premierepro.wikia.com/wiki/FAQ:How_do_I_convert_my_files%3F
    Convert your HD files to DV-AVI Type II with 48KHz 16-bit Audio
    As well as the links just above, use Google to find conversion software
    I have NOT used the products below, I only forward due to other mentions... so YMMV and all the usual disclaimers... check the links and read to find out if one of the products listed below will rip or convert the files you have to something you need for editing
    http://www.corel.com/servlet/Satellite/us/en/Product/1175714228541#tabview=tab0
    http://www.womble.com/products/mvw.html
    http://www.magix.com/us/movie-edit-pro/ plus $5 Ship
    http://www.nchsoftware.com/prism/index.html
    http://www.videoredo.com/en/index.htm
    http://www.nchsoftware.com/prism/index.html Converter
    http://www.daniusoft.com/media-converter-ultimate.html
    http://www.deskshare.com/dmc.aspx Digital Media Converter
    http://www.any-dvd-ripper.com/any-dvd-ripper-windows.html
    http://www.deskshare.com/dvd-ripping-software.aspx
    http://www.dvdcopysoftware-reviews.com/dvd-cloner/
    http://www.topsoftwareol.com/product/Video/Video_Converter_Standard.html
    http://www.erightsoft.com/SUPER.html Multi-Converter <-- supposed to be very good
    http://download.cnet.com/FreeStar-Free-Video-Converter/3000-2194_4-10854990.html
    http://www.dvddecrypter.org.uk/ or http://www.mrbass.org/dvdrip/
    http://www.flaskmpeg.net/download.php Mpeg to AVI Converter
    http://www.squared5.com/ MPEG Streamclip Converter
    http://www.virtualdub.org/ Mpeg to AVI Converter
    http://www.sothinkmedia.com/video-converter/
    http://www.videohelp.com/tools/XviD4PSP

  • What paper type to choose for self-adhesive labels?

    Trying to tell my printer that I'm printing Avery self-adhesive labels. But I don't see any settings for label paper under paper type.
    What should I pick, "Specialty Paper"? "Other inkjet paper"?

    You choose a standard page size. Most labels are on an 8.5x11 sheet and in portrait orientation. So select that size if it's not already the default for the printer.
    I've done labels on many Macs and number of printers. Most of the time, a template for the various Avery labels and their clones is available within the program that generated labels. I've not seen a printer setting for labels on any of the 5+ printers I've used to make labels, going back to Mac OS 6.
    Example: In MS Word 2008, the is a menu choice in Tools > Labels... that helps you set up labels. The screen will show an image of the layout you selected from the "Labels.." option. Word inserts section breaks and columns that exactly fit the Avery number you chose.
    At that point you can fill in each label manually or, even better yet, use The Mail Merge function in Office to populate the labels with info from a spreadsheet or a Word table. It goes so fast that it's probably taken me more time for my challeged typing skills to hammer out this repsonse that to make a bunch of labels!
    PageMaker and, later,Adobe InDesign have similar templates.
    So what program are you using the make labels?
    TIP: I have both a b/w laser and an ink-jet printer. I almost always use the laser for printing labels that will go though the mail. The reason: laser lettering is waterproof. If the the letter has ink-jet labels and gets wet, the ink on the labels will run and be harder for our postal employees to read and deliver.
    Note that a laser printer requires a special type of label stock that will stand up the high heat inside the printer.
    Allan

  • Which module do I choose for reading voltages

    Hi All,
    Could someone give me some advice in there opinion on which SCXI
    voltage module to choose please.
    I want to log analog voltages ranging from the low mvolts to volts.
    I'm looking at between the SCXI-1100, the SCXI-1102 and the
    SCXI-1102B/C. Could someone also explain the filtering rate as well,
    what effect this has on the signal etc.
    Thanks in advance
    Nat

    Hi Natalie,
    I know this is not the answer you are looking for, but probably, the best solution is to call your local NI Field/Sales Engineer and explain him/her what you are trying to do. Also, it will be easier to disscuss price, performance and other parameters that must be considered when taking such a decision.(usually, his/her e-mail/phone is in the bottom-left page corner when logging to "MyNI" account)
    Good Luck

  • Trying to check in to airline. Says I need a flashplayer. Which one do I choose for iPad

    I am trying to check in online for airline boarding pass. Says I need a flash player which is not supported by iPad. Is there an app I can get to install flash player?

    Adobe has not made a version of Flash for the iPad.
    Kappy explains why. https://discussions.apple.com/message/19446567#19446567
    5 Flash Player Alternatives http://www.techshout.com/features/2011/01/flash-player-for-ipad-apps/
    Top 4 browsers supports flash player on iPad and iPhone
    http://mashtips.com/flash-player-ios/
     Cheers, Tom

  • Which mov type is used for transfer?

    Hi,
    Which move ment type is used to transfer vendor consignment stock to unrestricted stock, is this 403?
    Thanks,
    Aditya

    Hi Aditya,
    To transfer the material from vendor consignment to unrestricted stock you must use movement type :411 bwith special stock indicator K.
    Regards,
    Tushar Patankar

  • Which ODBC driver to choose for a multi version , multi home installation

    I have a situation where I need to rollout a piece of software which connects to an Oracle 64 bit database. The client group that I need to rollout to includes a combination of Oracle8, Oracle 9 and Oracle 10. Some installations have dual 8/9 Homes and I am sure that there are other combinations.
    The software connects through either a normal oracle connection or can connect through ODBC. However, the normal connection software will not connect through Oracle below Oracle 9, So I am left with an ODBC driver. I am using the microsoft driver currently - it is very slow, but it is at least already installed on all the user pc's. However I believe that it does not work with dual homes.
    Is there an Oracle driver that would meet our needs?, i.e allow connections from version 8 to 10 with any combination of homes.

    You're right that the Microsoft ODBC driver for Oracle doesn't support multiple Oracle Homes. It also isn't updated regularly, so it doesn't support a lot of functionality that was added in Oracle 9 or 10.
    Exactly what versions of Oracle does "Oracle8" comprise. There is a world of difference between having some 8.1.7 databases still in prod and having some ancient 8.0.4 databases around. Depending on the "Oracle8" variants in the world, you should be able to use either the 8.1.7.x or 9.2.0.x Oracle ODBC driver should work for you. You'll need to install an appropriate Oracle Home for that driver (i.e. the machine will have to have an 8.1.7 Oracle Home if you're going to use the 8.1.7.x Oracle ODBC driver, it'll need a 9.2 Oracle Home if you're going to use the 9.2.0.x Oracle ODBC driver). Since 8.1.7 has been desupported, I'm hopeful that you can use the 9.2.0.x Oracle ODBC driver since Oracle 9.2 will at least be supported a few more months.
    Justin

  • Which address format to choose for Chinese addresses?

    Hi;
    In Addressbook, I'm trying to enter a Chinese address. I'm standing in Beijing, can't get more Chinese than this.
    A Chinese address looks like this:
    中国北京市东城区东中街20号3号楼1311 100022
    Chinese addresses go from country (中国) first to apartment number (1311) in a single stream, with the postal code last for sorting.
    This has nothing to do with the Address format when I choose "China" under "Change Address Format". Is there another "China" that I should select?
    Any help would be appreciated -- I'd like to preserve as much of the chinese characters and formatting as I can.
    Additionally, if I can manually create a format that goes:
    Country-Province-City-District-address postal
    ... then I'd at least preserve the chinese formatting.
    Thanks...
    Allan
    Powerbook G4   Mac OS X (10.4.8)   Addressbook 4.0.4 (485.1)

    FAT is FAT32 is MSDOS
    exFAT is FATex
    Disk Utility select second drive media
    Hit the partition tap, select big box click 2 partitions,
    select 1 partition format OS X extended, select the other partition format MSDOS click Apply.
    https://discussions.apple.com/message/16276201#16276201
    Because you have a unusual setup, I don't know exactly how Bootcamp is going to handle it, you got to download the drivers and read the PDF.
    However when you insert the Windows 7 DVD to install, you first need to change the MSDOS/FAT32 format to NTFS using the Windows disk, Disk Utility or Bootcamp won't do it.
    https://www.apple.com/support/bootcamp/

  • Which wifi adaptor to choose for T410s?

    Hello,
    I am now ordering a new T410s and I don't know what the real (not on paper) difference is between these four choices:
    ThinkPad b/g/n
    Intel Centrino Advanced-N 6200 (2X2 AGN) [add $20.00]
    Intel Centrino Ultimate-N 6300 (3X3 AGN) [add $40.00]
    Intel Centrino Advanced-N + WiMAX 6250 [add $55.00]
    Is it worth it for me to pay some extra $20 or $40? Theoretically these adapters can work faster when plugged into a fast network, but doesn't it ultimately depend on the internet provider? and is there a real-life difference between these? I use comcast at home but I take my laptop to university where I work everyday. The university has an all-campus coverage but for some reason i get a very weak signal in my office. Would the 6200 help me solve this issue? Is it worth the money? Thank you,
    Christina

    Two high end manufacturers that haven't been mentioned, Metric Halo and RME:
    http://mhsecure.com/metric_halo/products/hardware/uln-2.html
    http://www.rme-audio.de/en_index.php

Maybe you are looking for

  • No way to print report instance

    When users view a report instance that was saved as an MS Excel spreadsheet the print option does not automatically appear in the toolbar.  Is there a way to make the Standard options appear in the toolbar?

  • To restrict Multiple Entries in IT 2006

    Hi All, We are generating the absence quotas using the report RPTQTA00. Problem is if the some one is running this report multiple times for the same period multiple entries are getting generated with same quota type and same dates. Please advice how

  • Import EJB to Java Studio Creator 2?

    Hey all, I'm not quite sure if this is where I want to ask this question or not. I could not find another place to so I hope here will be fine. I've been working with EJB's and deploying them to JBoss for some time now, however I'm not to great on th

  • Regarding API for crreating input values.

    hi everybody, this is API to create input values for an element. when i run this script it gives me error saying ORA-20001: PAY_6171_INPVAL_NO_LOOKUP: this is the code DECLARE P_INPUT_VALUE_ID     NUMBER; P_OBJECT_VERSION_NUMBER NUMBER ; P_EFFECTIVE_

  • Nokia Booklet 3G release date in New Zealand

    Im a Nokia faithful, love the new booklet 3g. I just wondering anyone happen to know if Nokia is planning on selling their notebook in New Zealand in the near future.