Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Cisco pushes for new wireless security protocol

LEAPs into loose and FAST acronymn world

Article comments

Cisco Systems has put its weight behind a new wireless security protocol to protect its proprietary but widely used EAP system.

The company has submitted a draft document to the IETF for a new Extensible Authentication Protocol type that's designed to fix security weaknesses in its proprietary Lightweight EAP, or LEAP, and calls it EAP Flexible Authentication via Secure Tunneling (EAP-FAST).

LEAP is Cisco's own authentication mechanism, used as part of an IEEE 802.1x authentication system, which is generally considered to be the emerging standard for network authentication.

Last year, LEAP security was compromised by various programs that enabled someone to guess a password while another person was logging onto a system with a dictionary program. Cisco's initial recommendations to worried users were:

  1. Use hard-to-guess passwords
  2. Use another existing EAP type, such as Protected EAP

But those other EAP types all require the use of a fairly complex digital certificate infrastructure to set up a secure tunnel between two ends of a network connection.

With EAP-FAST, Cisco has drafted a mechanism that looks and behaves like LEAP, but creates a PEAP-like tunnel without the use of certificates and infrastructure needed to support them, says Chris Bolinger, manager of product marketing for Cisco's wireless networking business unit.

It will be introduced into the Cisco Secure ACS security server and on Aironet wireless adapter cards, starting with the 350 series, in March, Bolinger says. The new type also is being released to partners in Cisco Compatability Extensions 3.0 specification. This spec outlines how to write software drivers that can work with parts of Cisco's operating system software. An array of third-party adapters and security products are expected to feature EAP FAST by fall, Bolinger says.


More from Techworld

More relevant IT news


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *