WindowsXP部署安全無線網(wǎng)PPT課件_第1頁
WindowsXP部署安全無線網(wǎng)PPT課件_第2頁
WindowsXP部署安全無線網(wǎng)PPT課件_第3頁
WindowsXP部署安全無線網(wǎng)PPT課件_第4頁
WindowsXP部署安全無線網(wǎng)PPT課件_第5頁
已閱讀5頁,還剩18頁未讀, 繼續(xù)免費閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)

文檔簡介

1、pap, chap, mschap, eapadeap用戶驗證用戶驗證訪問策略訪問策略密鑰管理密鑰管理.3comuserdatabasexp 客戶端客戶端無線無線access point with 802.1xprimary ias3combackup iasdhcp serverdsds客戶端與 無線access point關(guān)聯(lián). 802.11access point 禁止對局域網(wǎng)(the virtual port)的訪問, 并應(yīng)用 802.1x 到客戶端 access point 在客戶端和 ias/radius服務(wù)器之間路由eap (extensible authentication p

2、rotocol)包 (over ethernet)如果客戶端驗證成功, ias 告訴 access point 開放端口. ias can return restrictions that the access point must implement for that port. these restrictions can include vlans and filters and encryption policies.after the port is opened, client initiates dhcp to get ipaddress on the connection.交互

3、過程xp client無線無線access point with 802.1x ias3comdsdsdhcpcert serverturn on user or machine cert auto-enrollment.machines/users already on 局域網(wǎng)will automatically get certificate.how do we handle users who have valid passwords, but they they do not have the auto-enrolled certificates to connect to 無線lan

4、?when client finds that it does not have certificates, it connects to network without an identity.if ias is configured to provide guest access, it tells the access point to accept the connection with restrictions accept, with a restriction to put the client into a special vlan or to apply ipfilters.

5、after connection, client gets auto-enrollment cert from ad, and establishes a new connection with the right credentials.interaction restricted lanphymacraw rate(mbps)ieee 802.11frequency hopping,direct sequencecarrier sense multiple accesscollision avoidance (csma/ca)1 or 2ieee 802.11bcomplementary

6、codekeying direct sequencecsma/ca11ieee 802.11gcck dscsma/ca22ieee 802.11aorthogonal frequencydivision multiplexingcsma/ca54hiperlan1gmskthree phase priority driven23.5hiperlan2ofdmtime division multiple access54openairfrequency hoppingcsma/ca1.6homerffrequency hoppingcsma/ca1, 10bluetoothfrequency

7、hoppingtime division multiple access1wireless physical layerwireless link layerinterface, e.g. ndisnetwork protocols, e.g.spx/ipx, tcp/ipclient applicationwireless physicallayerwireless link layerbridging functionwire link layer, e.g.ethernetwire physical layer,e.g. ethernetinterface, e.g. ndisnetwork protocols, e.g.spx/ipx, tcp/ipserver applicationphysical layerlink layeraccess pointmobileserverinternetaccesspointaccesspointethernetinternet gatewayrouting, access control, bi

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論