WindowsXP部署安全無(wú)線網(wǎng)PPT課件_第1頁(yè)
WindowsXP部署安全無(wú)線網(wǎng)PPT課件_第2頁(yè)
WindowsXP部署安全無(wú)線網(wǎng)PPT課件_第3頁(yè)
WindowsXP部署安全無(wú)線網(wǎng)PPT課件_第4頁(yè)
WindowsXP部署安全無(wú)線網(wǎng)PPT課件_第5頁(yè)
已閱讀5頁(yè),還剩18頁(yè)未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

1、pap, chap, mschap, eapadeap用戶驗(yàn)證用戶驗(yàn)證訪問(wèn)策略訪問(wèn)策略密鑰管理密鑰管理.3comuserdatabasexp 客戶端客戶端無(wú)線無(wú)線access point with 802.1xprimary ias3combackup iasdhcp serverdsds客戶端與 無(wú)線access point關(guān)聯(lián). 802.11access point 禁止對(duì)局域網(wǎng)(the virtual port)的訪問(wèn), 并應(yīng)用 802.1x 到客戶端 access point 在客戶端和 ias/radius服務(wù)器之間路由eap (extensible authentication p

2、rotocol)包 (over ethernet)如果客戶端驗(yàn)證成功, ias 告訴 access point 開(kāi)放端口. ias can return restrictions that the access point must implement for that port. these restrictions can include vlans and filters and encryption policies.after the port is opened, client initiates dhcp to get ipaddress on the connection.交互

3、過(guò)程xp client無(wú)線無(wú)線access point with 802.1x ias3comdsdsdhcpcert serverturn on user or machine cert auto-enrollment.machines/users already on 局域網(wǎng)will automatically get certificate.how do we handle users who have valid passwords, but they they do not have the auto-enrolled certificates to connect to 無(wú)線lan

4、?when client finds that it does not have certificates, it connects to network without an identity.if ias is configured to provide guest access, it tells the access point to accept the connection with restrictions accept, with a restriction to put the client into a special vlan or to apply ipfilters.

5、after connection, client gets auto-enrollment cert from ad, and establishes a new connection with the right credentials.interaction restricted lanphymacraw rate(mbps)ieee 802.11frequency hopping,direct sequencecarrier sense multiple accesscollision avoidance (csma/ca)1 or 2ieee 802.11bcomplementary

6、codekeying direct sequencecsma/ca11ieee 802.11gcck dscsma/ca22ieee 802.11aorthogonal frequencydivision multiplexingcsma/ca54hiperlan1gmskthree phase priority driven23.5hiperlan2ofdmtime division multiple access54openairfrequency hoppingcsma/ca1.6homerffrequency hoppingcsma/ca1, 10bluetoothfrequency

7、hoppingtime division multiple access1wireless physical layerwireless link layerinterface, e.g. ndisnetwork protocols, e.g.spx/ipx, tcp/ipclient applicationwireless physicallayerwireless link layerbridging functionwire link layer, e.g.ethernetwire physical layer,e.g. ethernetinterface, e.g. ndisnetwork protocols, e.g.spx/ipx, tcp/ipserver applicationphysical layerlink layeraccess pointmobileserverinternetaccesspointaccesspointethernetinternet gatewayrouting, access control, bi

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

評(píng)論

0/150

提交評(píng)論