Cisco WLAN bridge: to VPN or not to VPN..that is the question

From: blah (blah@blah.com)
Date: 04/30/02


From: blah@blah.com (blah)
Date: Mon, 29 Apr 2002 23:25:52 GMT

Without going into all the gory details.....

I can do a Cisco Bridge 350 using Cisco LEAP to authenticate the
non-root bridge as a LEAP client. Then I get all the 802.1x stuff as
well as the cisco security tweaks while using a Steel Belted Radius
Server for authentication (of non-root bridge).

or I can setup a pair of Nokia Crypto-clusters and run triple-des over
the link and leave the physical side of things fairly open.

obviously the vpn solution adds cost, complexity, support issues,
etc., but would 802.1x leap be secure enough for the next 12 months or
so??

any opinions welcome..



Relevant Pages

  • Re: Cisco WLAN bridge: to VPN or not to VPN..that is the question
    ... O lot of security experts recommend, ... > I can do a Cisco Bridge 350 using Cisco LEAP to authenticate the ... > non-root bridge as a LEAP client. ... > Server for authentication (of non-root bridge). ...
    (comp.security.misc)
  • Weaknesses in LEAP Challenge/Response
    ... I sent a tool I had written to the Cisco PSIRT team ... authentication mechanism. ... to efficiently launch offline dictionary attacks against LEAP user ... was that Cisco was continuing to push LEAP to customers in their CCX ...
    (Bugtraq)
  • Re: Weaknesses in LEAP Challenge/Response
    ... I sent a tool I had written to the Cisco PSIRT team ... > to efficiently launch offline dictionary attacks against LEAP user ... mitigate against dictionary attacks is to create a strong password policy. ...
    (Bugtraq)
  • Re: 802.11 adapter for CE 5.0, leap compatible
    ... Cisco and use that. ... > You could write an EAP extension DLL yourself to handle LEAP, ... >> I am not sure if you understand that the hospitals are not coming to us ...
    (microsoft.public.windowsce.platbuilder)
  • LEAP (or WPA-Ent) and WPA-PSK to work on a single 1200AP???
    ... Palm LifeDrive only support WEP or WPA-PSK. ... Our Cisco Wlan uses CISCO ... Leap but we are considering going to WPA-Enterprise. ... upgrade our LEAP to WPA-Enterprise first?? ...
    (comp.dcom.sys.cisco)