 ysreenu
join:2006-01-10 Austin, TX
| Using 8021X authentication and static WEP keys
Hi All,
I want to know how good or bad using 8021X authentication coupled with static WEP keys.
Is it theoretically possible to configure both AP and station to use 8021X authentication for Access control purpose and static WEP keys for encryption purpose?
I see this kind of option being provided in Wireless supplicant's like Microsoft's WZC and Funk Odyssey client. Please let me know if any APs in the marked let the user configure static/dynamic WEP keys along with 8021X authentication?
-- ysreenu |
|
  funchords Robb Topolski Premium,MVM join:2001-03-11 Hillsboro, OR
·Verizon Online DSL
·Skype
·Comcast
| Sure, it's possible. No wi-fi devices offer it, AFAIK. That's one step away from 802.1X with dynamic WEP keys.
But, to your question:
With static keys, WEP is easily cracked with freeware tools. So, at some point, it would be easy to capture the packets from your network, and use your cracked key to later decrypt and read your e-mail, instant messages, and web traffic (except for secure websites).
The 802.1X authentication would keep a bad guy from actually connecting, but they don't need to connect in order to monitor. -- Robb Topolski -= funchords.com =- Hillsboro, Oregon USA ~ Keeper of the D-Link FAQ ~ Did you Search? ~ More features, Free! Join BBR! ~ |
|
 jbibe Premium,MVM join:2001-02-22
| reply to ysreenu said by ysreenu :Please let me know if any APs in the marked let the user configure static/dynamic WEP keys along with 8021X authentication? Several Access Points built by ZyXEL provide 802.1x with static/dynamic WEP. Although it is available, I strongly recommend against static WEP. As a minimum, use dynamic WEP. If you want more information, contact ZyXEL before making any purchase, since some items sold by ZyXEL do not include this feature. |
|
 DavidJWood Premium join:2001-10-12 UK | From memory, ZyXEL's documentation strongly recommends against 802.1x with even dynamic WEP. If you're going to that much trouble, why not deploy WPA Enterprise and get the advantages of, amongst other things, MIC?
David |
|
 ysreenu
join:2006-01-10 Austin, TX
| Hi All,
Thanks for your information. I just wnated to know this to evaluate a sample AP that I am testing. I am not going to buy an AP for myself 
Thanks anyway.
-- ysreenu |
|