
7. Click Next to open the Security Settings.
8. Click Enterprise Security.
9. Network Authentication: Select WPA-Enterprise or WPA2-Enterprise (Recommended).
10. Data Encryption:
AES-CCMP is recommended.
11. Enable 802.1X: Selected.
12. Authentication Type: Select EAP-FAST to be used with this connection.
Step 1 of 3: EAP-FAST Provisioning
With CCXv4, EAP-FAST supports two modes for provisioning:
● Server-Authenticated Mode: Provisioning inside a server authenticated TLS tunnel.
● Server-Unauthenticated Mode: Provisioning inside an unauthenticated TLS tunnel.
NOTE: Server-Authenticated Mode provides significant security advantages over Server-Unauthenticated
Mode even when EAP-MS-CHAP-V2 is being used as an inner method. This mode protects the EAP-MS-
CHAP-V2 exchanges from potential Man-in-the-Middle attacks by verifying the server’s authenticity before
exchanging MS-CHAP-V2. Therefore, Server-Authenticated Mode is preferred whenever it is possible. EAP-
Commentaires sur ces manuels