cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
0
Helpful
7
Replies

PEAP username over the air

jamesgef
Level 1
Level 1

I have a 4404 controller with 1010APs and deciding which EAP method to use. As I was analyzing this and sniffing wireless packets, username is sent in clear over the air when authenticating with PEAP.

I was somewhat surprised and thought that was one of the limitation of LEAP but not PEAP.

Is this normal behavior?

Thx!

James

7 Replies 7

misramanish
Level 1
Level 1

Interesting post! I'm debating between PEAP and EAP-FAST myself and am really surprised to hear that you were able to capture username from your sniffer.

What encryption method are you using, btw? TKIP, CCMP or AES? Of the three, I have heard that AES will provide highest encryption (which in theory should totally encrypt all user credentials).

What 802.1X supplicant is at work here?

Controller is set only for WPA2 with AES encryption and 802.1x.

I'm using a Cisco Aironet a/b/g PCMCIA card using the Cisco Aironet utility (latest version) as my supplicant (not using windows configuration for wireless networks).

James

Just to provide more information, my profile in the Cisco Aironet Utility is configured for PEAP with MS-CHAP-v2.

James

Zhenning is correct. The encryption method has nothing to do with the 802.1x process. Until the authentication process is finished the unicast keys are not generated. All the data exchange gets encrypted using the generated keys after the authentication process.

zhenningx
Level 4
Level 4

PEAP usernames can be sent in clear text or encrypted. By using windows native WZC config, the usersnames are in clear text. By using Intel supplicant, the PEAP usernames are encrypted as well. The capture only sees "anoymous" as the username.

Zhenning

Is MSCHAVPv2 or GTS being used as the inner method for ACU?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card