1
00:00:00,150 --> 00:00:00,983
In this lesson,

2
00:00:00,983 --> 00:00:03,540
we're going to cover wireless security setting.

3
00:00:03,540 --> 00:00:06,750
Wireless networks have become a big part of modern life

4
00:00:06,750 --> 00:00:08,220
by providing us with convenient

5
00:00:08,220 --> 00:00:10,440
and flexible access to the internet.

6
00:00:10,440 --> 00:00:13,200
However, these wireless networks can also present

7
00:00:13,200 --> 00:00:14,910
some unique security challenges.

8
00:00:14,910 --> 00:00:15,883
So we need to look at the importance

9
00:00:15,883 --> 00:00:19,260
of using the right wireless security settings,

10
00:00:19,260 --> 00:00:21,420
including the use of WPA3

11
00:00:21,420 --> 00:00:24,450
or other forms of wireless encryption, AAA,

12
00:00:24,450 --> 00:00:26,460
and RADIUS for creating additional layers

13
00:00:26,460 --> 00:00:28,230
of authentication on a network,

14
00:00:28,230 --> 00:00:31,200
and the use of the Extensible Authentication Protocol

15
00:00:31,200 --> 00:00:32,043
known as EAP.

16
00:00:33,060 --> 00:00:35,940
First, let's review some of the most common forms

17
00:00:35,940 --> 00:00:40,940
of wireless encryption, including WEP, WPA, WPA2,

18
00:00:41,997 --> 00:00:46,290
and the most secure form of the wireless encryption, WPA3.

19
00:00:46,290 --> 00:00:48,930
Wireless encryption and cryptographic protocols

20
00:00:48,930 --> 00:00:51,150
are an important part of wireless security

21
00:00:51,150 --> 00:00:54,150
since they provide us with the algorithms that we can use

22
00:00:54,150 --> 00:00:57,270
to encrypt any data being sent over our wireless networks

23
00:00:57,270 --> 00:00:59,400
to ensure that it's unreadable to anyone

24
00:00:59,400 --> 00:01:01,320
who might try to intercept it.

25
00:01:01,320 --> 00:01:04,680
This provides us with confidentiality in our networks.

26
00:01:04,680 --> 00:01:07,653
The first form of wireless encryption was known as WEP.

27
00:01:08,520 --> 00:01:11,820
WEP, also known as Wired Equivalent Privacy

28
00:01:11,820 --> 00:01:13,440
was released in 1999

29
00:01:13,440 --> 00:01:17,340
as part of the original IEEE 802.11 standard,

30
00:01:17,340 --> 00:01:19,320
and it's considered to be an outdated

31
00:01:19,320 --> 00:01:21,000
wireless network security standard

32
00:01:21,000 --> 00:01:23,610
that aimed to provide a wireless local area network

33
00:01:23,610 --> 00:01:26,160
with the equivalent level of security and privacy

34
00:01:26,160 --> 00:01:28,500
when compared against what is usually expected

35
00:01:28,500 --> 00:01:30,723
of a wired local area network.

36
00:01:31,637 --> 00:01:35,160
WEP employs a static encryption key system

37
00:01:35,160 --> 00:01:37,860
where devices on the same network use the same key

38
00:01:37,860 --> 00:01:40,320
to encrypt and decrypt messages.

39
00:01:40,320 --> 00:01:42,810
Wired equivalent privacy encryption keys

40
00:01:42,810 --> 00:01:47,100
come in two main sizes 64-bit and 128-bit.

41
00:01:47,100 --> 00:01:51,960
The 64-bit WEP key is typically 40 bits of actual key data

42
00:01:51,960 --> 00:01:53,430
with an additional 24 bits

43
00:01:53,430 --> 00:01:56,520
of initialization vector added to it.

44
00:01:56,520 --> 00:02:01,260
While the 128-bit WEP key is composed of 104 bits

45
00:02:01,260 --> 00:02:04,530
of key data, again with an additional 24 bits

46
00:02:04,530 --> 00:02:06,300
of initialization vector.

47
00:02:06,300 --> 00:02:10,050
The use of a longer key and the 128-bit WEP

48
00:02:10,050 --> 00:02:12,300
was intended to offer stronger security,

49
00:02:12,300 --> 00:02:13,710
but both have been proven

50
00:02:13,710 --> 00:02:16,290
to be easily compromised with modern techniques.

51
00:02:16,290 --> 00:02:18,180
This system is fundamentally flawed

52
00:02:18,180 --> 00:02:20,700
because with enough data traffic to analyze,

53
00:02:20,700 --> 00:02:23,100
especially with tools to automate this process,

54
00:02:23,100 --> 00:02:25,530
an intruder can often reconstruct the key.

55
00:02:25,530 --> 00:02:28,230
Leading to unauthorized network access.

56
00:02:28,230 --> 00:02:30,810
Furthermore, due to its reliance on the weak

57
00:02:30,810 --> 00:02:34,710
and vulnerable RC4 encryption algorithm, WEP is susceptible

58
00:02:34,710 --> 00:02:37,530
to relatively straightforward cryptographic attacks,

59
00:02:37,530 --> 00:02:40,140
so it is considered to be an insecure option

60
00:02:40,140 --> 00:02:43,140
for wireless security and should no longer be used.

61
00:02:43,140 --> 00:02:45,390
When you hear about WEP, I want you to remember

62
00:02:45,390 --> 00:02:46,950
that it is considered insecure

63
00:02:46,950 --> 00:02:49,860
because of a weak 24-bit initialization vector

64
00:02:49,860 --> 00:02:52,740
that modern laptops can crack in just about three minutes

65
00:02:52,740 --> 00:02:55,053
for almost every WEP-based network.

66
00:02:56,070 --> 00:03:00,180
WEP was then replaced by WPA or Wi-Fi Protected Access

67
00:03:00,180 --> 00:03:04,530
in 2003 as an interim security enhancement over the flawed WEP

68
00:03:04,530 --> 00:03:08,280
while the IEEE 802.11i wireless security center

69
00:03:08,280 --> 00:03:09,300
was being developed.

70
00:03:09,300 --> 00:03:12,510
WPA aimed to correct the pitfalls of WEP

71
00:03:12,510 --> 00:03:14,160
and provide stronger security measures

72
00:03:14,160 --> 00:03:15,630
for wireless networks.

73
00:03:15,630 --> 00:03:19,380
WPA was designed to improve upon WEP's encryption mechanisms

74
00:03:19,380 --> 00:03:22,620
by implementing a temporal key integrity protocol

75
00:03:22,620 --> 00:03:24,450
known as TKIP,

76
00:03:24,450 --> 00:03:28,320
which dynamically generates a new 128-bit key

77
00:03:28,320 --> 00:03:29,400
for each packet,

78
00:03:29,400 --> 00:03:31,920
and thus prevents the key reuse vulnerabilities

79
00:03:31,920 --> 00:03:33,660
associated with WEP.

80
00:03:33,660 --> 00:03:37,320
However, while WPA was a significant step forward,

81
00:03:37,320 --> 00:03:40,080
it still inherited some of WEP's vulnerabilities

82
00:03:40,080 --> 00:03:42,690
due to having being initially designed as a patch

83
00:03:42,690 --> 00:03:45,390
for the existing WEP networks already in use

84
00:03:45,390 --> 00:03:47,310
by enterprises around the world.

85
00:03:47,310 --> 00:03:49,980
Although it was considered to be more secure than WEP

86
00:03:49,980 --> 00:03:53,370
at the time of its release, WPA's own vulnerabilities,

87
00:03:53,370 --> 00:03:57,330
particularly those within the TKIP quickly became apparent,

88
00:03:57,330 --> 00:03:59,880
and this makes WPA susceptible to certain forms

89
00:03:59,880 --> 00:04:00,990
of cryptographic attacks

90
00:04:00,990 --> 00:04:03,540
and emphasizes the need for further advancements

91
00:04:03,540 --> 00:04:05,640
in wireless security protocols.

92
00:04:05,640 --> 00:04:08,130
When you hear about WPA, I want you to remember

93
00:04:08,130 --> 00:04:09,510
that it's considered insecure

94
00:04:09,510 --> 00:04:12,090
because of the lack of sufficient data integrity checks

95
00:04:12,090 --> 00:04:14,460
and the TKIP implementation.

96
00:04:14,460 --> 00:04:18,660
So when the 802.11i standard was introduced in 2004,

97
00:04:18,660 --> 00:04:21,269
a replacement for WPA called WPA2

98
00:04:21,269 --> 00:04:24,360
or Wi-Fi Protected Access 2 was released.

99
00:04:24,360 --> 00:04:27,150
WPA2 brought a new level of data protection

100
00:04:27,150 --> 00:04:29,760
and network access control to wireless networks

101
00:04:29,760 --> 00:04:32,190
by rectifying meaning of the weaknesses observed

102
00:04:32,190 --> 00:04:35,820
in the older and more vulnerable WPA implementation.

103
00:04:35,820 --> 00:04:39,930
While WPA2 replaced WPA's TKIP

104
00:04:39,930 --> 00:04:43,200
with the Advanced Encryption Standard or AES protocol,

105
00:04:43,200 --> 00:04:46,050
and it also began utilizing the CCMP

106
00:04:46,050 --> 00:04:48,480
as a more robust encryption mechanism,

107
00:04:48,480 --> 00:04:51,480
the real name for CCMP is a Counter Cipher Mode

108
00:04:51,480 --> 00:04:55,230
with Block Chaining Message Authentication Code Protocol,

109
00:04:55,230 --> 00:04:57,660
but most people simply refer to it as CCMP

110
00:04:57,660 --> 00:04:58,800
in the real world.

111
00:04:58,800 --> 00:05:00,510
By shifting to WPA2,

112
00:05:00,510 --> 00:05:02,730
we receive not only stronger encryption,

113
00:05:02,730 --> 00:05:04,830
but also new integrity checking feature

114
00:05:04,830 --> 00:05:08,040
called the Message Integrity Code or MIC.

115
00:05:08,040 --> 00:05:10,260
However, despite these advancements,

116
00:05:10,260 --> 00:05:12,930
WPA2 eventually showed vulnerabilities as well,

117
00:05:12,930 --> 00:05:15,930
such as with the KRACK attack in 2016, which demonstrated

118
00:05:15,930 --> 00:05:17,970
that even the most robust security protocols

119
00:05:17,970 --> 00:05:20,760
can become susceptible to threats over time.

120
00:05:20,760 --> 00:05:22,560
And this brings us to our more secure

121
00:05:22,560 --> 00:05:24,930
and most modern implementation of wireless security

122
00:05:24,930 --> 00:05:27,720
and encryption known as WPA3.

123
00:05:27,720 --> 00:05:32,010
WPA3 or Wi-Fi Protected Access 3 is the latest version,

124
00:05:32,010 --> 00:05:34,530
and it continues to use AES for encryption

125
00:05:34,530 --> 00:05:36,030
while adding new features,

126
00:05:36,030 --> 00:05:38,820
including the Simultaneous Authentication of Equals,

127
00:05:38,820 --> 00:05:42,150
Enhanced Open, updated cryptographic protocols,

128
00:05:42,150 --> 00:05:44,490
and the use of management protection frames.

129
00:05:44,490 --> 00:05:47,850
The Simultaneous Authentication of Equals or SAE

130
00:05:47,850 --> 00:05:50,520
provides a new key establishment protocol

131
00:05:50,520 --> 00:05:54,450
to replace the older pre-shared key method using WPA2

132
00:05:54,450 --> 00:05:56,220
to provide us with better protection

133
00:05:56,220 --> 00:05:58,620
against offline dictionary attacks.

134
00:05:58,620 --> 00:06:00,720
The Simultaneous Authentication of Equals

135
00:06:00,720 --> 00:06:03,120
replace the four-way handshake authentication

136
00:06:03,120 --> 00:06:06,210
and association mechanism of WPA with a protocol

137
00:06:06,210 --> 00:06:09,120
that is based on the Diffie-Hellman key agreement.

138
00:06:09,120 --> 00:06:11,760
This means that even if an attacker captures the data

139
00:06:11,760 --> 00:06:15,390
necessary to form the cryptographic handshake in WPA3,

140
00:06:15,390 --> 00:06:18,360
they still cannot use that data to perform an offline attack

141
00:06:18,360 --> 00:06:20,130
to guess the network password.

142
00:06:20,130 --> 00:06:22,350
WPA3 provides several improvements

143
00:06:22,350 --> 00:06:24,570
over the older WPA2 protocol,

144
00:06:24,570 --> 00:06:26,970
including offering more robust protections

145
00:06:26,970 --> 00:06:31,170
even if the user chooses a weak, simple, or short password.

146
00:06:31,170 --> 00:06:34,620
WPA3 also simplifies the process of configuring security

147
00:06:34,620 --> 00:06:38,670
for devices that have limited or no display interfaces.

148
00:06:38,670 --> 00:06:42,840
The second feature added to WPA3 is Enhanced Open.

149
00:06:42,840 --> 00:06:44,940
Enhanced Open, also known as

150
00:06:44,940 --> 00:06:47,560
Opportunistic Wireless Encryption or OWE

151
00:06:48,420 --> 00:06:51,360
presents a significant step forward in wireless security,

152
00:06:51,360 --> 00:06:52,440
particularly for networks

153
00:06:52,440 --> 00:06:54,900
that utilize the open authentication method.

154
00:06:54,900 --> 00:06:57,180
In traditional open Wi-Fi networks,

155
00:06:57,180 --> 00:06:59,460
data is sent over the air unencrypted,

156
00:06:59,460 --> 00:07:01,560
which makes it easier for eavesdroppers

157
00:07:01,560 --> 00:07:03,660
to capture your sensitive information

158
00:07:03,660 --> 00:07:05,820
while it's being transmitted over the network.

159
00:07:05,820 --> 00:07:08,250
Enhanced Open improves upon this

160
00:07:08,250 --> 00:07:10,350
by providing individualized data encryption

161
00:07:10,350 --> 00:07:12,930
between the user device and the Wi-Fi access point,

162
00:07:12,930 --> 00:07:14,610
even where there is no authentication,

163
00:07:14,610 --> 00:07:16,620
such as password protection being required

164
00:07:16,620 --> 00:07:17,850
to join the network.

165
00:07:17,850 --> 00:07:21,810
The Enhanced Open method enhances user privacy and security

166
00:07:21,810 --> 00:07:25,020
since it protects against passive eavesdropping attacks

167
00:07:25,020 --> 00:07:27,690
that are common in public Wi-Fi scenarios.

168
00:07:27,690 --> 00:07:31,410
While it doesn't offer a full-fledged security like WPA3,

169
00:07:31,410 --> 00:07:34,200
Enhanced Open helps to ensure that the connection

170
00:07:34,200 --> 00:07:37,290
between clients and access points are encrypted.

171
00:07:37,290 --> 00:07:40,410
Enhanced Open also provides a more secure connection

172
00:07:40,410 --> 00:07:43,530
than traditional open networks, so it is a valuable feature

173
00:07:43,530 --> 00:07:46,620
for network providers who offer public Wi-Fi services

174
00:07:46,620 --> 00:07:48,000
to their end users.

175
00:07:48,000 --> 00:07:50,700
The third feature we need to cover in WPA3

176
00:07:50,700 --> 00:07:53,150
is the use of updated cryptographic protocols.

177
00:07:53,150 --> 00:07:57,810
In WPA3, the older AES CCMP used in WPA2

178
00:07:57,810 --> 00:08:00,060
is replaced with a newer variant of AES

179
00:08:00,060 --> 00:08:04,830
known as the AES GCMP or Galois Counter Mode protocol.

180
00:08:04,830 --> 00:08:09,390
This protocol not only supports the 128-bit AES algorithm

181
00:08:09,390 --> 00:08:10,710
for your personal networks,

182
00:08:10,710 --> 00:08:14,820
but also supports a 192-bit AES for the use of enterprise

183
00:08:14,820 --> 00:08:18,210
or personal networks with the WPA3 protocol.

184
00:08:18,210 --> 00:08:21,930
The fourth and final feature of WPA3 we need to cover

185
00:08:21,930 --> 00:08:23,970
is the use of management frame protection.

186
00:08:23,970 --> 00:08:26,370
These management protection frames are required

187
00:08:26,370 --> 00:08:28,620
to be used in order to safeguard your network

188
00:08:28,620 --> 00:08:30,750
against key recovery attacks.

189
00:08:30,750 --> 00:08:33,120
This security mechanism ensures the integrity

190
00:08:33,120 --> 00:08:36,030
of network mentoring traffic by preventing eavesdropping,

191
00:08:36,030 --> 00:08:38,909
forging, or tempering with these type of frames,

192
00:08:38,909 --> 00:08:41,220
which are critical for the overall management

193
00:08:41,220 --> 00:08:43,559
and maintenance of wireless communications.

194
00:08:43,559 --> 00:08:47,070
In prior protocols, these frames were transmitted unsecured,

195
00:08:47,070 --> 00:08:49,830
leaving them vulnerable to various forms of cyber attacks,

196
00:08:49,830 --> 00:08:51,870
including the Nile service attacks.

197
00:08:51,870 --> 00:08:53,520
By enforcing their protection,

198
00:08:53,520 --> 00:08:57,630
WPA3 enhances network stability and user security,

199
00:08:57,630 --> 00:09:00,450
ensuring that attackers cannot disrupt the network

200
00:09:00,450 --> 00:09:02,130
by manipulating the traffic essential

201
00:09:02,130 --> 00:09:04,500
for maintaining wireless connections.

202
00:09:04,500 --> 00:09:06,570
This represents another layer of defense,

203
00:09:06,570 --> 00:09:07,710
fortifying the network,

204
00:09:07,710 --> 00:09:10,020
especially in dense complex environments

205
00:09:10,020 --> 00:09:12,330
where such attacks can be very disruptive.

206
00:09:12,330 --> 00:09:14,790
Another important wireless security setting to consider

207
00:09:14,790 --> 00:09:19,320
is the use of AAA protocols like RADIUS or TACACS+.

208
00:09:19,320 --> 00:09:22,320
These protocols are pivotal in managing network security

209
00:09:22,320 --> 00:09:25,650
by facilitating the centralization of user authentication

210
00:09:25,650 --> 00:09:28,290
to ensure that only authorized individuals can access

211
00:09:28,290 --> 00:09:29,790
the network resources.

212
00:09:29,790 --> 00:09:31,590
Implementing such protocols is fundamental

213
00:09:31,590 --> 00:09:33,690
in creating a robust security infrastructure,

214
00:09:33,690 --> 00:09:34,950
especially in environments

215
00:09:34,950 --> 00:09:37,350
where sensitive data is transmitted over networks

216
00:09:37,350 --> 00:09:40,320
and stringent compliance requirements is a must.

217
00:09:40,320 --> 00:09:44,280
RADIUS or the Remote Authentication Dial-In User Service

218
00:09:44,280 --> 00:09:45,900
serves as a networking protocol

219
00:09:45,900 --> 00:09:47,940
that operates on a client server model

220
00:09:47,940 --> 00:09:50,190
that provides comprehensive authentication,

221
00:09:50,190 --> 00:09:53,790
authorization, and accounting services or AAA services

222
00:09:53,790 --> 00:09:55,620
to your network's users.

223
00:09:55,620 --> 00:09:58,620
RADIUS is widely used in an enterprise environment

224
00:09:58,620 --> 00:10:01,410
to enable secure access to your network resources

225
00:10:01,410 --> 00:10:04,080
by authenticating users through a centralized server

226
00:10:04,080 --> 00:10:05,850
that can validate users identities

227
00:10:05,850 --> 00:10:09,660
and grant appropriate access based on predefined policies.

228
00:10:09,660 --> 00:10:12,450
Additionally, RADIUS facilitates the monitoring

229
00:10:12,450 --> 00:10:14,910
of user activity to ensure that accountability

230
00:10:14,910 --> 00:10:18,000
and the enforcement of security policies is occurring.

231
00:10:18,000 --> 00:10:20,280
On the other hand, we have TACACS+

232
00:10:20,280 --> 00:10:24,150
or Terminal Access Controller Access-Control System Plus

233
00:10:24,150 --> 00:10:26,100
is another powerful protocol designed

234
00:10:26,100 --> 00:10:29,190
to provide a similar range of AAA services.

235
00:10:29,190 --> 00:10:32,340
Unlike RADIUS, TACACS+ separates the functions

236
00:10:32,340 --> 00:10:35,070
of authentication, authorization, and accounting

237
00:10:35,070 --> 00:10:38,550
to allow for a more granular control over these processes.

238
00:10:38,550 --> 00:10:41,520
This level of separation permits the distinct handling

239
00:10:41,520 --> 00:10:44,100
of each component across different service.

240
00:10:44,100 --> 00:10:47,790
Also, TACACS+ employs the transmission control protocol

241
00:10:47,790 --> 00:10:49,980
while encrypting the entire authentication process

242
00:10:49,980 --> 00:10:53,670
to enhance its security compared to the older AAA protocols.

243
00:10:53,670 --> 00:10:56,490
The final wireless security settings that we need to cover

244
00:10:56,490 --> 00:10:58,470
are the various authentication protocols

245
00:10:58,470 --> 00:11:00,660
you may come across in the real world.

246
00:11:00,660 --> 00:11:02,520
Authentication protocols are used

247
00:11:02,520 --> 00:11:04,833
to verify the identity of users trying to access a network,

248
00:11:04,833 --> 00:11:08,010
and there are a crucial aspect of network security

249
00:11:08,010 --> 00:11:09,960
that ensures that only authorized individuals

250
00:11:09,960 --> 00:11:11,550
can access the network.

251
00:11:11,550 --> 00:11:15,191
Some examples of authentication protocols include EAP,

252
00:11:15,191 --> 00:11:19,350
PEAP, EAP-TTLS, and EAP-FAST.

253
00:11:19,350 --> 00:11:22,860
EAP or the Extensible Authentication Protocol

254
00:11:22,860 --> 00:11:24,180
is an authentication framework

255
00:11:24,180 --> 00:11:26,670
that supports multiple authentication methods.

256
00:11:26,670 --> 00:11:28,740
EAP provides common functions

257
00:11:28,740 --> 00:11:30,777
and negotiation of authentication protocols

258
00:11:30,777 --> 00:11:32,790
and is used in wireless networks

259
00:11:32,790 --> 00:11:34,440
and point-to-point connections.

260
00:11:34,440 --> 00:11:37,380
While EAP is not a specific protocol by itself,

261
00:11:37,380 --> 00:11:39,330
it is used to define the message formats

262
00:11:39,330 --> 00:11:41,310
and the overall process that will be used

263
00:11:41,310 --> 00:11:44,550
by each specific EAP authentication method.

264
00:11:44,550 --> 00:11:47,730
PEAP or the Protected Extensible Authentication Protocol

265
00:11:47,730 --> 00:11:50,280
is an authentication protocol that encapsulates EAP

266
00:11:50,280 --> 00:11:51,930
within a potentially encrypted

267
00:11:51,930 --> 00:11:56,310
and authenticated transport layer security or TLS tunnel.

268
00:11:56,310 --> 00:11:58,950
PEAP was jointly developed by Cisco Systems,

269
00:11:58,950 --> 00:12:01,110
Microsoft, and RSA Security

270
00:12:01,110 --> 00:12:04,230
as a method to transport authentication data securely

271
00:12:04,230 --> 00:12:07,650
via 802.11 Wi-Fi networks.

272
00:12:07,650 --> 00:12:11,400
EAP-TTLS or Extensible Authentication Protocol

273
00:12:11,400 --> 00:12:13,500
Tunneled Transport Layer Security

274
00:12:13,500 --> 00:12:16,710
is an authentication protocol that extends TLS support

275
00:12:16,710 --> 00:12:18,480
across multiple platforms.

276
00:12:18,480 --> 00:12:22,200
The main difference between PEAP and EAP-TTLS

277
00:12:22,200 --> 00:12:25,500
is that EAP-TTLS requires a certificate

278
00:12:25,500 --> 00:12:26,910
only on the service side,

279
00:12:26,910 --> 00:12:30,420
while PEAP requires dual-sided certificate authentication

280
00:12:30,420 --> 00:12:33,000
to occur on both server and the client side

281
00:12:33,000 --> 00:12:34,320
of the connection.

282
00:12:34,320 --> 00:12:35,940
With EAP-TTLS,

283
00:12:35,940 --> 00:12:38,280
the protocol will encapsulate a second protocol

284
00:12:38,280 --> 00:12:39,990
for authentication that is carried

285
00:12:39,990 --> 00:12:42,930
inside the TLS encryption tunnel.

286
00:12:42,930 --> 00:12:46,140
EAP-FAST, or the Extensible Authentication Protocol

287
00:12:46,140 --> 00:12:48,780
Flexible Authentication via Secure Tunneling

288
00:12:48,780 --> 00:12:51,600
is an authentication protocol developed by Cisco Systems

289
00:12:51,600 --> 00:12:54,000
that allows users to re-authenticate securely

290
00:12:54,000 --> 00:12:55,590
when roaming within a network

291
00:12:55,590 --> 00:12:57,900
without having to perform full authentication

292
00:12:57,900 --> 00:12:59,100
every single time.

293
00:12:59,100 --> 00:13:01,590
EAP-FAST uses protected access credentials

294
00:13:01,590 --> 00:13:03,360
to establish a TLS tunnel

295
00:13:03,360 --> 00:13:05,430
in which client credentials are verified.

296
00:13:05,430 --> 00:13:07,620
EAP-FAST was created as a replacement

297
00:13:07,620 --> 00:13:10,050
for Lightweight EAP called LEAP,

298
00:13:10,050 --> 00:13:11,910
which had several security vulnerabilities

299
00:13:11,910 --> 00:13:13,080
associated with it.

300
00:13:13,080 --> 00:13:15,540
Each of these Extensible Authentication Protocols

301
00:13:15,540 --> 00:13:17,460
has its own strengths and weaknesses,

302
00:13:17,460 --> 00:13:18,780
and the choice between them

303
00:13:18,780 --> 00:13:20,877
depends on the specific requirements of the network

304
00:13:20,877 --> 00:13:22,680
and resources available.

305
00:13:22,680 --> 00:13:25,590
So remember, as wireless networks continue

306
00:13:25,590 --> 00:13:28,680
to expand the popularity, it is important that we learn

307
00:13:28,680 --> 00:13:30,660
the best ways to secure those networks,

308
00:13:30,660 --> 00:13:34,980
including using WPA3 or other forms of wireless encryption,

309
00:13:34,980 --> 00:13:38,250
AAA and RADIUS for creating additional layers

310
00:13:38,250 --> 00:13:40,200
of authentication on the network,

311
00:13:40,200 --> 00:13:43,170
and the use of the Extensible Authentication Protocol

312
00:13:43,170 --> 00:13:44,882
known as EAP.

313
00:13:44,882 --> 00:13:47,580
WPA3 is the latest and most secure version

314
00:13:47,580 --> 00:13:51,330
of the Wi-Fi Protected Access or WPA protocol,

315
00:13:51,330 --> 00:13:53,100
and it is used to provide us

316
00:13:53,100 --> 00:13:54,990
with the most robust protections,

317
00:13:54,990 --> 00:13:57,060
even when users choose passwords that fall short

318
00:13:57,060 --> 00:13:59,760
of typical complexity recommendations.

319
00:13:59,760 --> 00:14:01,680
RADIUS is a networking protocol

320
00:14:01,680 --> 00:14:04,500
that provides centralized authentication, authorization,

321
00:14:04,500 --> 00:14:06,810
and accounting management for users who connect

322
00:14:06,810 --> 00:14:08,400
and use a network service.

323
00:14:08,400 --> 00:14:10,620
While TACACS+ is a separate protocol

324
00:14:10,620 --> 00:14:13,710
that allows for more granular control over authentication,

325
00:14:13,710 --> 00:14:15,150
authorization, and accounting

326
00:14:15,150 --> 00:14:16,860
that offers some advanced security

327
00:14:16,860 --> 00:14:20,310
by encrypting the entire authentication process.

328
00:14:20,310 --> 00:14:23,040
EAP or the Extensible Authentication Protocol

329
00:14:23,040 --> 00:14:25,080
is a universal authentication framework

330
00:14:25,080 --> 00:14:27,420
used to support various authentication methods

331
00:14:27,420 --> 00:14:31,050
such as token cards, smart cards, certificates, and others,

332
00:14:31,050 --> 00:14:33,810
and wireless networks, and point-to-point connections.

333
00:14:33,810 --> 00:14:36,840
By embracing these advanced protocols and methodologies,

334
00:14:36,840 --> 00:14:38,880
we can better empower our wireless networks

335
00:14:38,880 --> 00:14:40,740
with a more secure infrastructure

336
00:14:40,740 --> 00:14:43,230
that is designed to withstand modern threat actors

337
00:14:43,230 --> 00:14:45,660
by ensuring that both user authenticity

338
00:14:45,660 --> 00:14:48,933
and data integrity are protected in our wireless networks.

