Cisco LEAP Authentication

The authentication can start in one of two ways: by client initiation with the Start message or by access point initiation with the Request/Identity message. In either case, the client responds to the access point with a user name. The access point encapsulates that response in a RADIUS Access-Request message and forwards it to the RADIUS server. The RADIUS server then begins the challenge response process with the client. After the challenges are met with correct authentication, a Success message is sent to the access point, indicating that the client has been authenticated.

The client needs to validate that the access point and RADIUS server are truly what they say they are. This process is the LEAP mutual authentication function. The client sends a challenge message to the access point to forward to the RADIUS server. The RADIUS server must then correctly respond to the challenge for the client to validate the network and then associate. Upon successful authentication, a pairwise master key (PMK) is generated on both the client and the RADIUS server. The RADIUS server forwards the PMK for installation in the access point for that specific client. The access point and the client perform the four-way handshake.

6-48 Optimizing Converged Cisco Networks (ONT) v1.0 © 2006 Cisco Systems, Inc.

Continue reading here: And WPA Authentication and Key Management Overview

Was this article helpful?

0 0