EAP-TTLS (Tunneled Transport Layer Security) supports flexible inner authentication methods including:
MS-CHAPv2
EAP-GTC (Generic Token Card)
EAP-TLS (in some configurations)
This versatility allows EAP-TTLS to be used with a wide range of back-end authentication systems, while only requiring a server-side certificate.
Incorrect:
A. H-REAP (now FlexConnect) is a Cisco AP deployment mode, not an EAP type.
B. EAP-GTC is a simple authentication method and not a tunnel or container for others.
D. PEAP typically supports MS-CHAPv2 but not EAP-GTC or EAP-TLS as inner methods.
E. LEAP uses MS-CHAPv1 and is considered deprecated and insecure.
[References:, , CWSP-208 Study Guide, Chapter 4 (EAP Methods), , , ]
Submit