CAS-003 · Question #197
Three companies want to allow their employees to seamlessly connect to each other's wireless corporate networks while keeping one consistent wireless client configuration. Each company wants to…
The correct answer is A. The three companies should agree on a single SSID and configure a hierarchical RADIUS. The requirement is that employees authenticate against their home company's infrastructure when visiting the other two companies' networks, using a consistent 802.1x EAP-PEAP-MSCHAPv2 configuration. A hierarchical RADIUS proxy federation achieves this: each company runs its own…
Question
Three companies want to allow their employees to seamlessly connect to each other's wireless corporate networks while keeping one consistent wireless client configuration. Each company wants to maintain its own authentication infrastructure and wants to ensure that an employee who is visiting the other two companies is authenticated by the home office when connecting to the other companies' wireless network. All three companies have agreed to standardize on 802.1x EAP-PEAP-MSCHAPv2 for client configuration. Which of the following should the three companies implement?
Options
- AThe three companies should agree on a single SSID and configure a hierarchical RADIUS
- BThe three companies should implement federated authentication through Shibboleth
- CThe three companies should implement a central portal-based single sign-on and agree to
- DAll three companies should use the same wireless vendor to facilitate the use of a shared
How the community answered
(33 responses)- A48% (16)
- B9% (3)
- C12% (4)
- D30% (10)
Explanation
The requirement is that employees authenticate against their home company's infrastructure when visiting the other two companies' networks, using a consistent 802.1x EAP-PEAP-MSCHAPv2 configuration. A hierarchical RADIUS proxy federation achieves this: each company runs its own RADIUS server, and when a visitor connects, the local RADIUS server recognizes that the user's realm (e.g., the domain suffix) belongs to a different company and proxies the authentication request up the hierarchy to that company's RADIUS server. The home RADIUS server authenticates the user and returns the result. A shared SSID ensures the client configuration is identical everywhere. Shibboleth (option B) is web-based SSO, not suitable for 802.1x. Portal-based SSO (option C) doesn't integrate with 802.1x. Shared vendor hardware (option D) doesn't solve the authentication federation problem.
Topics
Community Discussion
No community discussion yet for this question.