PSK ืคืจื˜ื™ (ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ) - ืชื›ื•ื ื•ืช ื•ื™ื›ื•ืœื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ExtremeCloud IQ

WPA3 ื›ื‘ืจ ืื•ืžืฅ, ื•ืžืื– ื™ื•ืœื™ 2020 ื”ื•ื ื—ื•ื‘ื” ืขื‘ื•ืจ ืžื›ืฉื™ืจื™ื ืฉืื•ืฉืจื• ืขืœ ื™ื“ื™ WiFi-Alliance, WPA2 ืœื ื‘ื•ื˜ืœ ื•ืœื ื”ื•ืœืš ืœืขืฉื•ืช ื–ืืช. ื™ื—ื“ ืขื ื–ืืช, ื’ื WPA2 ื•ื’ื WPA3 ืžืกืคืงื™ื ื”ืคืขืœื” ื‘ืžืฆื‘ื™ PSK ื•-Enterprise, ืืš ืื ื• ืžืฆื™ืขื™ื ืœืฉืงื•ืœ ืืช ื˜ื›ื ื•ืœื•ื’ื™ื™ืช PSK ืคืจื˜ื™ืช ื‘ืžืืžืจ ืฉืœื ื•, ื›ืžื• ื’ื ืืช ื”ื™ืชืจื•ื ื•ืช ืฉื ื™ืชืŸ ืœื”ืฉื™ื’ ื‘ืขื–ืจืชื”.

PSK ืคืจื˜ื™ (ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ) - ืชื›ื•ื ื•ืช ื•ื™ื›ื•ืœื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ExtremeCloud IQ

ื‘ืขื™ื•ืช WPA2-Personal ื™ื“ื•ืขื•ืช ื›ื‘ืจ ื–ืžืŸ ืจื‘ ื•ื‘ืื•ืคืŸ ื›ืœืœื™, ื›ื‘ืจ ืชื•ืงื ื• (Priority Management Frames, ืชื™ืงื•ื ื™ื ืœืคื’ื™ืขื•ืช KRACK ื•ื›ื•'). ื”ื—ื™ืกืจื•ืŸ ื”ืขื™ืงืจื™ ืฉื ื•ืชืจ ื‘-WPA2 ื‘ืืžืฆืขื•ืช PSK ื”ื•ื ืฉืกื™ืกืžืื•ืช ื—ืœืฉื•ืช ืงืœื•ืช ืœืžื“ื™ ืœืคื™ืฆื•ื— ื‘ื”ืชืงืคืช ืžื™ืœื•ืŸ. ื‘ืžืงืจื” ืฉืœ ืคืฉืจื” ื•ื”ื—ืœืคืช ื”ืกื™ืกืžื” ืœื—ื“ืฉื”, ื™ื”ื™ื” ืฆื•ืจืš ืœื”ื’ื“ื™ืจ ืžื—ื“ืฉ ืืช ื›ืœ ื”ืžื›ืฉื™ืจื™ื ื”ืžื—ื•ื‘ืจื™ื (ื•ื ืงื•ื“ื•ืช ื”ื’ื™ืฉื”), ืžื” ืฉื™ื›ื•ืœ ืœื”ื™ื•ืช ืชื”ืœื™ืš ืฉืœื•ืงื— ื–ืžืŸ ืจื‘ (ื›ื“ื™ ืœืคืชื•ืจ ืืช ื‘ืขื™ื™ืช "ื”ืกื™ืกืžื” ื”ื—ืœืฉื”", WiFi- Alliance ืžืžืœื™ืฆื” ืœื”ืฉืชืžืฉ ื‘ืกื™ืกืžืื•ืช ืฉืœ 20 ืชื•ื•ื™ื ืœืคื—ื•ืช).

ื‘ืขื™ื” ื ื•ืกืคืช ืฉืœืขื™ืชื™ื ืœื ื ื™ืชื ืช ืœืคืชืจื•ืŸ ื‘ืืžืฆืขื•ืช WPA2-Personal ื”ื™ื ื”ืงืฆืืช ืคืจื•ืคื™ืœื™ื ืฉื•ื ื™ื (Vlan, QoS, Firewall...) ืœืงื‘ื•ืฆื•ืช ืฉืœ ืžื›ืฉื™ืจื™ื ื”ืžื—ื•ื‘ืจื™ื ืœืื•ืชื• SSID.

ื‘ืขื–ืจืช WPA2-Enterprise ื ื™ืชืŸ ืœืคืชื•ืจ ืืช ื›ืœ ื”ื‘ืขื™ื•ืช ืฉืชื•ืืจื• ืœืขื™ืœ, ืืš ื”ืžื—ื™ืจ ืœื›ืš ื™ื”ื™ื”:

  • ื”ืฆื•ืจืš ืœื”ื—ื–ื™ืง ืื• ืœืคืจื•ืก PKI (ืชืฉืชื™ืช ืžืคืชื— ืฆื™ื‘ื•ืจื™) ื•ืื™ืฉื•ืจื™ ืื‘ื˜ื—ื”;
  • ื”ื”ืชืงื ื” ืขืฉื•ื™ื” ืœื”ื™ื•ืช ืงืฉื”;
  • ืคืชืจื•ืŸ ื‘ืขื™ื•ืช ืขืฉื•ื™ ืœื”ื™ื•ืช ืงืฉื”;
  • ืœื ื”ืคืชืจื•ืŸ ื”ื˜ื•ื‘ ื‘ื™ื•ืชืจ ืขื‘ื•ืจ ืžื›ืฉื™ืจื™ IoT ืื• ื’ื™ืฉื” ืœืื•ืจื—ื™ื.

ืคืชืจื•ืŸ ืงื™ืฆื•ื ื™ ื™ื•ืชืจ ืœื‘ืขื™ื•ืช ืฉืœ WPA2-Personal ื”ื•ื ื”ืžืขื‘ืจ ืœ-WPA3, ืฉื”ืฉื™ืคื•ืจ ื”ืขื™ืงืจื™ ื‘ื• ื”ื•ื ื”ืฉื™ืžื•ืฉ ื‘-SAE (Simultaneous Authentication of Equals) ื•ื‘-PSK ืกื˜ื˜ื™. WPA3-Personal ืคื•ืชืจ ืืช ื‘ืขื™ื™ืช "ื”ืชืงืคืช ื”ืžื™ืœื•ืŸ", ืืš ืื™ื ื• ืžืกืคืง ื–ื™ื”ื•ื™ ื™ื™ื—ื•ื“ื™ ื‘ืžื”ืœืš ื”ืื™ืžื•ืช ื•ื‘ื”ืชืื ืœื›ืš ื™ื›ื•ืœืช ืœื”ืงืฆื•ืช ืคืจื•ืคื™ืœื™ื (ืฉื›ืŸ ื”ื•ื ืขื“ื™ื™ืŸ ืžืฉืชืžืฉ ื‘ืกื™ืกืžื” ืกื˜ื˜ื™ืช ื ืคื•ืฆื”).

PSK ืคืจื˜ื™ (ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ) - ืชื›ื•ื ื•ืช ื•ื™ื›ื•ืœื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ExtremeCloud IQ
ื—ืฉื•ื‘ ื’ื ืœื–ื›ื•ืจ ื›ื™ ืœืžืขืœื” ืž-95% ืžื”ืœืงื•ื—ื•ืช ื”ืงื™ื™ืžื™ื ืื™ื ื ืชื•ืžื›ื™ื ื›ื™ื•ื ื‘-WPA3 ื•-SAE, ื•-WPA2 ืžืžืฉื™ืš ืœืขื‘ื•ื“ ื‘ื”ืฆืœื—ื” ืขืœ ืžื™ืœื™ืืจื“ื™ ื”ืžื›ืฉื™ืจื™ื ืฉื›ื‘ืจ ืฉื•ื—ืจืจื•.

ืขืœ ืžื ืช ืœืงื‘ืœ ืคืชืจื•ืŸ ืœื‘ืขื™ื•ืช ื”ืงื™ื™ืžื•ืช, ืื• ื”ืคื•ื˜ื ืฆื™ืืœื™ื•ืช ื”ืžืชื•ืืจื•ืช ืœืขื™ืœ, ืคื™ืชื—ื” ืืงืกื˜ืจื™ื ื ื˜ื•ื•ืจืงืก ืืช ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ื”-Private Pre-Shared Key (PPSK). PPSK ืชื•ืื ืœื›ืœ ืœืงื•ื— Wi-Fi ื”ืชื•ืžืš ื‘-WPA2-PSK ื•ืžืืคืฉืจ ืœืš ืœื”ืฉื™ื’ ืจืžืช ืื‘ื˜ื—ื” ื“ื•ืžื” ืœื–ื• ื”ืžื•ืฉื’ืช ื‘ืืžืฆืขื•ืช WPA2-Enterprise, ืœืœื ืฆื•ืจืš ื‘ื‘ื ื™ื™ืช ืชืฉืชื™ืช 802.1X/EAP. PSK ืคืจื˜ื™ ื”ื•ื ื‘ืขืฆื WPA2-PSK, ืื‘ืœ ืœื›ืœ ืžืฉืชืžืฉ (ืื• ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื) ื™ื›ื•ืœ ืœื”ื™ื•ืช ืกื™ืกืžื” ืžืฉืœื”ื ืฉื ื•ืฆืจื” ื‘ืื•ืคืŸ ื“ื™ื ืžื™. ื ื™ื”ื•ืœ PPSK ืื™ื ื• ืฉื•ื ื” ืžื ื™ื”ื•ืœ PSK ืฉื›ืŸ ื”ืชื”ืœื™ืš ื›ื•ืœื• ืื•ื˜ื•ืžื˜ื™. ื ื™ืชืŸ ืœืื—ืกืŸ ืืช ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ ื”ืžืคืชื— ื‘ืื•ืคืŸ ืžืงื•ืžื™ ื‘ื ืงื•ื“ื•ืช ื’ื™ืฉื” ืื• ื‘ืขื ืŸ.

PSK ืคืจื˜ื™ (ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ) - ืชื›ื•ื ื•ืช ื•ื™ื›ื•ืœื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ExtremeCloud IQ
ื ื™ืชืŸ ืœื”ืคื™ืง ืกื™ืกืžืื•ืช ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘ืฆื•ืจื” ื’ืžื™ืฉื” ืืช ืื•ืจืš/ื—ื•ื–ืงืŸ, ืชืงื•ืคื” ืื• ืชืืจื™ืš ืชืคื•ื’ื”, ืฉื™ื˜ืช ืžืฉืœื•ื— ืœืžืฉืชืžืฉ (ื‘ืžื™ื™ืœ ืื• ื‘-SMS):

PSK ืคืจื˜ื™ (ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ) - ืชื›ื•ื ื•ืช ื•ื™ื›ื•ืœื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ExtremeCloud IQ
PSK ืคืจื˜ื™ (ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ) - ืชื›ื•ื ื•ืช ื•ื™ื›ื•ืœื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ExtremeCloud IQ
ืืชื” ื™ื›ื•ืœ ื’ื ืœื”ื’ื“ื™ืจ ืืช ื”ืžืกืคืจ ื”ืžืงืกื™ืžืœื™ ืฉืœ ืœืงื•ื—ื•ืช ืฉื™ื›ื•ืœื™ื ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช PPSK ืื—ื“, ืื• ืืคื™ืœื• ืœื”ื’ื“ื™ืจ "MAC-binding" ืขื‘ื•ืจ ื”ืชืงื ื™ื ืžื—ื•ื‘ืจื™ื. ื‘ืคืงื•ื“ืช ืžื ื”ืœ ื”ืจืฉืช, ื ื™ืชืŸ ืœื‘ื˜ืœ ื‘ืงืœื•ืช ื›ืœ ืžืคืชื—, ื•ื”ื’ื™ืฉื” ืœืจืฉืช ืชื™ืฉืœืœ ืœืœื ืฆื•ืจืš ื‘ื”ื’ื“ืจื” ืžื—ื“ืฉ ืฉืœ ื›ืœ ืฉืืจ ื”ืžื›ืฉื™ืจื™ื. ืื ื”ืœืงื•ื— ืžื—ื•ื‘ืจ ื›ืืฉืจ ื”ืžืคืชื— ื ืฉืœืœ, ื ืงื•ื“ืช ื”ื’ื™ืฉื” ืชื ืชืง ืื•ืชื• ืื•ื˜ื•ืžื˜ื™ืช ืžื”ืจืฉืช.

ืžื”ื™ืชืจื•ื ื•ืช ื”ืขื™ืงืจื™ื™ื ืฉืœ PPSK, ื ืฆื™ื™ืŸ:

  • ืงืœื•ืช ืฉื™ืžื•ืฉ ืขื ืจืžืช ืื‘ื˜ื—ื” ื’ื‘ื•ื”ื”;
  • ื”ืจื—ืงืช ื”ืชืงืคืช ืžื™ืœื•ืŸ ื ืคืชืจืช ื‘ืืžืฆืขื•ืช ืกื™ืกืžืื•ืช ืืจื•ื›ื•ืช ื•ื—ื–ืงื•ืช ืฉ-ExtremeCloudIQ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ื•ืœื”ืคื™ืฅ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™;
  • ื”ื™ื›ื•ืœืช ืœื”ืงืฆื•ืช ืคืจื•ืคื™ืœื™ ืื‘ื˜ื—ื” ืฉื•ื ื™ื ืœืžื›ืฉื™ืจื™ื ืฉื•ื ื™ื ื”ืžื—ื•ื‘ืจื™ื ืœืื•ืชื• SSID;
  • ื ื”ื“ืจ ืขื‘ื•ืจ ื’ื™ืฉื” ืžืื•ื‘ื˜ื—ืช ืœืื•ืจื—ื™ื;
  • ืžืขื•ืœื” ืœื’ื™ืฉื” ืžืื•ื‘ื˜ื—ืช ื›ืืฉืจ ืžื›ืฉื™ืจื™ื ืื™ื ื ืชื•ืžื›ื™ื ื‘-802.1X/EAP (ืกื•ืจืงื™ื ื›ืฃ ื™ื“ ืื• ื”ืชืงื ื™ IoT/VoWiFi);
  • ื”ืฉืชืžืฉื• ื‘ื”ืฆืœื—ื” ื•ื”ืฉืชืคืจื• ื‘ืžืฉืš ืœืžืขืœื” ืž-10 ืฉื ื™ื.

ืื ื™ืฉ ืœืš ืฉืืœื•ืช ืื• ืฉืืœื•ืช, ืืชื” ืชืžื™ื“ ื™ื›ื•ืœ ืœืฉืื•ืœ ืืช ืฆื•ื•ืช ืžืฉืจื“ื ื• - [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ].

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”