Appendix A:Glossary 715Nortel WLAN—Security Switch 2300 Series Configuration GuideEAP Extensible Authentication Protocol. A general point-to-point protocol that supports multipleauthentication mechanisms. Defined in RFC 2284, EAP has been adopted by IEEE 802.1X in an encapsulatedform for carrying authentication messages in a standard message exchange between a user (client) and anauthenticator. The encapsulated EAP, also known as EAP over LAN (EAPoL) and EAP over Wireless (EAPoW),enables the authenticator’s server to authenticate the client with an authentication protocol agreed upon byboth parties. See also EAP type.EAPoL EAP over LAN. An encapsulated form of the Extensible Authentication Protocol (EAP), defined inthe IEEE 802.1X standard, that allows EAP messages to be carried directly by a LAN media access control(MAC) service between a wireless client (or supplicant) and an authenticator. EAPoL is also known as EAPover Wireless (EAPoW). See also EAP.EAP over LAN See EAPoL.EAP over Wireless See EAPoL.EAPoW See EAPoL.EAP-TLS Extensible Authentication Protocol with Transport Layer Security. An EAP subprotocol for802.1X authentication. EAP-TLS supports mutual authentication and uses digital certificates to fulfill themutual challenge. When a user (client) requests access, the authentication server responds with a servercertificate. The client replies with its own certificate and also validates the server certificate. From thecertificate values, the EAP-TLS algorithm can derive session encryption keys. After validating the clientcertification, the authentication server sends the session encryption keys for a particular session to the client.Compare PEAP.EAP type A specific Extensible Authentication Protocol (EAP) authentication mechanism. Both thewireless client (or supplicant) and the authenticator must support the same EAP type for successfulauthentication to occur. EAP types supported in a Nortel WLAN 2300 system wireless LAN (WLAN) includeEAP-MD5, EAP-TLS, PEAP-TLS, PEAP-MS-CHAP, and Tunneled Transport Layer Security (TTLS). Seealso MD5; MS-CHAP-V2; PEAP; TLS; TTLS.EAP with Transport Layer Security See EAP-TLS.enabled access Permission to use all WLAN Security Switch 2300 Series (WSS Software)command-line interface (CLI) commands required for configuration and troubleshooting. Enabled accessrequires a separate enable password. Compare restricted access.encryption Any procedure used in cryptography to translate data into a form that can be read by only itsintended receiver. An encrypted signal must be decrypted to be read. See also cryptography.ESS Extended service set. A logical connection of multiple basic service sets (BSSs) connected to the samenetwork. Roaming within an ESS is guaranteed by the Nortel WLAN 2300 system.Ethernet II The original Ethernet specification produced by Digital, Intel, and Xerox (DIX) that served asthe basis of the IEEE 802.3 standard.ETSI European Telecommunications Standards Institute. A nonprofit organization that establishestelecommunications and radio standards for Europe.European Telecommunications Standards Institute See ETSI.extended service set See ESS.