User's Manual

43
Chapter4
|
WirelessSettings
RadioSettings
Security Settings
MethodSetsthewirelesssecuritymethodforeachVAP,including
associationmode,encryption,andauthentication.(Default:NoSecurity)
NoSecurity The VAP broadcasts a beaconsignal includingthe
configuredSSID.WirelessclientswithanSSIDsettingof“any”canreadthe
SSIDfromthebeaconandautomaticallysettheirSSIDtoallowimmediate
connection.
WEP Open System The VAP broadcastsa beaconsignalincluding the
configuredSSID.WirelessclientswithanSSIDsettingof“any”canreadthe
SSIDfromthebeaconandautomaticallysettheirSSIDtoallowimmediate
connection.
KeyWEPisusedtoencryptdatatransmittedbetweenwireless
clientsandtheVAP.WEPusesstaticsharedkeys(fixedlength
hexadecimaloralphanumericstrings)thataremanuallydistributedto
allclientsthatwanttousethenetwork.
WEPisthesecurityprotocolinitiallyspecifiedintheIEEE802.11
standardforwirelesscommunications.Unfortunately,WEPhasbeen
foundtobeseriouslyflawedandcannotberecommendedforahigh
levelofnetworksecurity.Formorerobustwirelesssecurity,theaccess
pointprovidesWiFiProtectedAccess(WPA)andWPA2forimproved
dataencryptionanduserauthentication.
BesurethattheWEPsharedkeysarethesameforeachclientinthe
wirelessnetwork.Allclientssharethesamekeys,whichareusedfor
data encryption.
For64bitWEP,stringlengthmustbe5ASCIIcharacters(lettersand
numbers)or10hexadecimaldigits.For128bitWEP,stringlengthmust
be13ASCIIcharacters(lettersandnumbers)or26hexadecimaldigits.
WPAPSKForenterprisedeployment,WPArequiresaRADIUS
authenticationservertobeconfiguredonthewirednetwork.However,for
smallofficenetworksthatmaynothavetheresourcestoconfigureand
maintainaRADIUSserver,WPAprovidesasimpleoperatingmodethatuses
justapresharedpasswordfornetworkaccess.ThePreSharedKeymode
usesacommonpasswordforuserauthenticationthatismanuallyentered
ontheaccesspointandallwirelessclients.ThePSKmodeusesthesame
TKIPpacketencryptionandkeymanagementasWPAintheenterprise,
providingarobustandmanageablealternativeforsmallnetworks.
Encryption
Dataencryptionusesoneof thefollowingmethods:
CCMP(AES)AESCCMPis usedasth e multicastencryption
cipher.AESCCMPisthestanda rdencryptioncipherrequiredfor
WPA2.(Thisisthedefaultsetting.)
TKIP
TKIPisusedasthemulticastencryptioncipher.