User's Manual
–
43
–
Chapter4
|
WirelessSettings
RadioSettings
Security Settings
◆
Method—SetsthewirelesssecuritymethodforeachVAP,including
associationmode,encryption,andauthentication.(Default:NoSecurity)
■
NoSecurity — The VAP broadcasts a beaconsignal includingthe
configuredSSID.WirelessclientswithanSSIDsettingof“any”canreadthe
SSIDfromthebeaconandautomaticallysettheirSSIDtoallowimmediate
connection.
■
WEP Open System — The VAP broadcastsa beaconsignalincluding the
configuredSSID.WirelessclientswithanSSIDsettingof“any”canreadthe
SSIDfromthebeaconandautomaticallysettheirSSIDtoallowimmediate
connection.
■
Key—WEPisusedtoencryptdatatransmittedbetweenwireless
clientsandtheVAP.WEPusesstaticsharedkeys(fixed‐length
hexadecimaloralphanumericstrings)thataremanuallydistributedto
allclientsthatwanttousethenetwork.
WEPisthesecurityprotocolinitiallyspecifiedintheIEEE802.11
standardforwirelesscommunications.Unfortunately,WEPhasbeen
foundtobeseriouslyflawedandcannotberecommendedforahigh
levelofnetworksecurity.Formorerobustwirelesssecurity,theaccess
pointprovidesWi‐FiProtectedAccess(WPA)andWPA2forimproved
dataencryptionanduserauthentication.
BesurethattheWEPsharedkeysarethesameforeachclientinthe
wirelessnetwork.Allclientssharethesamekeys,whichareusedfor
data encryption.
For64‐bitWEP,stringlengthmustbe5ASCIIcharacters(lettersand
numbers)or10hexadecimaldigits.For128‐bitWEP,stringlengthmust
be13ASCIIcharacters(lettersandnumbers)or26hexadecimaldigits.
■
WPA‐PSK—Forenterprisedeployment,WPArequiresaRADIUS
authenticationservertobeconfiguredonthewirednetwork.However,for
smallofficenetworksthatmaynothavetheresourcestoconfigureand
maintainaRADIUSserver,WPAprovidesasimpleoperatingmodethatuses
justapre‐sharedpasswordfornetworkaccess.ThePre‐SharedKeymode
usesacommonpasswordforuserauthenticationthatismanuallyentered
ontheaccesspointandallwirelessclients.ThePSKmodeusesthesame
TKIPpacketencryptionandkeymanagementasWPAintheenterprise,
providingarobustandmanageablealternativeforsmallnetworks.
■
Encryption
—Dataencryptionusesoneof thefollowingmethods:
■
CCMP(AES)—AES‐CCMPis usedasth e multicastencryption
cipher.AES‐CCMPisthestanda rdencryptioncipherrequiredfor
WPA2.(Thisisthedefaultsetting.)
■
TKIP
—TKIPisusedasthemulticastencryptioncipher.