User's Manual
–
43
–
Chapter4
|
WirelessSettings
RadioSettings
Security Settings
◆
Method—SetsthewirelesssecuritymethodforeachVAP,including
associationmode,encryption,andauthentication.(Default:NoSecurity)
■
NoSecurity — The VAP broadcasts a beaconsignalincluding the
configuredSSID.WirelessclientswithanSSIDsettingof“any”canreadthe
SSIDfromthebeaconandautomaticallysettheirSSIDtoallowimmediate
connection.
■
WEP OpenSystem — The VAP broadcastsa beacon signal including the
configuredSSID.WirelessclientswithanSSIDsettingof“any”canreadthe
SSIDfromthebeaconandautomaticallysettheirSSIDtoallowimmediate
connection.
■
Key—WEPisusedtoencryptdatatransmittedbetweenwireless
clientsandtheVAP.WEPusesstaticsharedkeys(fixed‐length
hexadecimaloralphanumericstrings)thataremanuallydistributedto
allclientsthatwanttousethenetwork.
WEPisthesecurityprotocolinitiallyspecifiedintheIEEE802.11
standardforwirelesscommunications.Unfortunately,WEPhasbeen
foundtobeseriouslyflawedandcannotberecommendedforahigh
levelofnetworksecurity.Formorerobustwirelesssecurity,theaccess
pointprovidesWi‐FiProtectedAccess(WPA)andWPA2forimproved
dataencryptionanduserauthentication.
BesurethattheWEPsharedkeysarethesameforeachclientinthe
wirelessnetwork.Allclientssharethesamekeys,whichareusedfor
data encryption.
For64‐bitWEP,stringlengthmustbe5ASCIIcharacters(lettersand
numbers)or10hexadecimaldigits.For128‐bitWEP,stringlengthmust
be13ASCIIcharacters(lettersandnumbers)or26hexadecimaldigits.
■
WPA‐PSK—Forenterprisedeployment,WPArequiresaRADIUS
authenticationservertobeconfiguredonthewirednetwork.However,for
smallofficenetworksthatmaynothavetheresourcestoconfigureand
maintainaRADIUSserver,WPAprovidesasimpleoperatingmodethatuses
justapre‐sharedpasswordfornetworkaccess.ThePre‐SharedKeymode
usesacommonpasswordforuserauthenticationthatismanuallyentered
ontheaccesspointandallwirelessclients.ThePSKmodeusesthesame
TKIPpacketencryptionandkeymanagementasWPAintheenterprise,
providingarobustandmanageablealternativeforsmallnetworks.
■
Encryption
—Dataencryptionusesoneof thefollowingmethods:
■
CCMP(AES)—AES‐CCMPis use d as themulticastencryption
cipher.AES‐CCMPisthestandardencryptioncipherrequiredfor
WPA2.(Thisisthedefaultsetting.)
■
TKIP
—TKIPisusedasthemulticastencryptioncipher.