User's Manual

Table Of Contents
Wireless LAN Array
188 Appendix B: Technical Support
Security
Q. How do I know my management session is secure?
A. Follow these guidelines:
z Administrator passwords
Always change the default administrator password (the default
is admin), and choose a strong replacement password. When
appropriate, issue read only administrator accounts.
z SSH versus Telnet
Be aware that Telnet is not secure over network connections and
should be used only with a direct serial port connection. When
connecting to the unit’s Command Line Interface over a network
connection, you must use a Secure SHell (SSH) utility. The most
commonly used freeware providing SSH tools is PuTTY.
z Configuration auditing
Do not change approved configuration settings. The optional
Xirrus Wireless Management System (XM-3300) offers powerful
management features for small or large XS-3900 deployments,
and can audit your configuration settings automatically. In
addition, using the XM-3300 eliminates the need for an FTP
server.
Q. Which wireless data encryption method should I use?
A. Wireless data encryption prevents eavesdropping on data being
transmitted or received over the airwaves. The XS-3900 allows you to
establish the following data encryption configuration options:
z Open
This option offers no data encryption and is not recommended,
though you might choose this option if clients are required to use
a VPN connection through a secure SSH utility, like PuTTy.