User guide

Adding or Modifying Network Properties 61
Chapter 6: Managing Network Access
Encryption Methods for an Association Mode
Your choice of encryption method depends on the access point requirements. The
choices available to you depend on the association mode you choose. See
“Wired-Equivalent Privacy” on page 10 and “Wi-Fi Protected Access and its
Encryption Methods” on page 11 for more information.
You have the following options:
None—Use this setting to select 802.1X authentication without WEP keys. This
option is available to you only when you configure access point association in
open mode. This is a typical setting to use for wireless hotspots.
WEP—Use this setting to use WEP keys for data encryption. This is an option
for open mode association and is required when you associate in shared mode.
When you use WEP encryption, you must fill in at least one preconfigured WEP
key at the bottom of the Add Network dialog, unless you authenticate using a
profile and select Keys will be generated automatically for data privacy. You
must choose WEP encryption when the access points in your network require
shared mode association with WEP keys or when your access points require
WEP encryption.
TKIP—Use this setting to use the temporal key integrity protocol. Choose this
option when the access points in your network require WPA or WPA2
association and are configured for TKIP data encryption.
AES—Use this setting to use the advanced encryption standard protocol.
Choose this option when the access points in your network require WPA or
WPA2 association and are configured for AES data encryption. If your client
hardware and access point support AES, use AES encryption when you
associate in WPA2 or WPA mode. You must use this method for encryption
when associating to hardware that supports xSec.
FIPS Association Mode (FE Only)
All FIPS network configurations require that you use TLS for EAP authentication.
xSec and WPA2 are the only association modes supported for FIPS secure
encryption. If you configure FIPS mode with WPA2 and AES, you can authenticate
using either a passphrase or a profile.
FIPS Secure Encryption (FE Only)
If you require FIPS encryption each time that you connect to a specific wireless
network, select FIPS mode required as part of setting up a configuration for that
network. If not, leave the box cleared.
Whether you configure xSec or WP2 as the association mode for FIPS security, you
must use AES as the encryption method.
NOTE: This is an advanced feature. Please see your network administrator if you
have any questions about its use. If you are a network administrator and you
require FIPS–compliant connections to this network, it is best to create and lock
this network connection for your users using the tools in the Odyssey Access
Client Administrator.