User Manual

Professional Access Point
Administrator Guide
Security - 99
insecure LAN always virtually separated from any sensitive information on the Internal LAN. For example,
the guest network might simply provide internet and printer access for day visitors.
The absence of security on the Guest network is designed to make it as easy as possible for guests to get
a connection without having to program any security settings in their clients.
For a minimum level of protection on a guest network, you can choose to prohibit the broadcast of the
SSID, discouraging client devices from automatically discovering your access point. (See also “Does
Prohibiting the Broadcast of SSID Enhance Security?” on page 96).
For more about the Guest network, see “Guest Login” on page 111.
Static WEP
Wired Equivalent Privacy (WEP) is a data encryption protocol for 802.11 wireless networks. All wireless
stations and access points on the network are configured with a static 64-bit (40-bit secret key + 24-bit ini-
tialization vector (IV)) or 128-bit (104-bit secret key + 24-bit IV) Shared Key for data encryption.
You cannot mix 64-bit and 128-bit WEP keys between the access point and its clients.
Static WEP is not the most secure mode available, but it offers more protection than None as it does pre-
vent an outsider from easily sniffing out unencrypted wireless traffic. (For more secure modes, see the sec-
tions on “IEEE 802.1x” on page 104, “WPA/WPA2 Enterprise (RADIUS)” on page 107, or “WPA/WPA2
Personal (PSK)” on page 105.)
WEP encrypts data moving across the wireless network based on a static key. (The encryption algorithm is
a stream cipher called RC4.)
The access point uses a key to transmit data to the clients. Each client must use that same key to decrypt
data it receives from the access point.
Clients can use different keys to transmit data to the access point. (Or they can all use the same key, but
this is less secure because it means one station can decrypt the data being sent by another.)
If you selected Static WEP as the security mode, provide the following on the access point settings: