User's Manual
Table Of Contents
- Chapter 0 - Front Cover
- Chapter 0 - Table of Contents
- Chapter 1 - Introduction
- Chapter 2 - Starting Out
- Chapter 3 - Example Applications
- Chapter 4 - Utilities and Features
- Chapter 5 - Web Configuration Manager
- Chapter 6 - Serial Configuration and Applications
- Chapter 7 - Bridging and Mesh Networking
- Chapter 8 - Antenna Setup
- Apx A - Licensing Information
- Apx B - Interface Ports
- Apx C - Radio Configuration
- Apx D - Security
- Apx E - Troubleshooting
- Apx F - Horizon 2.4 Specifications
- Apx G - Horizon 900 Specifications
- Apx H - Horizon 4.9 Specifications
- Apx I - Horizon 5.8 Specifications
APPENDIXD
SECURITY
Revised: 27 Jun 16 APX D-1 ESTeem Horizon Series
OVERVIEW
ThesecurityfortheESTeemHorizon,likeallnetworksecurity,mustbemulti‐layered.Onelevelofsecurityisneverenoughto
makesurethatdatadoesnotendupinthewronghands. Pleasereviewthefollowingsecuritylevelsanddecidewhatis themost
appropriateforyournetwork.
AES‐CCMP(802.11iandWPA‐2)
AES‐CCMP(AdvancedEncryptionStandard‐CounterMo deCBC‐MACProtocol)istheencryptionalgorithmusedintheIEEE802.11i
andWPA‐2securityprotocols.Thisnationalencryptionstandardusesa128bit‐AESblockcipherandCCMPtechniquetoensure
thehi g hes tlevelofsecurityandintegrityav ai labl e onawirelessnetwork.AES‐CCM
Pincorporatestw o sophisticatedcryptographic
techniques(countermodeandCBC‐MAC)andadaptsthemtoEthernetframestoprovidearobustsecurityprotocolbetweenthe
mobilecl ie ntandtheaccesspoint . AESitselfisaverystrongcipher,butco un t e r modemakesitdifficul t foraneavesdroppertosp
ot
patterns,andtheCBC‐MACmessageintegritymethodensuresthatmessageshavenotbee n tamperedwith. TheESTeem Horizon
iscompatibleasei the ranAccessPointorclientineit her WPA2orIEEE802.11isecuritysystems.
Wi‐Fi ProtectedAccess2withPresharedKey(WPA2PSK)
WPA2 PSK uses a co
mmon passphrase (preshar e d key) between the Access Point (AP) and the client to begin a secure
communicationsession.ThispassphrasemustbeenteredexactlythesameinboththeAccessPointandtheclient.Thispassphrase
isusedto authenticatecommunicationsessionbetweentheAPandclienttobeginthese
curewireless networki n gsession.
Wi‐FiProtected Access2withEnterpriseServer(WPAEnterprise)
LikeWPA2PSK,WPA2EnterpriseverifiestheauthenticityoftheAccessPointandclient,butusesan802.1xbackendauthentication
serverhandlingtheauthenticationdecision.ThemostcommonlytypeofauthenticationserverisaRADIUSserver.Th
eESTeem
HorizoncanbeconfiguredtooperatewithanestablishedRADIUSserveronthenetwork.
WPA
Wi‐FiProtected AccesswithPresharedKey(WPAPSK)
WPA, which uses 802.1x, was introduced in 2003 to improve on the authentication and encryption features of WEP. All
authenticationishandledwithinthisaccesspo intdevice.WPAhastwosignificantadvantagesove rWEP:
1. An encryption key differing in every packet. The TKI
P (Temporal Key Integrity Protocol) mechanism shares a starting key
betweendevices.Eachdevicethenchangesthei r encryptionkeyforev e r y packet.Itisextremelydifficultforhackerstoread
messageseveniftheyhaveinterceptedthedat a.
2. CertificateAuthentication(CA)canbeused,blockingahackerposingasav
aliduser.
Wi‐FiProtected AccesswithEnterpriseServer(WPAEnterprise)
LikeWPAPSK,WPAEnterpriseverifiestheauthenticityoftheAccessPointandclient,butusesan802.1xbackendauthentication
serverhandlingtheauthenticationdecision.ThemostcommonlytypeofauthenticationserverisaRADIUSserver.TheEST
eem
HorizoncanbeconfiguredtooperatewithanestablishedRADIUSserveronthenetwork.
WPAisserver/clientrelationshipfromasoftwaredrive ronacomputer’swirelessLAN(WLAN)cardtoanAccessPoint.Thescope
ofWPAislimitedinusetothisconfigurationonly.TheESTeemHorizoncansupportWPAEnterpri
seandPSKasanAccessPoint,
butthelevelofsecurityontheBridginglayerisconfiguredseparately.