Specifications

Security
RoamAbout RBT-4102 Wireless Access Point Configuration Guide 4-83
Supported‐allowsWPAenab ledclientsandclientsonlycapableofsupportingWEPto
accessthenetwork.
WPAKeyManagement:YoucanconfigureWPAtoworkinanenterpriseenvironmentusing
IEEE802.1xandaRADIUSserverforuserauthentication.Forsmallernetworks,youcan
configureWPAusingacommonpre
sharedkeyforclientauthenticationwiththeaccess
point.
WPAauthenticationover802.1xsetsthisradiointerfaceorVAPtotheWPAenterprise
mode.ThismodeusesIEEE802.1xtoauthenticateusersandtodynamicallydistribute
encryptionkeystoclients.
WPAPresharedKeysetsthisradiointerfaceorVAP
totheWPAmodeforsmallnetworks.
Thismodeusesacommonpasswordstringthatismanuallydistributed.Youmust
configureallwirelessclientsassociatedwiththisradiointerfaceorVAPwiththe same
key.YoumustspecifythekeystringundertheWPAPreSharedKeyTypesectionof
the
SecuritySettingspage.
MulticastCipherModeselectsanencryptionmethodfortheglobalkeyusedformulticastand
broadcasttraffic,whichissupportedbyallwirelessclientsassociatedwiththisradiointerface
orVAP.
WEPspecifiesthatcommunicatingdevicesmustusethesameWEPkeytoencryptand
decryptradio
signals.WEPhasmanysecurityflaws,andisnotrecommendedfor
transmittinghighlysensitivedata.
TKIPprovidesdataencryptionenhancementsincludingperpacketkeyhashing(thatis,
changingtheencryptionkeyoneachpacket),amessageintegritycheck,anextended
initializationvectorwithsequencingrules,andarekeyingmechanism.
AESdesignatedbytheNationalInstituteofStandardsandTechnologyasthesuccessorto
theDataEncryptionStandard(DES)encryptionalgorithm.
WPAPresharedKeyTypespecifiestheWPApresharedkeytypeandthekeyforclient
authenticationwiththisradiointerfaceorVAP.IfyouusetheWPA
presharedkey,youmust
configureallwirelessclientswiththesamekeyenteredheretocommunicatewiththis
interfaceorVAP.
Hexadecimalusesakeymadeupofastringof64hexadecimalnumbers.
WPAPreSharedKeyspecifiesthepresharedkeyintheappropriateformatforthetype
of
keyyouselected:astringof64hexadecimalnumbers,orastringof8to63alphanumeric
characters.
802.1xAuthentication:
WirelessclientscanbeauthenticatedfornetworkaccessbycheckingtheirMACaddress
againstthelocaldatabaseconfiguredontheaccesspoint,orbyusingtheIEEE802.1x
network
accessauthenticationprotocoltolookuptheirMACaddressesonaRADIUSserver.The
802.1xprotocolcanalsobeconfiguredtocheckotherusercredentialssuchasausernameand
password.
802.1xSetup.IEEE802.1xisastandardframeworkfornetworkaccesscontrolthatusesa
centralRADIUS
serverforuserauthentication.Thiscontrolfeaturepreventsunauthorized
accesstothenetworkbyrequiringan802.1xclientapplicationtosubmitusercredentialsfor
authentication.The802.1xstandardusestheExtensibleAuthenticationProtocol(EAP)topass
usercredentials(eitherdigitalcertificates,usernamesandpasswords,orother)fromtheclient
to
theRADIUSserver.ClientauthenticationisthenverifiedontheRADIUSserverbeforethe
accesspointgrantsclientaccesstothenetwork.