Specifications
Security
RoamAbout RBT-4102 Wireless Access Point Configuration Guide 4-83
– Supported‐allowsWPA‐enab ledclientsandclientsonlycapableofsupportingWEPto
accessthenetwork.
• WPAKeyManagement:YoucanconfigureWPAtoworkinanenterpriseenvironmentusing
IEEE802.1xandaRADIUSserverforuserauthentication.Forsmallernetworks,youcan
configureWPAusingacommonpre
‐sharedkeyforclientauthenticationwiththeaccess
point.
– WPAauthenticationover802.1xsetsthisradiointerfaceorVAPtotheWPAenterprise
mode.ThismodeusesIEEE802.1xtoauthenticateusersandtodynamicallydistribute
encryptionkeystoclients.
– WPAPre‐sharedKeysetsthisradiointerfaceorVAP
totheWPAmodeforsmallnetworks.
Thismodeusesacommonpasswordstringthatismanuallydistributed.Youmust
configureallwirelessclientsassociatedwiththisradiointerfaceorVAPwiththe same
key.YoumustspecifythekeystringundertheWPAPre‐SharedKeyTypesectionof
the
SecuritySettingspage.
• MulticastCipherModeselectsanencryptionmethodfortheglobalkeyusedformulticastand
broadcasttraffic,whichissupportedbyallwirelessclientsassociatedwiththisradiointerface
orVAP.
– WEPspecifiesthatcommunicatingdevicesmustusethesameWEPkeytoencryptand
decryptradio
signals.WEPhasmanysecurityflaws,andisnotrecommendedfor
transmittinghighly‐sensitivedata.
– TKIPprovidesdataencryptionenhancementsincludingper‐packetkeyhashing(thatis,
changingtheencryptionkeyoneachpacket),amessageintegritycheck,anextended
initializationvectorwithsequencingrules,andare‐keyingmechanism.
–
AESdesignatedbytheNationalInstituteofStandardsandTechnologyasthesuccessorto
theDataEncryptionStandard(DES)encryptionalgorithm.
• WPAPre‐sharedKeyTypespecifiestheWPApre‐sharedkeytypeandthekeyforclient
authenticationwiththisradiointerfaceorVAP.IfyouusetheWPA
pre‐shared‐key,youmust
configureallwirelessclientswiththesamekeyenteredheretocommunicatewiththis
interfaceorVAP.
– Hexadecimalusesakeymadeupofastringof64hexadecimalnumbers.
– WPAPre‐SharedKeyspecifiesthepre‐sharedkeyintheappropriateformatforthetype
of
keyyouselected:astringof64hexadecimalnumbers,orastringof8to63alphanumeric
characters.
• 802.1xAuthentication:
WirelessclientscanbeauthenticatedfornetworkaccessbycheckingtheirMACaddress
againstthelocaldatabaseconfiguredontheaccesspoint,orbyusingtheIEEE802.1x
network
accessauthenticationprotocoltolookuptheirMACaddressesonaRADIUSserver.The
802.1xprotocolcanalsobeconfiguredtocheckotherusercredentialssuchasausernameand
password.
• 802.1xSetup.IEEE802.1xisastandardframeworkfornetworkaccesscontrolthatusesa
centralRADIUS
serverforuserauthentication.Thiscontrolfeaturepreventsunauthorized
accesstothenetworkbyrequiringan802.1xclientapplicationtosubmitusercredentialsfor
authentication.The802.1xstandardusestheExtensibleAuthenticationProtocol(EAP)topass
usercredentials(eitherdigitalcertificates,usernamesandpasswords,orother)fromtheclient
to
theRADIUSserver.ClientauthenticationisthenverifiedontheRADIUSserverbeforethe
accesspointgrantsclientaccesstothenetwork.