Specifications

Security
4-66 Advanced Configuration
WPAPresharedKeyTypespecifiestheWPApresharedkeytypeandthekeyforclient
authenticationwiththisradiointerfaceorVAP.IfyouusetheWPApresharedkey,youmust
configureallwirelessclientswiththesamekeyenteredheretocommunicatewiththis
interfaceor
VAP.
Hexadecimalusesakeymadeupofastringof64hexadecimalnumbers.
Alphanumericusesakeyinaneasytorememberformoflettersandnumbers.Thestring
mustbefrom8to63charactersandcanincludespaces.
WPAPreSharedKeyspecifiesthepresharedkeyin
theappropriateformatforthetypeof
keyyouselected:astringof64hexadecimalnumbers,orastringof8to63alphanumeric
characters.
802.1xAuthentication:
WirelessclientscanbeauthenticatedfornetworkaccessbycheckingtheirMACaddress
againstthelocaldatabaseconfiguredontheaccesspoint,or
byusingtheIEEE802.1xnetwork
accessauthenticationprotocoltolookuptheirMACaddressesonaRADIUSserver.The
802.1xprotocolcanalsobeconfiguredtocheckotherusercredentialssuchasausernameand
password.
802.1xSetup.IEEE802.1xisastandardframeworkfornetworkaccesscontrol
thatusesa
centralRADIUSserverforuserauthentication.Thiscontrolfeaturepreventsunauthorized
accesstothenetworkbyrequiringan802.1xclientapplicationtosubmitusercredentialsfor
authentication.The802.1xstandardusestheExtensibleAuthenticationProtocol(EAP)topass
usercredentials(eitherdigitalcertificates,usernamesandpasswords,
orother)fromtheclient
totheRADIUSserver.ClientauthenticationisthenverifiedontheRADIUSserverbeforethe
accesspointgrantsclientaccesstothenetwork.
The802.1xEAPpacketsarealsousedtopassdynamicunicastsessionkeysandstatic
broadcastkeystowirelessclients.Sessionkeysare
uniquetoeachclientandareusedto
encryptandcorrelatetrafficpassingbetweenaspecificclientandtheaccesspoint.Youcan
alsoenablebroadcastkeyrotation,sotheaccesspointprovidesadynamicbroadcastkeyand
changesitataspecifiedinterval.
Youcanenable802.1xasoptionallysupported
orasrequiredtoenhancethesecurityofthe
wirelessnetwork.
Disableindicatesthattheaccesspointdoesnotsupport802.1xauthenticati onforany
wirelessclient.Aftersuccessfulwirelessassociationwiththeaccesspoint,eachclientis
allowedtoaccessthenetwork.
Supportedindicatesthattheaccesspointsupports802.1x
authenticationonlyforclients
initiatingthe802.1xauthenticationprocess(thatis,theaccesspointdoesnotinitiate
802.1xauthenticati on).Forclientsinitiating802.1x,onlythosesuccessfullyauthenticated
areallowedtoaccessthenetwork.Forthoseclientsnotinitiating802.1x,accesstothe
networkisallowedaftersuccessfulwirelessassociationwiththe
accesspoint.
Requiredindicatesthattheaccesspointenforces802.1xauthenticationforallassociated
wirelessclients.If802.1xauthenticationisnotinitiatedbyaclient,theaccesspointwill
initiateauthentication.Onlythoseclientssuccessfullyauthenticatedwith802.1xare
allowedtoaccessthenetwork.