Specifications
Security
RoamAbout Access Point 3000 Configuration Guide 4-65
• DataEncryptionSetupenablesordisablestheaccesspointtouseWEPsharedkeysfordata
encryption.Ifthisoptionisselected,youmustconfigureat
leastonekeyontheaccesspoint
andallclients.(Default:Disable
)
• WPAClientssetsthespecifiedradiointerfaceorVAPto:
– Required‐allowonlyWPA‐enabledclientstoaccessthenetwork;
– Supported‐allowWPA‐enabledclientsandclientsonlycapableofsupportingWEPto
accessthenetwork;
– Notsupported‐doesnotallowWPA‐enabledclientstoaccessthenetwork.
Default:
Supported
• WPAKeyManagement:YoucanconfigureWPAtoworkinanenterpriseenvironmentusing
IEEE802.1xandaRADIUSserverforuserauthentication.Forsmallernetworks,youcan
configureWPAusingacommonpre‐sharedkeyforclientauthenticationwiththeaccess
point.
– WPAauthen ticationover802.1xsetsthisradio
interfaceorVAPtotheWPAenterprise
mode.ThismodeusesIEEE802.1xtoauthenticateusersandtodynamicallydistribute
encryptionkeystoclients.
– WPAPre‐sharedKeysetsthisradiointerfaceorVAPtotheWPAmodeforsmallnetworks.
Thismodeusesacommonpasswordstringthatis
manuallydistributed.Youmust
configureallwirelessclientsassociatedwiththisradiointerfaceorVAPwiththe same
key.YoumustspecifythekeystringundertheWPAPre‐SharedKeyTypesectionofthe
SecuritySettingspage.
• MulticastCipherModeselectsanencryptionmethodfortheglobalkeyused
formulticastand
broadcasttraffic,whichissupportedbyallwirelessclientsassociatedwiththisradiointerface
orVAP.
– WEPspecifiesthatcommunicatingdevicesmustusethesameWEPkeytoencryptand
decryptradiosignals.WEPhasmanysecurityflaws,andisnotrecommendedfor
transmittinghighly‐sensitivedata.
– TKIP
providesdataencryptionenhancementsincludingper‐packetkeyhashing(thatis,
changingtheencryptionkeyoneachpacket),amessageintegritycheck,anextended
initializationvectorwithsequencingrules,andare‐keyingmechanism.
– AESdesignatedbytheNationalInstituteofStandardsandTechnologyasthesuccessorto
theData
EncryptionStandard(DES)encryptionalgorithm.
Note: You must enable WEP encryption in order to enable all types of encryption on the access
point; however, you do not need to define WEP keys for WPA.