User`s guide

3-22 CB3000 Client Bridge User’s Guide
Configuring WPA2 Enterprise - EAP-TLS
Extensible Authentication Protocol (EAP) is an authentication framework that provides common functions
and a method to negotiate a desired authentication medium. EAP-Transport Layer Security (EAP-TLS) uses
client side certificates to ensure that security is not compromised.
See Figure 3.12 for WPA1 Enterprise EAP-TLS security fields.
WPA2 Algorithm Select the WPA2 algorithm to use:
TKIP – Defines a ‘wrapper’ that goes around an existing WEP encryption
algorithm. TKIP comprises the same encryption engine and RC4 algorithm
defined for WEP. However, the key used for encryption in TKIP is 128 bits
long.
TKIP changes the key used for each packet. The key is created by mixing
together a combination of things, including a base key (called a Pairwise
Transient Key), the MAC address of the transmitting station, and the serial
number for the packet.
CCMP (AES) Utilizes an Advanced Encryption Standard (AES) 128-bit
key algorithm with a 48-bit initialization vector (IV) for replay detection.
The Counter Mode (CM) component of CCMP is the algorithm providing
data privacy. The Cipher Block Chaining Message Authentication Code
(CBC-MAC) component of CCMP provides data integrity and
authentication.
Both – Select this option to enable CB3000 to support devices that use
both TKIP and CCMP algorithms. Use this option when the number of
devices is large.
WPA2 User ID The User ID for authentication.
WPA2 Key Password The key password.
WPA2 TLS Key /
WPA2 TLS Key Import
The WPA2 TLS Key. The key can be uploaded to the device by:
Pasting the TLS key in the Paste TLS Key text area. To upload the key,
click the Apply button located at the bottom of the screen.
By providing the path to the file containing the key in the Import text box.
Use the Browse button to display the Open File dialog box from where
the file can be selected. To upload the file containing the WPA2 TLS Key,
click the Apply Uploaded File button.
WPA2 User Certificate /
WPA2 User Certificate
Import
The WPA2 User Certificate. The user certificate can be uploaded to the
device by:
Pasting the certificate in the Paste User Certificate text area. To upload
the certificate, click the Apply button located at the bottom of the screen.
By providing the path to the file containing the WPA2 User Certificate in
the Import text box. Use the Browse button to display the Open File
dialog from where the file can be selected. To upload the file containing
the certificate, click the Apply Uploaded File button.