tication instance in the form of a server (e.g. a RADIUS server) is used in these cases. PSK
(preshared keys) are usually used in smaller networks, such as those seen in SoHo (Small
office, Home office). Therefore, all the wireless LAN subscribers must know the PSK, be-
cause it is used to generate the session key.
WPA2
WPA2 is the enhancement of WPA. In WPA2, the 802.11i standard is not only implemen-
ted for the first time in full, but another encryption algorithm AES (Advanced Encryption
Standard) is also used.
Access control
You can control which clients can access your wireless LAN via your device by creating an
Access Control List (
ACL Mode
or
MAC-Filter
). In the Access Control List, you enter the
MAC addresses of the clients that may access your wireless LAN. All other clients have no
access.
Security measures
To protect the data transferred on the WLAN, the following configuration steps should be
carried out in the
Wireless LAN
->
WLAN
->
Virtual Service Sets
->
New
->
/
menu, where
necessary:
• Change the access passwords for your device.
• Change the default SSID,
Network Name (SSID)
=
7!%
, of your access point.
Set
Visible
=
#/
. This will exclude all WLAN clients that attempt to establish a
connection with the general value for
Network Name (SSID)
1)
and do not know the
SSID settings.
• Use the available encryption methods. For this, select
Security Mode
=
0
,
0
,
01!-2
or
01 ,&
or both, and enter the corresponding key into the
access point under
WEP Key
1 - 4 or
Preshared Key
in the WLAN clients.
• The WEP key should be changed regularly. To do this, change
Transmit Key
. Select the
longer 104 Bit WEP key.
• For transmission of information with very high security relevance, configure
Security
Mode
=
01 ,&
with
WPA Mode
=
01
. This method contains hardware-
based encryption and RADIUS authentication of the client. In special cases, combination
with IPSec is possible.
• Restrict WLAN access to permitted clients. Enter the MAC addresses of the wireless net-
work cards for these clients in the
Allowed Addresses
list in the
MAC-Filter
menu (see
Fields in the MAC-Filter menu
on page 173).
Funkwerk Enterprise Communications GmbH
13 Wireless LAN
R1xxx/R3xxx/R4xxx
169