WAB–2000 Wireless Access Point
Chapter 1: Introduction
6
29000156-001 A
WAB–2000 Wireless Access Point
Chapter 1: Introduction
29000156-001 A
7
Data Encryption and Security
The WAB–2000 Wireless Access Point includes advanced wireless se-
curity features. Over the AP band, you have a choice of no security, Static
WEP, or WPA. Some level of security is suggested. Static WEP gives you
a choice of 64-bit, 128-bit, or 152-bit encryption. WPA includes the option
of using a WPA pre-shared key or, for the enterprise that has a Radius
Server installed, configuration to use the Radius Server for key manage-
ment with either TKIP or AES-CCMP. Bridging encryption is established
between WAB–2000’s and includes use of AES-ECB 128-bit encryption
(approved by the National Institute of Standards and Technology (NIST)
for U.S. Government and DoD agencies).
SSID
The Service Set ID (SSID) is a string used to define a common roam-
ing domain among multiple wireless access points. Different SSIDs on
access points can enable overlapping wireless networks. The SSID can
act as a basic password without which the client cannot connect to the
network. However, this is easily overridden by allowing the wireless AP
to broadcast the SSID, which means any client can associate with the AP.
SSID broadcasting can be disabled in the WAB–2000 setup menus.
WEP
WEP is an older encryption standard but is preferable to no encryp-
tion. If the WAB–2000 is configured with WEP encryption, it is compatible
with any 802.11b PC Card configured for WEP.
WPA with TKIP/ AES-CCMP
(WPA2)
WPA, an interim standard developed by the WiFi Alliance, combines
several technologies. It includes the use of the 802.1x standard and the
Extensible Authentication Protocol (EAP). In addition, it uses, for encryp-
tion, the Temporal Key Integrity Protocol (TKIP) and WEP 128-bit encryp-
tion keys. Finally, a message integrity check (MIC) is used to prevent an
attacker from capturing and altering or forging data packets. In addition,
it can employ a form of AES called AES-CCMP.
WPA is a subset of the 802.11i standard and is expected to maintain
forward compatibility.