![Ruckus Wireless ZoneDirector 1200 User Manual Download Page 223](http://html1.mh-extra.com/html/ruckus-wireless/zonedirector-1200/zonedirector-1200_user-manual_1498797223.webp)
• Every device on the WLAN has its own unique Dynamic PSK (DPSK) that is valid for
that device only.
• Each DPSK is bound to the MAC address of an authorized device - even if that PSK
is shared with another user, it will not work for any other machine.
• Since each device has its own DPSK, you can also associate a user (or device) name
with each key for easy reference.
• Each DPSK may also have an expiration date - after that date, the key is no longer
valid and will not work.
• DPSKs can be created and removed without impacting any other device on the
WLAN.
• If a hacker manages to crack the DPSK for one client, it does not expose the other
devices which are encrypting their traffic with their own unique DPSK.
DPSKs can be created in bulk and manually distributed to users and devices, or
ZoneDirector can auto-configure devices with a DPSK when they connect to the network
for the first time using Zero-IT Activation (see
Enabling Automatic User Activation with
on page 219).
Enabling Dynamic Pre-Shared Keys on a WLAN
To use DPSK for client authentication, you must enable it for a particular WLAN (if you
did not enable it during the initial ZoneDirector Setup Wizard process).
To enable DPSK for a WLAN:
1.
Go to
Configure
>
WLANs
2.
Either
Edit
an existing WLAN or
Create New
to open the WLAN configuration form.
3.
Under
Type
, select
Standard Usage
.
4.
Under
Authentication Options: Method
, select
MAC Address
or
Open
5.
Under
Encryption Options: Method
, select WPA2 (not WPA-Mixed, as selecting
WPA-Mixed will disable the Zero-IT activation option).
6.
Under
Encryption Options: Algorithm
, select AES (not Auto, as selecting Auto will
disable the Zero-IT activation option).
7.
If using MAC Address authentication, choose an
Authentication Server
to
authenticate clients against--either Local Database or RADIUS Server.
8.
Ensure that the
Zero-IT Activation
check box is enabled.
9.
Next to
Dynamic PSK
, enable the check box next to
Enable Dynamic PSK
. Select
a DPSK passphrase length (between 8 and 62 characters).
10.
Choose whether to use
Secure DPSK
or
Mobile Friendly DPSK
:
•
Secure DPSK
: Includes almost all printable ASCII characters, including periods,
hyphens, dashes, etc. This option is more secure, however it is difficult to input
for mobile clients whose keyboards may not contain the entire set of printable
ASCII characters.
223
Ruckus Wireless ZoneDirector™ Release 10.0 User Guide
Managing User Access
Working with Dynamic Pre-Shared Keys