Configuration / project engineering
5.6 Configuration with Web Based Management
SCALANCE W786-xPRO
124
Operating Instructions, Release 08/2007, C79000-G8976-C221-02
authentication can be omitted.
A RADIUS server is used to authenticate the client with an access point. The client logs
on at a RADIUS server based on a certificate (EAP-TLS) or a combination of user name
and password (EAP-PEAP or EAP-TTLS / internal authentication method MSCHAPv2).
As an option, the RADIUS server then identifies itself to the client using a certificate.
Following successful authentication, the client and RADIUS server generate key material
that is used for data encryption. AES or TKIP is used as the encryption method, AES
represents the standard method.
●
WPA-Auto-PSK
Setting with which an access point can process both the "WPA-PSK" as well as the
"WPA2-PSK" type of authentication. This is necessary when the access point
communicates with different clients, some using "WPA-PSK" and others "WPA2-PSK".
The same encryption method must be set on the clients.
●
WPA-Auto
Setting with which an access point can process both the "WPA" as well as the "WPA2"
type of authentication. This is necessary when the access point communicates with
different clients, some using "WPA" and others "WPA2". The same encryption method
must be set on the clients.
Encryption
Encryption protects the transferred data from eavesdropping and corruption. You can only
disable encryption if you have selected "Open System" for authentication. All other security
methods include both authentication and encryption.
Encryption methods
If you have selected Open System including encryption or "Shared Key" for authentication,
you will need to define a key in the "Keys" menu (see section "Keys menu command").
●
WEP (Wired Equivalent Privacy)
A weak, symmetrical stream encryption method with only 40- or 104-bit long keys based
on the RC4 algorithm (Ron
’
s Code 4).
If you have selected WPA-PSK or WPA (RADIUS) as the authentication, the following
alternatives are available in the "Cipher" box:
●
TKIP (Temporal Key Integrity Protocol)
A symmetrical stream encryption method with the RC4 algorithm (Ron
’
s Code 4). In
contrast to the weak WEP encryption, TKIP uses changing keys derived from a main key.
TKIP can also recognize corrupted packets.
●
AES (Advanced Encryption Standard)
Strong symmetrical block encryption method based on the Rijndael algorithm that further
improves the functions of TKIP.
●
AUTO
AES or TKIP is used depending on the capability of the other station.
RADIUS Authentication Method (only for clients and access points in client mode)
If a client is authenticated over an external RADIUS server, you can use the "RADIUS
authentication type" selection list to specify a method for external authentication. As default,
the "Auto" value is selected so that the client provides a RADIUS server with all supported
methods. Any other selection restricts the support by the client to this one method. This step