![Unify OpenScape WLAN Phone WL4 Planning Manual Download Page 13](http://html2.mh-extra.com/html/unify/openscape-wlan-phone-wl4/openscape-wlan-phone-wl4_planning-manual_3783828013.webp)
Security Considerations
Security Considerations
The handset can be configured to use various encryption and/or authentication schemes. The
use of extensive encryption/authentication schemes can cause incidents of dropped speech dur-
ing handover due to the time to process the authentication. No speech frames are delivered to/
from the handset until the authentication is successfully completed.
It is recommended to use Wi-Fi Protected Access (WPA2). If WPA2 security is used together
with 802.1X authentication, it is strongly recommended to use either 802.11r fast BSS transition
(FT) or proactive key caching (also called opportunistic key caching). These features are sup-
ported by the handset and enable the reuse of an existing PMKSA (Pairwise Master Key Secu-
rity Association) when roaming between APs. Roaming and handover times are reduced signifi-
cantly since only fresh session encryption keys need to be exchanged by the 4-way handshake.
When either WPA2-PSK, Opportunistic key caching or Fast BSS Transition is used, roaming dur-
ing a voice call can often be made seamless.
• MAC address filtering is not recommended because it does not provide any real protection,
only increased administration.
• Hidden SSID is not recommended because it does not provide any real protection and it
makes it more difficult for WLAN clients to roam passively.
A31003-M2000-P103-01-76A9, 29/04/2020
System Planning, Planning Guide
13