Professional Access Point
Administrator Guide
Security - 105
R
ECOMMENDATIONS
WPA/WPA2 Personal (PSK) is not recommended for use with the Professional Access Point when WPA/
WPA2 Enterprise (RADIUS) is an option.
USRobotics recommends that you use WPA/WPA2 Enterprise (RADIUS) mode instead, unless you have
interoperability issues that prevent you from using this mode.
For example, some devices on your network may not support WPA or WPA2 with
EAP
talking to a
RADIUS
server. Embedded printer servers or other small client devices with very limited space for
implementation may not support RADIUS. For such cases, USRobotics recommends that you use WPA/
WPA2 Personal (PSK).
S
EE
A
LSO
For information on how to configure this security mode, see “WPA/WPA2 Personal (PSK)” on page 115.
When to Use WPA/WPA2 Enterprise (RADIUS)
Wi-Fi Protected Access 2
(
WPA2
) with
Remote Authentication Dial-In User Service
(
RADIUS
) is an
implementation of the Wi-Fi Alliance IEEE
802.11i
standard, which includes
Advanced Encryption
Standard
(
AES
),
Counter mode/CBC-MAC Protocol
(
CCMP
), and
Temporal Key Integrity Protocol
(
TKIP
)
mechanisms. This mode requires the use of a RADIUS server to authenticate users. WPA/WPA2
Enterprise (RADIUS) provides the best security available for wireless networks.
This security mode also provides backward compatibility for wireless clients that support only the original
WPA
.
R
ECOMMENDATIONS
WPA/WPA2 Enterprise (RADIUS) mode is the
recommended mode
. The
CCMP
(
AES
) and
TKIP
encryption algorithms used with WPA modes are far superior to the
RC4
algorithm used for Static
WEP
or
IEEE 802.1x modes. Therefore, CCMP (AES) or TKIP should be used whenever possible. All WPA modes
allow you to use these encryption schemes, so WPA security modes are recommended above the others
when using WPA is an option.
Additionally, this mode incorporates a RADIUS server for user authentication, which gives it an edge over
WPA/WPA2 Personal (PSK) mode.
Use the following guidelines for choosing options within the WPA/WPA2 Enterprise (RADIUS) mode
security mode:
Key Management
Encryption Algorithms
User Authentication
WPA/WPA2 Enterprise (RADIUS)
mode provides dynamically-gener-
ated keys that are periodically
refreshed.
There are different
Unicast
keys for
each station.
•
Temporal Key Integrity Protocol
(
TKIP
)
•
Counter mode/CBC-MAC Proto-
col
(
CCMP
)
Advanced Encryption
Standard
(
AES
)
Remote Authentication Dial-In User
Service
(
RADIUS
)
You have a choice of using the Pro-
fessional Access Point embedded
RADIUS server or an external
RADIUS server. The embedded
RADIUS server supports Protected
EAP
(PEAP) and MSCHAP V2.
Summary of Contents for Instant802 APSDK
Page 1: ...Professional Access Point Administrator Guide R46 1224 00 rev 2 0 07 06...
Page 2: ......
Page 4: ...Professional Access Point Administrator Guide iv...
Page 8: ...Professional Access Point Administrator Guide viii...
Page 42: ...Professional Access Point Administrator Guide Basic Settings 42...
Page 52: ...Professional Access Point Administrator Guide Access Points 52...
Page 58: ...Professional Access Point Administrator Guide User Management 58...
Page 62: ...Professional Access Point Administrator Guide Sessions 62...
Page 70: ...Professional Access Point Administrator Guide Channel Management 70...
Page 88: ...Professional Access Point Administrator Guide Neighboring Access Points 88...
Page 96: ...Professional Access Point Administrator Guide Ethernet Wired Settings 96...
Page 120: ...Professional Access Point Administrator Guide Security 120...
Page 128: ...Professional Access Point Administrator Guide Virtual Wireless Networks 128...
Page 134: ...Professional Access Point Administrator Guide Radio 134...
Page 138: ...Professional Access Point Administrator Guide MAC Filtering 138...
Page 152: ...Professional Access Point Administrator Guide Quality of Service 152...
Page 160: ...Professional Access Point Administrator Guide Wireless Distribution System 160...
Page 164: ...Professional Access Point Administrator Guide Time Protocol 164...
Page 170: ...Professional Access Point Administrator Guide SNMP 170...
Page 290: ...Professional Access Point Administrator Guide Configuration Troubleshooting 290...
Page 298: ...Professional Access Point Administrator Guide Regulatory Information 298...
Page 328: ...Professional Access Point Administrator Guide Index 328...