background image

ZyXEL MAX-100 Series User’s Guide

51

A

P P E N D I X

B

WiMAX Security

Wireless security is vital to protect your wireless communications. Without it, information 
transmitted over the wireless network would be accessible to any networking device within 
range.

User Authentication and Data Encryption

The WiMAX (IEEE 802.16) standard employs user authentication and encryption to ensure 
secured communication at all times.

User authentication is the process of confirming a user’s identity and level of authorization. 
Data encryption is the process of encoding information so that it cannot be read by anyone 
who does not know the code. 

WiMAX uses PKMv2 (Privacy Key Management version 2) for authentication, and CCMP 
(Counter Mode with Cipher Block Chaining Message Authentication Protocol) for data 
encryption. 

WiMAX also supports EAP (Extensible Authentication Protocol, RFC 2486) which allows 
additional authentication methods to be deployed with no changes to the base station or the 
mobile or subscriber stations.

PKMv2

PKMv2 is a procedure that allows authentication of a mobile or subscriber station and 
negotiation of a public key to encrypt traffic between the MS/SS and the base station. PKMv2 
uses standard EAP methods such as Transport Layer Security (EAP-TLS) or Tunneled TLS 
(EAP-TTLS) for secure communication. 

In cryptography, a ‘key’ is a piece of information, typically a string of random numbers and 
letters, that can be used to ‘lock’ (encrypt) or ‘unlock’ (decrypt) a message. Public key 
encryption uses key pairs, which consist of a public (freely available) key and a private 
(secret) key. The public key is used for encryption and the private key is used for decryption. 
You can decrypt a message only if you have the private key. Public key certificates (or ‘digital 
IDs’) allow users to verify each other’s identity. 

CCMP

All traffic in a WiMAX network is encrypted using CCMP (Counter Mode with Cipher Block 
Chaining Message Authentication Protocol). CCMP is based on the 128-bit Advanced 
Encryption Standard (AES) algorithm. 

Summary of Contents for MAX-100 Series

Page 1: ...ZyXEL MAX 100 Series WiMAX PCMCIA Card User s Guide Version 1 00 Edition 1 03 2007 ...

Page 2: ......

Page 3: ...by ZyXEL Communications Corporation All rights reserved Disclaimer ZyXEL does not assume any liability arising out of the application or use of any products or software described herein Neither does it convey any license under its patent rights nor the patent rights of others ZyXEL further reserves the right to make changes in any products described herein without notice This publication is subjec...

Page 4: ...he user is encouraged to try to correct the interference by one or more of the following measures 1 Reorient or relocate the receiving antenna 2 Increase the separation between the equipment and the receiver 3 Connect the equipment into an outlet on a circuit different from that to which the receiver is connected 4 Consult the dealer or an experienced radio TV technician for help FCC Radiation Exp...

Page 5: ...ications not expressly approved by the party responsible for compliance could void the user s authority to operate the equipment This Class B digital apparatus complies with Canadian ICES 003 Cet appareil numérique de la classe B est conforme à la norme NMB 003 du Canada Viewing Certifications 1 Go to http www zyxel com 2 Select your product from the drop down list box on the ZyXEL home page to go...

Page 6: ...hock from lightning Connect ONLY suitable accessories to the device Do NOT open the device or unit Opening or removing covers can expose you to dangerous high voltage points or other risks ONLY qualified service personnel should service or disassemble this device Please contact your vendor for further information Do not use the device outside and make sure all the connections are indoors There is ...

Page 7: ...placement as provided under this warranty is the exclusive remedy of the purchaser This warranty is in lieu of all other warranties express or implied including any implied warranty of merchantability or fitness for a particular use or purpose ZyXEL shall in no event be held liable for indirect or consequential damages of any kind to the purchaser To obtain the services of this warranty contact Zy...

Page 8: ...ha 4 Modrany Ceská Republika info cz zyxel com 420 241 091 359 DENMARK support zyxel dk 45 39 55 07 00 www zyxel dk ZyXEL Communications A S Columbusvej 2860 Soeborg Denmark sales zyxel dk 45 39 55 07 07 FINLAND support zyxel fi 358 9 4780 8411 www zyxel fi ZyXEL Communications Oy Malminkaari 10 00700 Helsinki Finland sales zyxel fi 358 9 4780 8448 FRANCE info zyxel fr 33 4 72 52 97 97 www zyxel f...

Page 9: ...upport zyxel es 34 902 195 420 www zyxel es ZyXEL Communications Arte 21 5ª planta 28033 Madrid Spain sales zyxel es 34 913 005 345 SWEDEN support zyxel se 46 31 744 7700 www zyxel se ZyXEL Communications A S Sjöporten 4 41764 Göteborg Sweden sales zyxel se 46 31 744 7701 UKRAINE support ua zyxel com 380 44 247 69 78 www ua zyxel com ZyXEL Ukraine 13 Pimonenko Str Kiev 04050 Ukraine sales ua zyxel...

Page 10: ...ZyXEL MAX 100 Series User s Guide 10 Customer Support ...

Page 11: ...ce 19 1 2 Application Overview 19 1 3 ZyXEL Device Hardware 20 1 4 The ZyXEL Utility 20 1 4 1 Accessing the ZyXEL Utility 21 Chapter 2 Tutorial 23 2 1 Connecting to the Internet 23 2 1 1 Set Up Your User Name and Password 23 2 1 2 Set Up Search Frequencies 24 2 1 3 Confirm the Connection 25 Chapter 3 Wireless Configuration 27 3 1 WiMAX Overview 27 3 2 ZyXEL Utility Summary 28 3 3 The Link Info Scr...

Page 12: ...een 39 3 8 1 Uploading Firmware 40 Chapter 4 Maintenance 43 4 1 The About Screen 43 4 2 Uninstalling the ZyXEL Utility 43 4 3 Upgrading the ZyXEL Utility 44 Chapter 5 Troubleshooting 47 5 1 Problems Starting the ZyXEL Utility 47 5 2 Problems Connecting to the Internet 47 5 3 Problems with the Link Quality 48 Appendix A Product Specifications 49 Appendix B WiMAX Security 51 Appendix C Setting up Yo...

Page 13: ...Frequency Conversion 31 Table 8 DL Frequency Example Settings 33 Table 9 The Site Survey Screen Manual 34 Table 10 The Site Survey Screen Express 35 Table 11 Example Supported Frequencies GHz 35 Table 12 Example Frequency Settings 35 Table 13 The Profile Screen 38 Table 14 The Adapter Screen 40 Table 15 About 43 Table 16 Troubleshooting Starting the ZyXEL Utility 47 Table 17 Troubleshooting Intern...

Page 14: ...ZyXEL MAX 100 Series User s Guide 14 List of Tables ...

Page 15: ...rvey Screen manual 34 Figure 14 The Site Survey Screen Express 34 Figure 15 Search Example 1 36 Figure 16 Search Example 2 36 Figure 17 Frequency Values 36 Figure 18 Automatic Completion 37 Figure 19 Authentication 37 Figure 20 The Profile Screen 38 Figure 21 The Adapter Screen 39 Figure 22 Adapter Upload Firmware 40 Figure 23 About 43 Figure 24 Uninstall Confirm 44 Figure 25 Uninstall Finish 44 F...

Page 16: ...ZyXEL MAX 100 Series User s Guide 16 List of Figures ...

Page 17: ...or product news firmware updated documents and other support materials User Guide Feedback Help us help you E mail all User s Guide related comments questions or suggestions for improvement to techwriters zyxel com tw or send regular mail to The Technical Writing Team ZyXEL Communications Corp 6 Innovation Road II Science Based Industrial Park Hsinchu 300 Taiwan Thank you Syntax Conventions Enter ...

Page 18: ...ZyXEL MAX 100 Series User s Guide 18 Preface Graphics Icons Key Computer Notebook Computer Wireless Base Station Wireless Signal Internet Cloud Server Router ...

Page 19: ...puter See the appendix for detailed product specifications At the time of writing this User s Guide covers the following models This User s Guide uses screens and example settings from the MAX 100 model 1 2 Application Overview In a wireless metropolitan area network MAN the ZyXEL Device connects to a base station BS for Internet access The following diagram shows a notebook computer equipped with...

Page 20: ... ZyXEL Device an icon appears in the system tray Note The ZyXEL utility system tray icon displays only when the ZyXEL Device is inserted properly Table 2 The ZyXEL Device LABEL DESCRIPTION A PCMCIA connector B 2dBi rotating antenna C PWR LED ON The ZyXEL Device is properly connected and receiving power OFF The ZyXEL Device is not receiving power D LINK LED ON The ZyXEL Device has a connection with...

Page 21: ...lity icon in the system tray to open the ZyXEL utility The ZyXEL utility screens are similar in all Microsoft Windows versions Table 3 ZyXEL Utility System Tray Icon COLOR DESCRIPTION Orange The ZyXEL Device is not connected to a wireless network or is starting up Green The ZyXEL Device is connected to a wireless network Blue The ZyXEL Device is connected to a wireless network but is in power savi...

Page 22: ...ZyXEL MAX 100 Series User s Guide 22 Chapter 1 Getting Started ...

Page 23: ...vice Provider ISP about your account and the network In this example your ISP has given you the following information about your account See Section 3 4 on page 31 for more information on radio frequencies 2 1 1 Set Up Your User Name and Password After you install the ZyXEL utility and then insert the ZyXEL Device see the Quick Start Guide for details follow the steps below to set up your user nam...

Page 24: ...e button 2 1 2 Set Up Search Frequencies 1 Click the Site Survey tab to open the screen shown next The Site Survey screen allows you to specify a set of frequencies to search for a connection to a base station The Manual site survey screen displays Figure 5 Tutorial Site Survey Screen Manual 2 You have chosen to use the Manual site survey screen because you need to enter four different frequencies...

Page 25: ...ency 4 2 1 3 Confirm the Connection 1 Click the Link Info tab The screen appears as shown next If the ZyXEL Device has successfully connected to a base station the indicators at the bottom of the screen show the strength and quality of the connection Figure 7 Tutorial Link Info Screen 2 Open your Internet browser and enter http www zyxel com or the URL of any other web site in the address bar If y...

Page 26: ...ZyXEL MAX 100 Series User s Guide 26 Chapter 2 Tutorial ...

Page 27: ...ducts In a wireless MAN a wireless equipped computer is known either as a mobile station MS or a subscriber station SS Mobile stations use the IEEE 802 16e standard and are able to maintain connectivity while switching their connection from one base station to another base station handover while subscriber stations use other standards that do not have this capability IEEE 802 16 2004 for example T...

Page 28: ...station s coverage area can extend over many hundreds of meters even under poor conditions A base station provides network access to subscriber stations and mobile stations and communicates with other base stations 3 2 ZyXEL Utility Summary This section describes the ZyXEL utility Figure 10 ZyXEL Utility Summary B A C ...

Page 29: ...the utility Link Info Use this screen to see your current connection status configuration and data rate statistics Site Survey Use these screens to configure wireless connection settings Profile Use this screen to configure wireless security and Internet access settings Adapter Use this screen to see your ZyXEL Device s firmware version number and to upload new firmware About Click this button to ...

Page 30: ...ate a base station Initial DCD Downlink Channel Descriptor the ZyXEL Device has located a base station and is receiving information about a possible downlink connection Initial UCD Uplink Channel Descriptor the ZyXEL Device is receiving information from the base station about a possible uplink connection Initial Ranging and Calibration the ZyXEL Device and the base station are transmitting and rec...

Page 31: ...SI This value is a measurement of overall radio signal strength A higher RSSI level indicates a stronger signal and a lower RSSI level indicates a weaker signal UL Data Rate This field shows the number of data packets uploaded from the ZyXEL Device to the base station each second DL Data Rate This field shows the number of data packets downloaded to the ZyXEL Device from the base station each seco...

Page 32: ...ncies Your operator can give you information on the supported frequencies The downlink frequencies are points of the frequency range your ZyXEL Device searches for an available connection Use the site survey screen to set these bands You can set the downlink frequencies anywhere within the WiMAX frequency range In this example the downlink frequencies have been set to search all of the operator ra...

Page 33: ... moves on to the next DL Frequency field When the ZyXEL Device connects to a base station the values in this screen are automatically set to the base station s frequency The next time the ZyXEL Device searches for a connection it searches only this frequency If you want the ZyXEL Device to search other frequencies enter them in the DL Frequency fields The following table describes some examples of...

Page 34: ...n to a base station Figure 14 The Site Survey Screen Express Table 9 The Site Survey Screen Manual LABEL DESCRIPTION Site Information DL Frequency 1 9 These fields show the downlink frequency settings in kilohertz kHz Enter values in these fields to have the ZyXEL Device scan these frequencies for available channels in ascending numerical order Contact your service provider for details of supporte...

Page 35: ...ure for a connection as shown Table 10 The Site Survey Screen Express LABEL DESCRIPTION DL Frequency Start Use this field to set the low end of the frequency range in kilohertz DL Frequency Stop Use this field to set the high end of the frequency range in kilohertz DL Frequency Step Use this field to set the step size between DL Frequency values in kilohertz The step size is the difference between...

Page 36: ... range is not searched as in the following figure The arrow shows the ZyXEL Device searching the first nine points and the cross shows the points that are not searched Figure 16 Search Example 2 2 Your ISP gave you 25 MHZ as the downlink frequency step so leave the DL Frequency Step field at its default 25 MHz 25000 kHz Figure 17 Frequency Values 3 Click Finish to return to the Manual screen The D...

Page 37: ...bile or subscriber stations WiMAX uses PKM Privacy Key Management for authentication between the mobile or subscriber station and the base station and supports EAP Extensible Authentication Protocol between the mobile or subscriber station the base station and the AAA server The following figure shows a base station using an AAA server to authenticate mobile station MS allowing it to access the In...

Page 38: ...ount Don t save user and password Select this box if you want to enter your user name and password every time you use the ZyXEL Device on this computer If you do not select this box anyone using the ZyXEL Device on this computer can use your Internet account to access the Internet Anonymous Identity Enter the anonymous identity provided by your Internet Service Provider Anonymous identity also kno...

Page 39: ...for your device s specific model Refer to the label on your ZyXEL Device Figure 21 The Adapter Screen TTLS Inner EAP Select the type of inner authentication to be used from the drop down list box Check with your service provider if you are unsure of the correct setting for your account The ZyXEL Device supports the following inner authentication types CHAP Challenge Handshake Authentication Protoc...

Page 40: ...t when you are ready to upload A window similar to the following appears Figure 22 Adapter Upload Firmware 3 Locate the firmware file and click Open 4 The firmware s filename appears in the Image File Name field The progress bar displays how much of the file has uploaded This may take several minutes Table 14 The Adapter Screen LABEL DESCRIPTION Version This is the version number of the firmware t...

Page 41: ...ce or turn off the computer while firmware upload is in progress This may PERMANENTLY DAMAGE your device 5 When the upload is finished restart your ZyXEL Device unplug it then plug it back in Open the utility and click the Adapter tab Check that the Version field displays the filename of the new firmware ...

Page 42: ...ZyXEL MAX 100 Series User s Guide 42 Chapter 3 Wireless Configuration ...

Page 43: ...d only fields in this screen 4 2 Uninstalling the ZyXEL Utility Follow the steps below to remove or uninstall the ZyXEL utility from your computer Note Before you uninstall the ZyXEL utility make a copy of your current wireless configurations Table 15 About LABEL DESCRIPTION Driver version This field displays the version number of the ZyXEL Device driver The driver is a piece of software your comp...

Page 44: ...l Finish 4 3 Upgrading the ZyXEL Utility To perform the upgrade follow the steps below 1 Download the latest version of the utility from the ZyXEL web site and save the file on your computer Note Before you uninstall the ZyXEL utility make a copy of your current wireless configurations 2 Follow the steps in Section 4 2 on page 43 to remove the current ZyXEL utility from your computer Restart your ...

Page 45: ...ZyXEL MAX 100 Series User s Guide Chapter 4 Maintenance 45 5 Insert the ZyXEL Device and check the version numbers in the About screen to make sure the new utility is installed properly ...

Page 46: ...ZyXEL MAX 100 Series User s Guide 46 Chapter 4 Maintenance ...

Page 47: ...tility icon does not display Restart your computer and insert the ZyXEL Device If the icon still does not display uninstall remove and re install the ZyXEL utility Table 17 Troubleshooting Internet Connection PROBLEM CORRECTIVE ACTION I cannot access the Internet Check your connection Open the ZyXEL utility and check the Link Info screen If the ZyXEL Device cannot detect a signal you are not conne...

Page 48: ...ink Info screen in the ZyXEL utility to see information about your wireless connection Poor signal reception may be improved by changing the position of the antenna or moving the ZyXEL Device away from thick walls and other obstructions or to a higher floor in your building There may be radio interference caused by nearby electrical devices such as microwave ovens and radio transmitters Move the Z...

Page 49: ...2W Dimensions 58 x 125 x 10mm RADIO SPECIFICATIONS Media Access Protocol IEEE 802 16e WiMAX Frequency Range MAX 100 2 5 2 7 GHz MAX 110 3 4 3 6 GHz MAX 130 2 3 2 4 GHz Data Rate Downlink Maximum 5Mbps Uplink Maximum 2Mbps Modulation QPSK upload and download 16 QAM upload and download 64 QAM download only Output Power 23dBm 1dB Duplex mode Time Division Duplex TDD SOFTWARE SPECIFICATIONS Device Dri...

Page 50: ...ZyXEL MAX 100 Series User s Guide 50 Appendix A ...

Page 51: ...ion methods to be deployed with no changes to the base station or the mobile or subscriber stations PKMv2 PKMv2 is a procedure that allows authentication of a mobile or subscriber station and negotiation of a public key to encrypt traffic between the MS SS and the base station PKMv2 uses standard EAP methods such as Transport Layer Security EAP TLS or Tunneled TLS EAP TTLS for secure communication...

Page 52: ...n as a security association SA In a WiMAX network the process of security association has three stages Authorization request and reply The MS SS presents its public certificate to the base station The base station verifies the certificate and sends an authentication key AK to the MS SS Key request and reply The MS SS requests a transport encryption key TEK which the base station generates and encr...

Page 53: ... sends another Access Request message The following types of RADIUS messages are exchanged between the base station and the RADIUS server for user accounting Accounting Request Sent by the base station requesting accounting Accounting Response Sent by the RADIUS server to indicate that it has started or stopped accounting In order to ensure network security the access point and the RADIUS server u...

Page 54: ...icate is an electronic ID card that authenticates the sender s identity However to implement EAP TLS you need a Certificate Authority CA to handle certificates which imposes a management overhead EAP TTLS Tunneled Transport Layer Service EAP TTLS is an extension of the EAP TLS authentication that uses certificates for only the server side authentications to establish a secure connection Client aut...

Page 55: ...CP IP installed Windows 2000 and Windows XP usually include TCP IP Configure the TCP IP settings in order to communicate with your network Windows 2000 XP 1 Click start Start in Windows 2000 Control Panel Figure 26 Windows XP Start Menu 2 Click Network Connections Network and Dial up Connections in Windows 2000 ...

Page 56: ...e 27 Windows XP Control Panel 3 Right click Local Area Connection and then click Properties Figure 28 Windows XP Control Panel Network Connections Properties 4 Select Internet Protocol TCP IP under the General tab in Win XP and click Properties ...

Page 57: ...erties window the General tab in Windows XP opens Figure 30 Windows XP Internet Protocol TCP IP Properties If you have a dynamic IP address click Obtain an IP address automatically If you have a static IP address click Use the following IP Address and fill in the IP address Subnet mask and Default gateway fields Click Advanced ...

Page 58: ...he above two steps for each IP address you want to add Configure additional default gateways in the IP Settings tab by clicking Add in Default gateways In TCP IP Gateway Address type the IP address of the default gateway in Gateway To manually configure a default metric the number of transmission hops clear the Automatic metric check box and type a metric in Metric Click Add Repeat the previous th...

Page 59: ...erties 8 Click OK to close the Internet Protocol TCP IP Properties window 9 Click Close OK in Windows 2000 to close the Local Area Connection Properties window 10Close the Network Connections window Network and Dial up Connections in Windows 2000 11Restart your computer if prompted Verifying Settings 1 Click Start All Programs Accessories and then Command Prompt 2 In the Command Prompt window type...

Page 60: ...ZyXEL MAX 100 Series User s Guide 60 ...

Page 61: ... base station see BS BS 27 links 27 C CA 54 CBC MAC 52 CCMP 51 52 CD 17 cell 27 certificate 51 verification 52 Certificate Authority see CA certifications 4 notices 5 viewing 5 chaining 52 chaining message authentication see CCMP CMAC see MAC configuration 27 statistics 29 connection 17 20 status 21 29 contact information 8 copyright 3 counter mode see CCMP coverage area 27 cryptography 51 custome...

Page 62: ...hentication 53 installation 17 20 interface 49 interference 48 Internet access 23 24 37 Internet Service Provider see ISP interoperability 27 introduction 19 ISP 23 K key 51 key request and reply 52 L link quality troubleshooting 48 M MAC 52 MAN 27 manual site survey 24 25 media access protocol 49 message authentication code see MAC message integrity 52 Metropolitan Area Network see MAN Microsoft ...

Page 63: ...arnings 6 secure communication 51 secure connection 37 security 49 51 settings 29 security association 52 see SA services 37 settings frequency 24 Internet access 29 security 29 signal quality 25 signal strength 25 site survey 23 24 specifications 49 physical and environmental 49 radio 49 SS 27 standards 49 storage humidity 49 storage temperature 49 subscriber station see SS support 17 syntax conv...

Page 64: ... Forum 27 wireless configuration 27 wireless connection status 25 Wireless Interoperability for Microwave Access see WiMAX wireless Metropolitan Area Network see MAN wireless network 23 access 27 standard 27 wireless network adapter 19 wireless security 49 51 Z ZyXEL Device about 19 ZyXEL utility 19 20 23 27 access 21 icon 20 status 21 summary 28 troubleshooting 47 upgrading 44 version number 43 ...

Reviews: