Appendix D Wireless LANs
P-320W v3 User’s Guide
244
TKIP regularly changes and rotates the encryption keys so that the same
encryption key is never used twice. The RADIUS server distributes a Pairwise
Master Key (PMK) key to the AP that then sets up a key hierarchy and
management system, using the pair-wise key to dynamically generate unique data
encryption keys to encrypt every data packet that is wirelessly communicated
between the AP and the wireless clients. This all happens in the background
automatically.
WPA2 AES (Advanced Encryption Standard) is a block cipher that uses a 256-bit
mathematical algorithm called Rijndael.
The Message Integrity Check (MIC) is designed to prevent an attacker from
capturing data packets, altering them and resending them. The MIC provides a
strong mathematical function in which the receiver and the transmitter each
compute and then compare the MIC. If they do not match, it is assumed that the
data has been tampered with and the packet is dropped.
By generating unique data encryption keys for every data packet and by creating
an integrity checking mechanism (MIC), TKIP makes it much more difficult to
decode data on a Wi-Fi network than WEP, making it difficult for an intruder to
break into the network.
The encryption mechanisms used for WPA and WPA-PSK are the same. The only
difference between the two is that WPA-PSK uses a simple common password,
instead of user-specific credentials. The common-password approach makes WPA-
PSK susceptible to brute-force password-guessing attacks but it's still an
improvement over WEP as it employs an easier-to-use, consistent, single,
alphanumeric password.
User Authentication
WPA or WPA2 applies IEEE 802.1x and Extensible Authentication Protocol (EAP) to
authenticate wireless clients using an external RADIUS database.
If both an AP and the wireless clients support WPA2 and you have an external
RADIUS server, use WPA2 for stronger data encryption. If you don't have an
external RADIUS server, you should use WPA2 -PSK (WPA2 -Pre-Shared Key) that
only requires a single (identical) password entered into each access point, wireless
gateway and wireless client. As long as the passwords match, a wireless client will
be granted access to a WLAN.
If the AP or the wireless clients do not support WPA2, just use WPA or WPA-PSK
depending on whether you have an external RADIUS server or not.
Select WEP only when the AP and/or wireless clients do not support WPA or WPA2.
WEP is less secure than WPA or WPA2.
Summary of Contents for P-320W v3
Page 2: ......
Page 8: ...Safety Warnings P 320W v3 User s Guide 8 ...
Page 10: ...Contents Overview P 320W v3 User s Guide 10 ...
Page 18: ...Table of Contents P 320W v3 User s Guide 18 ...
Page 20: ...20 ...
Page 24: ...Chapter 1 Getting to Know Your P 320W v3 P 320W v3 User s Guide 24 ...
Page 36: ...Chapter 2 Introducing the Web Configurator P 320W v3 User s Guide 36 ...
Page 54: ...54 ...
Page 72: ...Chapter 4 Wireless LAN P 320W v3 User s Guide 72 ...
Page 76: ...Chapter 5 Wireless Client Mode P 320W v3 User s Guide 76 ...
Page 88: ...Chapter 7 LAN P 320W v3 User s Guide 88 ...
Page 104: ...Chapter 10 VLAN P 320W v3 User s Guide 104 ...
Page 105: ...105 PART III Security Firewall 117 Content Filtering 125 ...
Page 106: ...106 ...
Page 116: ...Chapter 11 WAN P 320W v3 User s Guide 116 ...
Page 124: ...Chapter 12 Firewall P 320W v3 User s Guide 124 ...
Page 130: ...130 ...
Page 134: ...Chapter 14 Static Route P 320W v3 User s Guide 134 ...
Page 140: ...Chapter 15 Remote Management P 320W v3 User s Guide 140 ...
Page 154: ...Chapter 16 Universal Plug and Play UPnP P 320W v3 User s Guide 154 ...
Page 155: ...155 PART V Maintenance and Troubleshooting System 157 Logs 163 Product Specifications 193 ...
Page 156: ...156 ...
Page 178: ...Chapter 18 Logs P 320W v3 User s Guide 178 ...
Page 184: ...Chapter 19 Tools P 320W v3 User s Guide 184 ...
Page 192: ...Chapter 20 Troubleshooting P 320W v3 User s Guide 192 ...
Page 196: ...Chapter 21 Product Specifications P 320W v3 User s Guide 196 ...
Page 198: ...198 ...
Page 260: ...Index P 320W v3 User s Guide 260 ...
Page 261: ......
Page 262: ......