background image

CONNECT2AIR™ WLAN AP-600RP-USB

 

 

Page 39 / 62

  

8.4.12 IEEE 802.1x 

IEEE 802.1x is a standard for network access control (port-based), which was introduced 
especially for distributing encryption keys in a wireless network. The AccessPoint supports 
802.1x for keeping out unauthorized users and for verifying the credentials of users with 
RADIUS so that authorized users can access the network and services. 
 

 

 

To use 802.1x, you will need at least one common Extensible 
Authentication Protocol (EAP) method on your authentication 
server, APs (authenticator) and stations (supplicant). 802.1x is 
also used to perform generation and distribution of encryption 
keys from AP to the station as part of or after the authentication 
process. A further factor here is dynamic WEP, which is based 
on legacy RC4 WEP encryption and is available in this Ac-
cessPoint under the setting for enabling 802.1x security in as-
sociation with disabled Wired Equivalent Privacy (WEP) set-
tings. There are two options for the key length, i.e. 40 and 104 
bits. The longer the key length, the greater security it will offer. 
 

 

802.1x and Radius Server: 

An 802.1x client needs to be 
combined with a Radius server. 
The server acts as an authenti-
cation authority, the Access-
Point as an authenticator and 
the client as supplicant. 
Windows XP already comes 
with integrated 802.1x capabili-
ties and can therefore be used 
directly in combination with a 
Radius server. 
  

APPLICATION 

Содержание CONNECT2AIR WLAN AP-600RP-USB

Страница 1: ......

Страница 2: ...ents of this publication may not in part or in full be reproduced stored transcribed in an information retrieval system translated into any language or transmitted in any form or by any means be it me...

Страница 3: ...e separation between the equipment and receiver Connect the equipment to an outlet on a different circuit to that on which the receiver is connected Consult the dealer or an experienced radio TV techn...

Страница 4: ...USB with ADSL Modem 18 6 4 AP 600RP USB with CABLE Modem 19 6 5 Two AP 600RP USB in repetition mode WDS 20 7 SOFTWARE INSTALLATION 21 7 1 Install AP Start up Tool 21 7 2 User Manual 21 8 ACCESSPOINT...

Страница 5: ...8 5 2 Firewall 46 8 5 3 Time Zone 52 8 5 4 DMZ 52 8 6 Toolbox 53 8 6 1 Administrator Toolbox 53 8 6 2 Firmware Upgrade 53 9 ACCESS TO USB PRINTERS THROUGH WLAN 54 9 1 Configuration on Windows 2000 XP...

Страница 6: ...ll and use this product please read this manual carefully to ensure that you take full advantage of its functionality 1 1 Five steps to success To enable smooth entry into the world of wireless LAN yo...

Страница 7: ...stallation to help you to connect these devices properly Prepare your PCs and devices to connect to the AccessPoint Before an AccessPoint can be configured an initial connection must be established Se...

Страница 8: ...clients Printer sharing wireless printing Integrated printer server to allow wireless printing for each networked computer see the list of compatible printers on the Internet DHCP server support All...

Страница 9: ...ample 5 4 Mbps in 802 11g networks 3 1 IEEE Standards In order to guarantee a consistent and complete transmission of information from and to a source target WLAN device the manner of transmitting dat...

Страница 10: ...ge of one AccessPoint it moves into the range of another As a result wireless clients can freely roam from one AccessPoint domain to another and still maintain seamless network connectivity 3 3 Servic...

Страница 11: ...ry defaults please follow the steps 1 Press the reset button and hold it for more than 10 seconds 2 Release the button 3 After every LED has flashed more than one time and only the LEDs related to a s...

Страница 12: ...s cable the AP can automatically detect either b Wireless LAN connection Move the AP to a proper position to ensure the best transmission performance Figure 4 3 Setup of the AP s LAN and WAN connectio...

Страница 13: ...r ISP More precisely an IP address consists of a set of four numbers each 3 digits long and separated by a decimal point for example 192 168 100 200 These addresses can be set manually or be received...

Страница 14: ...ies button Click the IP Address tab Select Obtain an IP Address automatically 5 Click the Gateway tab Clear and remove all of the gateway settings Click the OK button L All the necessary settings incl...

Страница 15: ...ping 192 168 1 254 If a communication link between your computer and the AccessPoint has been established successfully the output will show four replies from your AP L If your request timed out no con...

Страница 16: ...s and helps you in configuring your AccessPoint as well as other devices in the network like ADSL Routers Inexperienced users and professionals will the information they require according to their kno...

Страница 17: ...o one of the LAN port not to the WAN port Additional network ing devices like network printers servers or scanners can be plugged to one of the free LAN ports and will be integrated in the IP segment...

Страница 18: ...th the AccessPoint as well as the ADSL Router have routing capabilities This case de scribes using both devices in the router mode in order to have the full feature set of the AccessPoint active like...

Страница 19: ...de vices like network printers servers or scanners can be plugged into one of the free LAN ports and will be integrated in the IP segment of 192 168 1 X Installation Note Most broadband Internet conn...

Страница 20: ...CABLE Modem to the WAN port Additional networking devices like network printers servers or scanners can be plugged into one of the free LAN ports and will be integrated in the IP segment of 192 168 1...

Страница 21: ...AP 600RP USB AP 600RP USB Floor 1 AP 600RP USB Floor 2 Connect the ADSL Modem to the WAN port of the AP1 otherwise the PPPoE session cannot be established and therefore the Internet service cannot be...

Страница 22: ...shown on the left side and then AP 600RP USB You can then choose from the various options appearing on the right side of the panel 7 1 Install AP Start up Tool The AccessPoint start up tool will autom...

Страница 23: ...he AccessPoint Start up Tool on your desktop or from Start Programs CONNECT2AIR WLAN AP 600RP USB ConfigStarter Activate your browser directly and type in the IP address of your AP in the Address fiel...

Страница 24: ...will be displayed as well as the connection type Local Area Network LAN The IP address DHCP server and the firewall status are displayed Wireless Settings WLAN If enhanced security has been set it wi...

Страница 25: ...der ISP It is vitally important that you read this chapter carefully in order to choose the right settings to connect to your ISP Internet Service Provider As described in the hardware installation yo...

Страница 26: ...assigned to you For security this field appears blank If you don t want to change the password leave it empty MAC address If a specific MAC address is to be mirrored to the ISP only for the dura tion...

Страница 27: ...not be disconnected i e the connection is permanent PPPoE Timeout The time of inactivity before disconnecting your PPPoE session Minimum value is 60 seconds No input is possible if Disconnect PPPOE Se...

Страница 28: ...tings Without an ISP If you wish to use the device purely as an AccessPoint i e without connection to a provider select this option The routing functionality is disabled as a consequence The AccessPoi...

Страница 29: ...802 11b devices 54 Mbps only cards com municate with each other at the high data rate L Note Because dramatic reductions in throughput will result from simply attaching legacy 802 11b clients to the 8...

Страница 30: ...difficult to memorize this de vice offers a conversion utility from a simple word into the hexadecimal code Click the key you want to update enter your passphrase and press Generate Keys The key is t...

Страница 31: ...address of this device The computers in your network must use this LAN IP address as their default gateway Subnet Mask Defines the size of the subnet mask range 255 255 255 0 default permits an addre...

Страница 32: ...her within the address range 192 168 1 X Gateway The gateway represents the connection and exchange node AccessPoint through which IP networks are connected together For connections to a different net...

Страница 33: ...been dis abled 8 4 5 DNS Settings As an alternative to the DNS address copied from the provider a manual DNS address can be provided to the clients through the DHCP server The AP 600RP does not have...

Страница 34: ...fferent WAN types are described in Section 8 3 1 You can clone a MAC address by copying a specific address to the field and pressing Save Alternatively you can click on Clone MAC Address to have the M...

Страница 35: ...802 11b devices 54 Mbps only cards com municate with each other at the high data rate L Note Because dramatic reductions in throughput will result from simply attaching legacy 802 11b clients to the 8...

Страница 36: ...encrypted at the source and decrypted at the destination Two types of encryption are available within this device WEP Wired Equivalent Privacy and dynamic WEP with periodically changing keys WPA Wi F...

Страница 37: ...ore needed at different levels of the AP s graphical user inter face GUI 8 4 9 Security begins when Changing the Standard Password The security of your WLAN begins when changing the standard password...

Страница 38: ...rase and press Generate Keys The key is then updated Proceed likewise with the other three keys if necessary Manual entry of the keys in the client is recommended Once the WEP security settings are co...

Страница 39: ...e provided no third party knows of it WPA Enterprise Mode Companies employing RADIUS based authentication can use WPA with 802 1x WPA EAP enterprise mode An EAP ex tensible authentication protocol is...

Страница 40: ...d distribution of encryption keys from AP to the station as part of or after the authentication process A further factor here is dynamic WEP which is based on legacy RC4 WEP encryption and is availabl...

Страница 41: ...a must do to accommodate the recently introduced Wi Fi Protected Access WPA EAP to wireless networks Setting up RADIUS information in your AccessPoint is quite simple just input the relevant IP addres...

Страница 42: ...vate MAC address control All of the settings on this page will only take effect when Enable is ticked Note that all settings made to the AP are stored if you disable MAC address control The following...

Страница 43: ...ynamic DNS The DDNS service enables you to access a local server in the LAN WLAN from the Inter net The service connects a static host name e g MyWebcam dyndns org with the dy namic IP address of the...

Страница 44: ...mmunication and control motor zoom These must be added to the virtual server using Add The WEBcam can only be accessed over the Internet in this way As a result all IP packets with port 80 or 7070 at...

Страница 45: ...ll then be listed in the table Assign a name to it in order to have it properly identified and press Save Repeat the pro cedure for all items The WDS link cannot be set up until all items have been co...

Страница 46: ...sible Service Function TCP UDP AUTH Authentication Service 113 113 BOOTPC Bootstrap Protocol Client 67 DNS Domain Name Server 53 FTP File Transfer Protocol 21 HTTP Hyper Text Transfer Protocol 80 NETB...

Страница 47: ...Point itself saves the data regarding the true identity of a message and can forward a reply from the Internet to the proper source if necessary Increased firewall protection by closing the ports The...

Страница 48: ...ll In accordance with the source or destination of data the AccessPoint can accept or reject the data traffic Input Data traffic with the AccessPoint as destination Output Data traffic with the Access...

Страница 49: ...ddress specifies the destination A rule can be used either for a particular address for example 192 168 1 100 or includes all IP addresses if All is selected Generally a rule applies to all protocols...

Страница 50: ...ed for the function In order to be able to configure an AccessPoint over the Internet WAN port the firewall must be activated Initially the firewall is fully open i e it does not block any data traffi...

Страница 51: ...ined for this purpose RULE 3 PC 2 in the Internet 192 35 35 10 with destination AP 600RP 212 35 65 205 ist allowed to ping and configure the AP Incoming data at the AP RULE 4 Data with AP 600RP as the...

Страница 52: ...ping OK What effects do these settings have with regard to the security of your network environ ment The firewall is activated there is generally no connection between the local and public networks pr...

Страница 53: ...ce Provider the clock cannot be adjusted 8 5 4 DMZ The Demilitarized Zone DMZ is used if you have received more than one fixed IP ad dress from your Internet Service Provider ISP This means that the A...

Страница 54: ...tem settings for the AccessPoint can be saved in a file for input into the device at a later stage again if necessary For example if you accidentally exclude yourself using the ACL Access Control List...

Страница 55: ...0 will continue to be so with future releases e g version 7 4 Multipurpose printing devices with integrated fax or scanner are only supported in certain conditions at the USB port of the AccessPoint A...

Страница 56: ...en Standard TCP IP Port and press Next 5 Press Next Step 6 Step 7 6 Add the AccessPoints IP address in the first field Default value of the AP 600RP USB is 192 168 1 254 The port name will be generate...

Страница 57: ...your connected printer If it is not listed use the CD ROM delivered with the device Press Next 11 Keep or change the listed printer name and press Next Step 12 Step 13 12 Tick Yes to have a test page...

Страница 58: ...f the object code under the following address http www fujitsu siemens com wireless No Warranty The free software included in this product is distributed in the hope that it will be useful but WITHOUT...

Страница 59: ...uced by others will not reflect on the original authors reputations Finally any free program is threatened constantly by software patents We wish to avoid the danger that redistributors of a free prog...

Страница 60: ...modified work as a whole If identifiable sections of that work are not derived from the Program and can be reasonably considered inde pendent and separate works in themselves then this License and it...

Страница 61: ...ibute the Program or its derivative works These actions are prohibited by law if you do not accept this License There fore by modifying or distributing the Program or any work based on the Program you...

Страница 62: ...f the Program does not specify a version number of this License you may choose any version ever published by the Free Soft ware Foundation 10 If you wish to incorporate parts of the Program into other...

Страница 63: ...CONNECT2AIR WLAN AP 600RP USB Page 62 62 ANY OTHER PROGRAMS EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES END OF TERMS AND CONDITIONS...

Отзывы: