background image

52

Appendix B: Wireless Security
Security Threats Facing Wireless Networks

Dual-Band Wireless Access Point

WPA Pre-Shared Key

. If you do not have a RADIUS server, select the type of algorithm, TKIP or AES, enter a 

password in the Pre-Shared key field of 8-64 characters, and enter a Group Key Renewal period time 
between 0 and 99,999 seconds, which instructs the Router or other device how often it should change the 
encryption keys.

WPA RADIUS

. WPA used in coordination with a RADIUS server. (This should only be used when a RADIUS 

server is connected to the Router or other device.) First, select the type of WPA algorithm, 

TKIP

 or 

AES

. Enter 

the RADIUS server’s IP Address and port number, along with a key shared between the device and the server. 
Last, enter a Group Key Renewal period, which instructs the device how often it should change the encryption 
keys.

RADIUS

. WEP used in coordination with a RADIUS server. (This should only be used when a RADIUS server is 

connected to the Router or other device.) First, enter the RADIUS server’s IP Address and port number, along 
with a key shared between the device and the server. Then, select a WEP key and a level of WEP encryption, 
and either generate a WEP key through the Passphrase or enter the WEP key manually.

Implementing encryption may have a negative impact on your network’s performance, but if you are transmitting 
sensitive data over your network, encryption should be used. 

These security recommendations should help keep your mind at ease while you are enjoying the most flexible 
and convenient technology Linksys has to offer.

Содержание WAP54G v2

Страница 1: ...A Division of Cisco Systems Inc Model No Access Point Wireless G WAP54G v2 User Guide WIRELESS GHz 2 4802 11g ...

Страница 2: ...ng this guide In addition to these symbols there are definitions for technical terms that are presented like this Also each figure diagram screenshot or other image is provided with a figure number and description like this Figure numbers and descriptions can also be found in the List of Figures section in the Table of Contents This exclamation point means there is a Caution or warning and is some...

Страница 3: ...on 8 Chapter 5 Setting Up the Wireless G Access Point 9 Setup Wizard 9 Linksys Wireless Guard Setup 15 Chapter 6 Linksys Wireless Guard 18 Client Software Installation 18 Network Access 21 Your Account 22 Chapter 7 Configuring the Wireless G Access Point 29 Overview 29 Navigating the Utility 30 Accessing the Utility 31 The Setup Tab 32 The Status Tab 40 The Advanced Tab 41 The Help Tab 45 Appendix...

Страница 4: ...int Appendix C Upgrading Firmware 53 Appendix D Windows Help 54 Appendix E Glossary 55 Appendix F Specifications 59 Appendix G Warranty Information 61 Appendix H Regulatory Information 62 Appendix I Contact Information 64 ...

Страница 5: ...5 9 The WPA PSK Screen 13 Figure 5 10 The Congratulations Screen 14 Figure 5 11 The Attention Screen 15 Figure 5 12 The Linksys Wireless Guard Setup Screen 15 Figure 5 13 The Securing your Access Point Screen 16 Figure 5 14 Note the New Password Screen 16 Figure 5 15 The Adding Authorized Users Screen 17 Figure 5 16 The Congratulations Screen 17 Figure 6 1 Note 18 Figure 6 2 Configuring Windows In...

Страница 6: ...Setup Screen 32 Figure 7 3 WPA Pre Shared Key Settings 34 Figure 7 4 WPA Radius Settings 34 Figure 7 5 Radius Settings 35 Figure 7 6 WEP Settings 35 Figure 7 7 The Password Screen 36 Figure 7 8 The AP Mode Screen 37 Figure 7 9 The Site Survey screen 37 Figure 7 10 Wireless Repeater diagram 38 Figure 7 11 Wireless Bridge diagram 38 Figure 7 12 The Log screen 39 Figure 7 13 The Status Screen 40 Figu...

Страница 7: ...a Network They are connected with Ethernet cables which is why the network is called wired PCs equipped with wireless cards and adapters can communicate without cumbersome cables By sharing the same wireless settings within their transmission radius they form a wireless network This is sometimes called a WLAN or Wired Local Area Network The Access Point bridges wireless networks of both 802 11g an...

Страница 8: ...s on the Access Point and how to install the setup on the Access Point for the Linksys Wireless Guard Chapter 6 The Linksys Wireless Guard This chapter explains how to install the client software for Linksys Wireless Guard and other information on the service Chapter 7 Configuring the Wireless G Access Point This chapter explains the use of the Access Point s Web based Utility Appendix A Troublesh...

Страница 9: ...l specifications Appendix G Warranty Information This appendix supplies the Access Point s warranty information Appendix H Regulatory Information This appendix supplies the Access Point s regulatory information Appendix I Contact Information This appendix provides contact information for a variety of Linksys resources including Technical Support ...

Страница 10: ... a wired network and may double the effective wireless transmission range for two wireless adapter PCs Since an access point is able to forward data within a network the effective transmission range in an infrastructure network may be doubled Roaming Infrastructure mode also supports roaming capabilities for mobile users Roaming means that you can move your wireless PC within your network and the ...

Страница 11: ...pters such at the PC Cards for your laptop computers PCI Card for your desktop PC and USB Adapters for when you want to enjoy USB connectivity These wireless products can also communicate with a 802 11g or 802 11b wireless PrintServer When you wish to connect your wired network with your wireless network the Access Point s network port can be used to connect to any of Linksys s switches or routers...

Страница 12: ...aults Either press the Reset Button for approximately ten seconds or restore the defaults from the Password tab in the Access Point s Web Based Utility With these and many other Linksys products your networking options are limitless Go to the Linksys website at www linksys com for more information about products that work with the Access Point Important Resetting the Access Point will erase all of...

Страница 13: ...yed are located on the front panel Power Green The Power LED lights up when the Access Point is powered on Act Green If the Act LED is flickering the Access Point is actively sending or receiving data to or from one of the devices over the LAN port Link Green The Link LED lights whenever the Access Point is successfully connected to a device through the LAN port Figure 3 2 Front Panel ...

Страница 14: ... your 10 100 Network 4 Connect the AC Power Adapter to the Access Point s Power Socket Only use the power adapter supplied with the Access Point Use of a different adapter may result in product damage Now that the hardware installation is complete proceed to Chapter 5 Setting Up the Wireless G Access Point for directions on how to set up the Access Point tcp ip a set of instructions PCs use to com...

Страница 15: ...not this means the Setup Wizard is not automatically running as it should Start the Setup Wizard manually by clicking the Start button selecting Run and typing d setup exe where D is your PC s CD ROM drive Click the Setup button to continue this Setup Wizard Clicking the User Guide button opened this Guide To exit this Setup Wizard click the Exit button Figure 5 1 The Setup Wizard s Welcome Screen...

Страница 16: ...ontinue or Exit to exit the Setup Wizard 4 The Setup Wizard will run a search for the Access Point within your network and then display a list along with the status information for each access point If this is the only access point on your network it will be the only one displayed If there are more than one displayed select the Access Point by clicking on it and click the Yes button to continue or...

Страница 17: ...t button to continue or Back to return to the previous page IP Address This IP address must be unique to your network The default IP address is 192 168 1 245 Subnet Mask The Access Point s Subnet Mask must be the same as your Ethernet network Gateway This IP address should be the IP address of the gateway device that allows for contact between the Internet and the local network Figure 5 4 Enter th...

Страница 18: ...acters which may be any keyboard character Make sure this setting is the same for all points in your wireless network Channel Select the appropriate channel from the list provided to correspond with your network settings between 1 and 11 All points in your wireless network must use the same channel in order to function correctly Device Name The Device Name is a unique name given to the Access Poin...

Страница 19: ...2 characters WPA Enterprise This option is for corporate wireless networks only and uses a special authentication server To choose this option select Disable You will need to enable the option in the web based utility Refer to Chapter 7 Configuring the Wireless G Access Point Linksys Wireless Guard With this subscription service you get the highest security of WPA RADIUS but without having to buil...

Страница 20: ...tion performed with the Setup Wizard is complete To configure any other Access Points in your network you can run this Setup Wizard again Click the Exit button to exit the Setup Wizard For more advanced configuration you can go to Chapter 7 Configuring the Wireless G Access Point Figure 5 10 The Congratulations Screen ...

Страница 21: ...ugh a broadband connection DSL cable other If you meet these requirements click Continue to sign up for the Linksys Wireless Guard service or click Cancel to cancel the setup 2 This screen guides you through the registration process Enter your user name password first and last name E mail address and a security question and answer below Then click Next to continue or Exit if you want to quit the S...

Страница 22: ...ke sure that the SSID is correct Click Next to add this Access Point to your network or click Back to return to the previous screen 4 For security reasons the password has been automatically changed Please note the new password before continuing or you won t be able to access the Access Point later After writing down the new password select I have noted the new password then click OK Figure 5 13 T...

Страница 23: ...om the list select the user then click Remove 6 The Access Point is now configured for Linksys Wireless Guard To finish configuring your wireless network you will need to install the Linksys Wireless Guard client software for each PC that will have access Click Main Menu then click Linksys Wireless Guard Client To add more Access Points to your Linksys Wireless Guard network run the Linksys Wirele...

Страница 24: ...cess your protected network and manage your account Client Software Installation 1 If you haven t already done so on the Main Menu of the Setup CD ROM click Linksys Wireless Guard Client The screen in Figure 6 1 will appear To install the software on this PC click Continue Click Cancel to cancel the installation 2 A screen will appear to notify you that the setup is in process Wait until the next ...

Страница 25: ...f no other applications are open click Next fo continue If you want to exit to close your other applications click Cancel 4 A license agreement will appear next Scroll down or press PAGE DOWN to read the entire agreement To accept the terms and continue the installation click Yes To quit the installation Click No Figure 6 3 Exit Applications Figure 6 4 License Agreement ...

Страница 26: ... click Next If you want to choose a different location for the folder click the Browse button and select the location Click Back to return to the previous screen Click Cancel to cancel the installation 6 The program files will start copying Click Next to continue Click Back to return to the previous screen Click Cancel to cancel the installation Figure 6 5 Destination Location Figure 6 6 Copying F...

Страница 27: ...uard Network Access After Linksys Wireless Guard is installed any time you access a Linksys Wireless Guard protected network this screen will appear To access your network click Login as a Wireless Guard Member or if you are a guest click Login as a Wireless Guard Guest Enter your user name and password then click Login Login as a Wireless Guard Member Select this option if you are a registered me...

Страница 28: ... key icon then click View Membership and Network Administraton Website to log in to the Linksys Wireless Guard website You can also click on your computer s Start button select the Linksys Wireless Guard folder then click Membership and Network Administration Website 1 The screen in Figure 6 9 will appear Enter the administrator s user name and password in the fields Click Login 2 The Wireless Gua...

Страница 29: ...ccess Point Add a Guest 1 On the Wireless Guard Member Website home screen Figure 6 10 click the Network Admin tab 2 The screen in Figure 6 11 will appear Under Network Administration click Modify Access Control Figure 6 10 Home Figure 6 11 Network Administration ...

Страница 30: ...of the guest you want to add Guest Last Name The last name of the guest you want to add Password Enter a password that s at least six characters for the guest you want to add Password Verify Enter the password again Access Duration Enter the length of time that the guest will be on the network in hours 5 The guest will need to install the Linksys Wireless Guard Client software on his PC The softwa...

Страница 31: ...ecurity is lost select Permission to Initiate Network Fallback When finished click Submit To register as a member for Linksys Wireless Guard refer to the following instructions then when finished with registration return to this screen The member will need to install the Linksys Wireless Guard Client software on his PC The software can be downloaded from the Setup CD ROM or from Linksys com suppor...

Страница 32: ...member registration 4 When the next screen appears choose who will be paying for the account If the new member will be paying for the account click I will pay for my own subscription I will enter my billing information on the web site later If the administrator will be paying for the account click Another member will be paying for my subscription Click Next Click Back to return to the previous scr...

Страница 33: ...ick Next to continue Click Back to return to the previous screen Click Cancel to cancel the member registration 6 When the congratulations screen appears you will be successfully registered for Linksys Wireless Guard Click Finish 7 You should now ask the administrator to add you to his Wireless Guard Protected Network s Access Control List To do so The network administrator needs to return to the ...

Страница 34: ...work you won t have to manually re secure the network connection Linksys Wireless Guard will recognize it and automatically reinstate security To unprotect a network Right click on the green Wireless Guard Network key icon on the right side of the system tray at the bottom of your screen Select Unprotect this Network Connection from the menu When the screen asks if you re sure you want to unprotec...

Страница 35: ...Navigator through use of a computer connected with an Ethernet cable to the Access Point For a basic network setup most users only have to use the following screens of the Utility Basic Setup On the Basic Setup screen enter your basic network settings here Password Click the Setup tab and then select the Password screen The Access Point s default password is admin To secure the Access Point change...

Страница 36: ... will work with other access points in your network Log You can view or save even email activity logs from this screen Status This screen will display current information on the Access Point its settings and its performance Advanced Filters From this screen you can allow or prevent access to your network Advanced Wireless From this screen you can configure the Access Point s more advanced wireless...

Страница 37: ...ress you entered in the Setup Wizard The default IP address is 192 168 1 245 Should you need to learn what IP Address the Access Point presently uses run the Setup Wizard again It will scan the Access Point and give you its IP Address Press the Enter key and the following screen will appear Leave the User Name field blank The first time you open the Web Based Utility use the default password admin...

Страница 38: ...guration DHCP if your ISP assigns IP addresses via a DHCP server The following fields apply ONLY when the Static IP Address option is selected IP Address The IP address must be unique to your network We suggest you use the default IP address of 192 168 1 245 This is a private IP address so there is no need to purchase a separate IP address from your service provider Subnet Mask The Subnet Mask mus...

Страница 39: ...ake sure that you disable it when you are finished With this enabled someone could easily obtain the SSID information with site survey software and gain unauthorized access to your network Click Enable to broadcast the SSID to all wireless devices in range Click Disable to increase network security and prevent the SSID from being seen on networked PCs Channel Select the appropriate channel from th...

Страница 40: ... enter a Group Key Renewal period which instructs the Access Point how often it should change the encryption keys WPA RADIUS This option features WPA used in coordination with a RADIUS server This should only be used when a RADIUS server is connected to the Access Point First select the type of WPA algorithm you want to use TKIP or AES Enter the RADIUS server s IP Address and port number along wit...

Страница 41: ...basic encryption method which is not as secure as WPA To use WEP select a Default Transmit Key choose which Key to use and a level of WEP encryption 64 bits 10 hex digits or 128 bits 26 hex digits Then either generate a WEP key using the Passphrase or enter the WEP key manually Change these settings as described here and click the Save Settings button to apply your changes or Cancel Changes to can...

Страница 42: ...o the AP Password field Then type it again into the second field to confirm To restore the Access Point s factory default settings click the Yes button beside Restore Factory Defaults To back up your Access Point configuration click the Backup button To restore the backed up configuration click the Restore button Click the Save Settings button to apply your changes or Cancel Changes to cancel your...

Страница 43: ...a remote access point The Access Point Client cannot communicate directly with any wireless clients A separate network attached to the Access Point Client can then be wirelessly bridged to the remote access point Enter the required LAN MAC address of the remote access point in the Remote AP MAC Address field To select an available access point click the Site Survey button and choose from the acces...

Страница 44: ...wired networks with two access points To configure a Wireless Bridge environment click Wireless Bridge and enter the LAN MAC address of the remote access point in the Remote Bridge MAC Address field The remote access point also needs to be set up as a Wireless Bridge Click the Save Changes button to apply your changes or Cancel Changes to cancel your changes If you require online help click the He...

Страница 45: ...hen you can designate a PC that will receive permanent log files periodically In the Send Log to field enter the IP address of this PC To view these permanent logs you must use Logviewer software which can be downloaded free of charge from www linksys com To see a temporary log of the Access Point s most recent activities click the View Log button Click the Save Changes button to apply your change...

Страница 46: ...ess Point is using a Subnet Mask it is shown here MAC Address The MAC Address of the LAN interface is displayed here SSID The unique name shared among all points in your wireless network is displayed here Mode The Access Point s mode is displayed here Channel The wireless channel shared by all wireless devices connected to this Access Point is displayed here Wireless Security The encryption method...

Страница 47: ...this button will block wireless access by MAC Address Permit Only Clicking this button will allow wireless access by MAC Address Edit MAC Address Filter List Clicking this button will open the MAC Address Filter List On this screen you can list users by MAC Address to whom you wish to provide or block access For easy reference click the Wireless Client MAC List button to display a list of network ...

Страница 48: ...t a series of rates advertising to the other wireless devices in your network at what rates the Access Point can transmit At the Default setting the Access Point will advertise that it will automatically select the best rate for transmission Other options of rates to advertise are 1 2Mbps for use with older wireless technology and All when you wish to make all rates advertised The Basic Rate is no...

Страница 49: ...recommended DTIM Interval This value indicates how often the Access Point sends out a Delivery Traffic Indication Message Lower settings result in more efficient networking while preventing your PC from dropping into power saving sleep mode Higher settings allow your PC to enter sleep mode thus saving power but interferes with wireless transmissions When you ve completed making any changes on this...

Страница 50: ... Enable Otherwise select Disable Identification In the Contact field enter contact information for the Access Point In the Device Name field enter the name of the Access Point In the Location field specify the area or location where the Access Point resides SNMP Community You may change the name from its default Public Enter a new name in the Public field Then configure the community s access as e...

Страница 51: ...ternet connection To download from the CD ROM click the Start button and select Run Type D Acrobat if D is the letter of your CD ROM drive New firmware versions are posted at www linksys com and can be downloaded for free If the Access Point is not experiencing difficulties then there is no need to download a more recent firmware version unless that version has a new feature that you want to use L...

Страница 52: ...er guide to determine if it supports operation over a network Can I play multiplayer games with other users of the wireless network Yes as long as the game supports multiple players over a LAN local area network Refer to the game s user guide for more information What IEEE 802 11b features are supported The product supports the following IEEE 802 11 functions CSMA CA plus Acknowledge protocol Mult...

Страница 53: ...e As the user moves on the end node s RF transmitter regularly checks the system to determine whether it is in touch with the original Access Point or whether it should seek a new one When a node no longer receives acknowledgment from its original Access Point it undertakes a new search Upon finding a new Access Point it then re registers and the communication process continues What is ISM band Th...

Страница 54: ...re side the WLAN series offers the encryption function WEP to enhance security and access control Users can set it up depending upon their needs Can Linksys Wireless products support file and printer sharing Linksys Wireless products perform the same function as LAN products Therefore Linksys Wireless products can work with Netware Windows NT 2000 or other LAN operating systems to support printer ...

Страница 55: ...02 11a on channels 52 56 60 and 64 than on the lower channels Lastly check the Advanced tab of the Web Based Utility and make sure that FULL is selected in the Transmission Rate field Does the Access Point function as a firewall No The Access Point is only a bridge from wired Ethernet to wireless clients I have excellent signal strength but I cannot see my network WEP is probably enabled on the Ac...

Страница 56: ...e 7 Change the WEP encryption keys periodically To ensure network security steps one through five should be followed at least Security Threats Facing Wireless Networks Wireless networks are easy to find Hackers know that in order to join a wireless network wireless networking products first listen for beacon messages These messages can be easily decrypted and contain much of the network s informat...

Страница 57: ...ddresses This makes it harder for a hacker to access your network with a random MAC Address WEP Encryption Wired Equivalent Privacy WEP is often looked upon as a cure all for wireless security concerns This is overstating WEP s ability Again this can only provide enough security to make a hacker s job more difficult There are several ways that WEP can be maximized 1 Use the highest level of encryp...

Страница 58: ...g with a key shared between the device and the server Last enter a Group Key Renewal period which instructs the device how often it should change the encryption keys RADIUS WEP used in coordination with a RADIUS server This should only be used when a RADIUS server is connected to the Router or other device First enter the RADIUS server s IP Address and port number along with a key shared between t...

Страница 59: ...low these instructions 1 Download the firmware from Linksys s website at www linksys com 2 Click the Web Utility s Help tab and click the Upgrade Firmware button 3 From the Upgrade Firmware screen enter the location of the firmware s file or click the Browse button to find the file 4 Then click the Upgrade button to upgrade the firmware Figure C 1 Upgrade Firmware ...

Страница 60: ...otocol all PCs follow to communicate over a network This is true for wireless networks as well Your PCs will not be able to utilize wireless networking without having TCP IP enabled Windows Help provides complete instructions on enabling TCP IP Shared Resources If you wish to share printers folder or files over your network Windows Help provides complete instructions on utilizing shared resources ...

Страница 61: ...n capacity of a given device or network Beacon Interval Data transmitted on your wireless network that keeps the network synchronized Bit A binary digit Browser An application program that provides a way to look at and interact with all the information on the World Wide Web CSMA CA Carrier Sense Multiple Access Collision Avoidance A method of data transfer that is used to prevent data collisions C...

Страница 62: ...ns protocols Hardware The physical aspect of computers telecommunications and other information technology devices IEEE The Institute of Electrical and Electronics Engineers An independent institute that develops networking standards Infrastructure A wireless network that is bridged to a wired network via an access point IP Internet Protocol A protocol used to send data over a network IP Address T...

Страница 63: ...and control protocol Software Instructions for the computer A series of instructions that performs a particular task is called a program SOHO Small Office Home Office Market segment of professionals who work at home or in small offices Spread Spectrum Wideband radio frequency technique used for more reliable and secure data transmission SSID Service Set IDentifier Your wireless network s name Stat...

Страница 64: ...gy The physical layout of a network Upgrade To replace existing software or firmware with a newer version WEP Wired Equivalent Privacy A method of encrypting network data transmitted on a wireless network for greater security WPA Wi Fi Protected Access a wireless security protocol using TKIP Temporal Key Integrity Protocol encryption which can be used in conjunction with a RADIUS server ...

Страница 65: ...ns One 10 100 RJ 45 Port One Power Port One Reset Button Cabling Type UTP CAT 5 or better Data Rate Up to 54Mbps Transmit Power 15dBm LEDs Power Act Link Dimensions 7 31 x 1 88 x 6 88 L x W x H 186 mm x 48 mm x 175 mm Antenna Height 4 5 114 mm Unit Weight 15 oz 0 42 kg Power External 12V DC Certifications FCC Canada Operating Temp 0ºC to 40ºC 32ºF to 104ºF Storage Temp 20ºC to 70ºC 4ºF to 158ºF ...

Страница 66: ...60 Appendix F Specifications Wireless G Access Point Operating Humidity 10 to 85 Non Condensing Storage Humidity 5 to 90 Non Condensing ...

Страница 67: ... AND WARRANTIES INCLUDING ANY IMPLIED WARRANTY OF NON INFRINGEMENT ARE DISCLAIMED Some jurisdictions do not allow limitations on how long an implied warranty lasts so the above limitation may not apply to You This warranty gives You specific legal rights and You may also have other rights which vary by jurisdiction This warranty does not apply if the Product a has been altered except by Linksys b ...

Страница 68: ...cate the receiving antenna Increase the separation between the equipment or devices Connect the equipment to an outlet other than the receiver s Consult a dealer or an experienced radio TV technician for assistance FCC Radiation Exposure Statement This equipment complies with FCC radiation exposure limits set forth for an uncontrolled environment This equipment should be installed and operated wit...

Страница 69: ...essentielles et aux dispositions relatives à la directive 1999 5 EC Belgique Dans le cas d une utilisation privée à l extérieur d un bâtiment au dessus d un espace public aucun enregistrement n est nécessaire pour une distance de moins de 300m Pour une distance supérieure à 300m un enregistrement auprès de l IBPT est requise Pour une utilisation publique à l extérieur de bâtiments une licence de l...

Страница 70: ...ing with Linksys products Give our advice line a call at 800 546 5797 LINKSYS Or fax your request in to 949 823 3002 If you experience problems with any Linksys product you can call us at 800 326 7114 Don t wish to call You can e mail us at support linksys com If any Linksys product proves defective during its warranty period you can call the Linksys Return Merchandise Authorization department for...

Отзывы: