5 - Configuration
DynaPro Go| Handheld PIN Pad Device with MSR/Contact/Contactless | Installation and Operation Manual
Page 27 of 60 (
D998200129-10
)
5.4
How to Configure Network Settings (ADVANCED)
This section and its subsections provide step-by-step instructions for configuring the 802.11 wireless
network, the device, and the host the device will connect to.
DynaPro Go can be configured to communicate with the host using 802.11 wireless in one of two ways:
•
In
Device Initiated
mode, the device will not listen for incoming connections, and instead expects to
initiate connections with the host on demand.
•
In
Always Listening
mode, the device keeps a TLS socket open that allows a single authenticated
host to connect.
In both cases, DynaPro Go 802.11 wireless network connections use TCP/IP protocol secured by
TLSv1.2 using x509 certificates, and the device enforces a requirement of mutual authentication between
the device and the host. If the host attempts to initiate an unauthenticated connection, the device will
refuse the connection and report
Configuration Error
on the display.
Both the device certificate and its corresponding private key are generated and injected by the
manufacturer. The private key cannot be accessed directly. MagTek provides the device’s CA certificate
chain to the customer for installation on the host.
5.4.1
How to Configure the Network to Support 802.11 Wireless Connections
When the device first connects to an 802.11 wireless network, it will attempt to contact a DHCP server to
acquire a dynamic IP address. If the device is unable to obtain an IP address from a DHCP server, it will
continuously report it is
Obtaining IP Address
.
To prepare the network for DynaPro Go and the host to communicate via the 802.11 wireless connection,
network and device administrators should do the following before deployment:
1)
. MagTek recommends performing these steps
before receiving the devices so the network will be ready when they arrive.
2)
Acquire or generate a TLSv1.2 certificate/key pair and certificate chain for the host. Certificates and
keys must be RSA 2048 bit, signature algorithm SHA-256RSA.
3)
Acquire the TLS Certificate Authority chain for DynaPro Go devices and install in Trusted Root
Certification Authorities
4)
The device can connect to only one access point. Test that there is adequate signal strength between
the access point and all locations where the device will operate wirelessly. In each location, open the
and make sure the Received Signal Strength Indicator level (
RSSI
) is
greater than or equal to
40
.