EasyManua.ls Logo

D-Link DWL-3600AP

D-Link DWL-3600AP
183 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
VirtualAccessPointSettings
D-Link UnifiedAccessPointAdministratorsGuide
November2011 Page76
UnifiedAccessPointAdministratorsGuide
StaticWEPRules
IfyouuseStaticWEP,thefollowingrulesapply:
•AllclientstationsmusthavetheWirelessLAN(WLAN)securitysettoWEP,andallclientsmusthaveoneof
theWEPkeysspecifiedontheAPinordertodecodeAPtostationdatatransmissions.
•TheAPmusthaveallkeys
usedbyclientsforstationtoAPtransmitsothatitcandecodethestation
transmissions.
•Thesamekeymustoccupythesameslotonallnodes(APandclients).ForexampleiftheAPdefines
abc123keyasWEPkey3,thentheclientstationsmustdefinethatsame
stringasWEPkey3.
•Clientstationscanusedifferentkeystotransmitdatatotheaccesspoint.(Ortheycanallusethesame
key ,butthisislesssecurebecauseitmeansonestationcandecryptthedatabeingsentbyanother.)
•Onsomewirelessclientsoftware,youcan
configuremultipleWEPkeysanddefineaclientstation
“transferkeyindex”,andthensetthestationstoencryptthedatatheytransmitusingdifferentkeys.This
ensuresthatneighboringAPscannotdecodeeachotherstransmissions.
•Youcannotmix64bitand128bitWEPkeysbetweentheaccesspointand
itsclientstations.
IEEE802.1X
IEEE802.1Xisthestandarddefiningportbasedauthenticationandinfrastructurefordoingkeymanagement.
ExtensibleAuthenticationProtocol( EAP)messagessentoveranIEEE802.11wirelessnetworkusingaprotocol
calledEAPEncapsulationOverLANs(EAPOL).IEEE802.1Xprovidesdynamicallygenerate dkeysthatare
periodicallyrefreshed.AnRC4streamcipher
isusedtoencrypttheframebodyandcyclicredundancychecking
(CRC)ofeach802.11frame.
ThismoderequirestheuseofanexternalRADIUSservertoauthenticateusers.TheAPrequiresaRADIUS
servercapableofEAP,suchastheMicrosoftInternetAuthenticationServer.ToworkwithWindowsclients,
the
authenticationservermustsupportProtectedEAP(PEAP)andMSCHAPV2.
YoucanuseanyofavarietyofauthenticationmethodsthattheIEEE802.1Xmodesupports,including
certificates,Kerberos,andpublickeyauthentication.Youmustconfiguretheclientstationstousethesame
authenticationmethodtheAPuses.
Table24:
IEEE802.1X
Field Description
UseGlobalRADIUS
ServerSettings
BydefaulteachVAPusestheglobalRADIUSsettingsthatyoudefinefortheAPatthetop
oftheVAPpage.However,youcanconfigureeachVAPtouseadifferentsetofRADIUS
servers.
TousetheglobalRADIUSserversettings,makesurethe
checkboxisselected.
TouseaseparateRADIUSserverfortheVAP ,clearthecheckboxandentertheRADIUS
serverIPaddres sandkeyinthefollowingfields.
RADIUSIPAddress
Type
SpecifytheIPversionthattheRADIUSserveruses.
Youcantogglebetweentheaddresstypestoconfigure
IPv4andIPv6globalRADIUS
addresssettings,buttheAPcontactsonlytheRADIUSserverorserversfortheaddress
typeyouselectinthisfield.

Table of Contents

Other manuals for D-Link DWL-3600AP

Related product manuals