EasyManua.ls Logo

D-Link DWL-3600AP - Ieee 802.1 X; Static WEP Rules; Table 24: IEEE 802.1 X

D-Link DWL-3600AP
183 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
VirtualAccessPointSettings
D-Link UnifiedAccessPointAdministratorsGuide
November2011 Page76
UnifiedAccessPointAdministratorsGuide
StaticWEPRules
IfyouuseStaticWEP,thefollowingrulesapply:
•AllclientstationsmusthavetheWirelessLAN(WLAN)securitysettoWEP,andallclientsmusthaveoneof
theWEPkeysspecifiedontheAPinordertodecodeAPtostationdatatransmissions.
•TheAPmusthaveallkeys
usedbyclientsforstationtoAPtransmitsothatitcandecodethestation
transmissions.
•Thesamekeymustoccupythesameslotonallnodes(APandclients).ForexampleiftheAPdefines
abc123keyasWEPkey3,thentheclientstationsmustdefinethatsame
stringasWEPkey3.
•Clientstationscanusedifferentkeystotransmitdatatotheaccesspoint.(Ortheycanallusethesame
key ,butthisislesssecurebecauseitmeansonestationcandecryptthedatabeingsentbyanother.)
•Onsomewirelessclientsoftware,youcan
configuremultipleWEPkeysanddefineaclientstation
“transferkeyindex”,andthensetthestationstoencryptthedatatheytransmitusingdifferentkeys.This
ensuresthatneighboringAPscannotdecodeeachotherstransmissions.
•Youcannotmix64bitand128bitWEPkeysbetweentheaccesspointand
itsclientstations.
IEEE802.1X
IEEE802.1Xisthestandarddefiningportbasedauthenticationandinfrastructurefordoingkeymanagement.
ExtensibleAuthenticationProtocol( EAP)messagessentoveranIEEE802.11wirelessnetworkusingaprotocol
calledEAPEncapsulationOverLANs(EAPOL).IEEE802.1Xprovidesdynamicallygenerate dkeysthatare
periodicallyrefreshed.AnRC4streamcipher
isusedtoencrypttheframebodyandcyclicredundancychecking
(CRC)ofeach802.11frame.
ThismoderequirestheuseofanexternalRADIUSservertoauthenticateusers.TheAPrequiresaRADIUS
servercapableofEAP,suchastheMicrosoftInternetAuthenticationServer.ToworkwithWindowsclients,
the
authenticationservermustsupportProtectedEAP(PEAP)andMSCHAPV2.
YoucanuseanyofavarietyofauthenticationmethodsthattheIEEE802.1Xmodesupports,including
certificates,Kerberos,andpublickeyauthentication.Youmustconfiguretheclientstationstousethesame
authenticationmethodtheAPuses.
Table24:
IEEE802.1X
Field Description
UseGlobalRADIUS
ServerSettings
BydefaulteachVAPusestheglobalRADIUSsettingsthatyoudefinefortheAPatthetop
oftheVAPpage.However,youcanconfigureeachVAPtouseadifferentsetofRADIUS
servers.
TousetheglobalRADIUSserversettings,makesurethe
checkboxisselected.
TouseaseparateRADIUSserverfortheVAP ,clearthecheckboxandentertheRADIUS
serverIPaddres sandkeyinthefollowingfields.
RADIUSIPAddress
Type
SpecifytheIPversionthattheRADIUSserveruses.
Youcantogglebetweentheaddresstypestoconfigure
IPv4andIPv6globalRADIUS
addresssettings,buttheAPcontactsonlytheRADIUSserverorserversfortheaddress
typeyouselectinthisfield.

Table of Contents

Other manuals for D-Link DWL-3600AP

Related product manuals