VirtualAccessPointSettings
D-Link UnifiedAccessPointAdministrator’sGuide
November2011 Page76
UnifiedAccessPointAdministrator’sGuide
StaticWEPRules
IfyouuseStaticWEP,thefollowingrulesapply:
•AllclientstationsmusthavetheWirelessLAN(WLAN)securitysettoWEP,andallclientsmusthaveoneof
theWEPkeysspecifiedontheAPinordertode‐codeAP‐to‐stationdatatransmissions.
•TheAPmusthaveallkeys
usedbyclientsforstation‐to‐APtransmitsothatitcande‐codethestation
transmissions.
•Thesamekeymustoccupythesameslotonallnodes(APandclients).ForexampleiftheAPdefines
abc123keyasWEPkey3,thentheclientstationsmustdefinethatsame
stringasWEPkey3.
•Clientstationscanusedifferentkeystotransmitdatatotheaccesspoint.(Ortheycanallusethesame
key ,butthisislesssecurebecauseitmeansonestationcandecryptthedatabeingsentbyanother.)
•Onsomewirelessclientsoftware,youcan
configuremultipleWEPkeysanddefineaclientstation
“transferkeyindex”,andthensetthestationstoencryptthedatatheytransmitusingdifferentkeys.This
ensuresthatneighboringAPscannotdecodeeachother’stransmissions.
•Youcannotmix64‐bitand128‐bitWEPkeysbetweentheaccesspointand
itsclientstations.
IEEE802.1X
IEEE802.1Xisthestandarddefiningport‐basedauthenticationandinfrastructurefordoingkeymanagement.
ExtensibleAuthenticationProtocol( EAP)messagessentoveranIEEE802.11wirelessnetworkusingaprotocol
calledEAPEncapsulationOverLANs(EAPOL).IEEE802.1Xprovidesdynamically‐generate dkeysthatare
periodicallyrefreshed.AnRC4streamcipher
isusedtoencrypttheframebodyandcyclicredundancychecking
(CRC)ofeach802.11frame.
ThismoderequirestheuseofanexternalRADIUSservertoauthenticateusers.TheAPrequiresaRADIUS
servercapableofEAP,suchastheMicrosoftInternetAuthenticationServer.ToworkwithWindowsclients,
the
authenticationservermustsupportProtectedEAP(PEAP)andMSCHAPV2.
YoucanuseanyofavarietyofauthenticationmethodsthattheIEEE802.1Xmodesupports,including
certificates,Kerberos,andpublickeyauthentication.Youmustconfiguretheclientstationstousethesame
authenticationmethodtheAPuses.
Table24:
IEEE802.1X
Field Description
UseGlobalRADIUS
ServerSettings
BydefaulteachVAPusestheglobalRADIUSsettingsthatyoudefinefortheAPatthetop
oftheVAPpage.However,youcanconfigureeachVAPtouseadifferentsetofRADIUS
servers.
TousetheglobalRADIUSserversettings,makesurethe
checkboxisselected.
TouseaseparateRADIUSserverfortheVAP ,clearthecheckboxandentertheRADIUS
serverIPaddres sandkeyinthefollowingfields.
RADIUSIPAddress
Type
SpecifytheIPversionthattheRADIUSserveruses.
Youcantogglebetweentheaddresstypestoconfigure
IPv4andIPv6globalRADIUS
addresssettings,buttheAPcontactsonlytheRADIUSserverorserversfortheaddress
typeyouselectinthisfield.