Security
4-74 Advanced Configuration
Security
Theaccesspointisconfiguredbydefaultasan“opensystem,”whichbroadcastsabeaconsignal
includingtheconfiguredSSID.WirelessclientswithanSSIDsettingof“any”canreadtheSSID
fromthebeaconandautomaticallysettheirSSIDtoallowimmediateconnectiontothenearest
accesspoint.
Thesecurity
mechanismsthatyoumayemploydependuponthelevelofsecurityrequired,the
networkandmanagementresourcesavailable,andthesoftwaresupportprovidedonwireless
clients.Table 4‐7providesasummaryofwirelesssecurityconsiderations.
Table 4-7 Security Mechanisms
Security
Mechanism
Client Support Implementation Considerations
WEP Built-in support on all 802.11a,
802.11b, and 802.11g devices
Provides only basic security
Requires manual key management
WEP over
802.1x
Requires 802.1x client support
in system or by add-in software
(native support provided in
Windows XP and Windows 2000
via patch)
Provides dynamic key rotation for improved WEP
security
• Requires configured RADIUS server
• 802.1x EAP type may require management of
digital certificates for clients and server
AES (Advanced
Encryption
Standard)
802.11i ready Provides more robust wireless security.
MAC Address
Filtering
Uses the MAC address of client
network card
• Management of authorized MAC addresses
• Can be combined with other methods for improved
security
• Optionally configured RADIUS server
WPA over
802.1x mode
Requires WPA-enabled system
and network card driver
(native support provided in
Windows XP)
Provides robust security in WPA-only mode (for
example, WPA clients only)
• Offers support for legacy WEP clients, but with
increased security risk (for example, WEP
authentication keys disabled)
• Requires configured RADIUS server
• 802.1x EAP type may require management of
digital certificates for clients and server
WPA Pre-shared
key type
Requires WPA-enabled system
and network card driver
(native support provided in
Windows XP)
• Provides good security in small networks
• Requires manual management of pre-shared key
Note: Although a WEP static key is not needed for WEP over 802.1x, WPA over 802.1x, and WPA
PSK modes, you must enable WEP encryption through the Web or CLI in order to enable all types of
encryption in the access point.