Security
4-78 Advanced Configuration
• Pre‐Authentication.IfPre‐Authenticationisenabled,aWPA2wirelessclientcanperforman
802.1Xauthenticationwithotherwirelessaccesspointsinitsrangewhenitisstillconnectedto
itscurrentwirelessaccesspoint.
TousePre‐Authentication,youmusthavethefollowing:
– WirelessnetworkadaptorsthatsupportWPA2.
–WindowsXPwirelessnetworkadaptordriversthatsupportthepassingofWPA2
capabilitiestoWindowsWirelessAutoConfiguration.
• Authentication
– OpenSystem(thedefaultsetting):SelectthisoptionifyouplantouseWPAor802.1xasa
securitymechanism.Ifyoudon’tsetupanyothersecuritymechanismontheaccess
point,
thenetworkhasnoprotectionandisopentoallusers.
– SharedKeysetstheaccesspointtouseWEPsharedkeys.Ifthisoptionisselected,you
mustconfigureatleastonekeyontheaccesspointandallclients.
– WPA(Wi‐FiProtectedAccess)isastandards‐based,
interoperablesecurityenhancement
thatstronglyincreasesthelevelofdataprotectionandaccesscontrolforexistingand
futurewirelessLANsystems.Itisderivedfromandwillbeforward‐compatiblewiththe
upcomingIEEE802.11istandard.WPAleveragesTKIP(TemporalKeyIntegrityProtocol)
fordataprotectionand802.1Xfora uthenticated
keymanagement.
– WPA‐PSK.UsesWPAkeymanagement,non‐rootaccesspoint/bridges andthe
authenticationserverauthenticatetoeachotherusinganEAPauthenticationmethod,and
thenon‐rootaccesspoint/bridgeandservergenerateapairwisemasterkey(PMK).Using
WPA,theservergeneratesthePMKdynamicallyandpassesit
totherootaccesspoint/
bridge.UsingWPA‐PSK,however,youconfigureapre‐sharedkeyonboththenon‐root
accesspoint/bridgeandtherootaccesspoint/bridge,andthatpre‐sharedkeyisusedas
thePMK.
– WPA2providesastrongerencryptionmechanismthroughAES,whichisarequirement
for
somecorporateandgovernmentusers.TKIP,theencryptionmechanisminWPA,
reliesonRC4insteadofTripleDataEncryptionStandard(3DES),AES,oranother
encryptionalgorithms.
– WPA‐WPA2‐MixedpermitsthecoexistenceofWPAandWPA2clientsonacommonSSID.
WPA2‐mixedmodeisaWi‐FiCertifiedfeature.
Theaccesspointadvertisesthe
encryptionciphers(TKIP,CCMP,other)thatareavailableforuse.Theclientselectsthe
encryptioncipheritwouldliketouse,andtheselectedencryptioncipherisusedfor
encryptionbetweentheclientandaccesspointonceitisselectedbytheclient.
• DataEncryptionenables
ordisablestheaccesspointtouseWEPsharedkeysfordata
encryption.Ifthisoptionisselected,youmustconfigureat
leastonekeyontheaccesspoint
andallclients.(Default:Disable
)
• WPAClientssetsthespecifiedradiointerfaceorVAPto:
– Required‐allowsonlyWPA‐enabled clientstoaccessthenetwork.
Note: To use 802.1x on wireless clients requires a network card driver and 802.1x
client software that supports the EAP authentication type that you want to use.
Windows XP provides native WPA support, other systems require additional software.
Note: You must enable WEP encryption in order to enable all types of encryption on the access
point; however, you do not need to define WEP keys for WPA.