EasyManua.ls Logo

Enterasys RoamAbout RBT-4102 - Page 115

Enterasys RoamAbout RBT-4102
160 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Security
RoamAbout RBT-4102 Wireless Access Point Configuration Guide 4-79
Supported‐allowsWPAenabled clientsandclientsonlycapableofsupportingWEPto
accessthenetwork.
WPAKeyManagement:YoucanconfigureWPAtoworkinanenterpriseenvironmentusing
IEEE802.1xandaRADIUSserverforuserauthentication.Forsmallernetworks,youcan
configureWPAusingacommonpre
sharedkeyforclientauthenticationwiththeaccess
point.
WPAauthenticationover802.1xsetsthisradiointerfaceorVAPtotheWPAenterprise
mode.ThismodeusesIEEE802.1xtoauthenticateusersandtodynamicallydistribute
encryptionkeystoclients.
WPAPresharedKeysetsthisradiointerfaceorVAP
totheWPAmodeforsmallnetworks.
Thismodeusesacommonpasswordstringthatismanuallydistributed.Youmust
configureallwirelessclientsassociatedwiththisradiointerfaceorVAPwiththe same
key.YoumustspecifythekeystringundertheWPAPreSharedKeyTypesectionof
the
SecuritySettingspage.
MulticastCipherModeselectsanencryptionmethodfortheglobalkeyusedformulticastand
broadcasttraffic,whichissupportedbyallwirelessclientsassociatedwiththisradiointerface
orVAP.
WEPspecifiesthatcommunicatingdevicesmustusethesameWEPkeytoencryptand
decryptradio
signals.WEPhasmanysecurityflaws,andisnotrecommendedfor
transmittinghighlysensitivedata.
TKIPprovidesdataencryptionenhancementsincludingperpacketkeyhashing(thatis,
changingtheencryptionkeyoneachpacket),amessageintegritycheck,anextended
initializationvectorwithsequencingrules,andarekeyingmechanism.
AESdesignatedbytheNationalInstituteofStandardsandTechnologyasthesuccessorto
theDataEncryptionStandard(DES)encryptionalgorithm.
WPAPresharedKeyTypespecifiestheWPApre sharedkeytypeandthekeyforclient
authenticationwiththisradiointerfaceorVAP.IfyouusetheWPA
presharedkey,youmust
configureallwirelessclientswiththesamekeyenteredheretocommunicatewiththis
interfaceorVAP.
Hexadecimalusesakeymadeupofastringof64hexadecimalnumbers.
WPAPreSharedKeyspecifiesthepresharedkeyintheappropriateformatforthetype
of
keyyouselected:astringof64hexadecimalnumbers,orastringof8to63alphanumeric
characters.
802.1xAuthentication:
WirelessclientscanbeauthenticatedfornetworkaccessbycheckingtheirMACaddress
againstthelocaldatabaseconfiguredontheaccesspoint,orbyusingtheIEEE802.1x
network
accessauthenticationprotocoltolookuptheirMACaddressesonaRADIUSserver.The
802.1xprotocolcanalsobeconfiguredtocheckotherusercredentialssuchasausernameand
password.
802.1xSetup.IEEE802.1xisastandardframeworkfornetworkaccesscontrolthatusesa
centralRADIUS
serverforuserauthentication.Thiscontrolfeaturepreventsunauthorized
accesstothenetworkbyrequiringan802.1xclientapplicationtosubmitusercredentialsfor
authentication.The802.1xstandardusestheExtensibleAuthenticationProtocol(EAP)topass
usercredentials(eitherdigitalcertificates,usernamesandpasswords,orother)fromtheclient
to
theRADIUSserver.ClientauthenticationisthenverifiedontheRADIUSserverbeforethe
accesspointgrantsclientaccesstothenetwork.

Table of Contents

Other manuals for Enterasys RoamAbout RBT-4102

Related product manuals