Chapter 12 AP Profile
NWA50AX User’s Guide
114
Security Mode Select a security mode from the list: no ne , e nha nc e d - o pe n, we p , wpa 2, wpa 2- m ix or
wp a 3.
e nha nc e d - o pe n uses Opportunistic Wireless Encryption (OWE) which encrypts the
wireless connection when possible.
Authentication Settings
Personal This field is available when you select the wpa 2, wpa 2- m ix or wpa 3 security mode.
Select this option to use a Pre-Shared Key (PSK) with WPA2 encryption or Simultaneous
Authentication of Equals (SAE) with WPA3 encryption.
Pre-Shared Key Enter a pre-shared key of between 8 and 63 case-sensitive ASCII characters (including
spaces and symbols) or 64 hexadecimal characters.
Transition Mode Enable this for backwards compatibility. This option is only available if the Se c urity Mo d e
is wpa 3 or e nha nc e d - o pe n. This creates two virtual APs (VAPs) with a primary (wpa 3 or
e nha nc e d - o pe n) and fallback (wpa 2 or no ne ) security method.
If the Se c urity Mo d e is wpa 3, enabling this will force Ma na g e m e nt Fra m e Pro te c tion to be
set to O p tio na l. If this is disabled or if the Se c urity Mo de is e nha nc e d- o p e n, Ma na g e m e nt
Fra m e Prote c tio n will be set to Re q uire d.
Advance
Note: Click on the Sho w Adva nc e d Se tting s button to show the fields describe below.
Idle Timeout Enter the idle interval (in seconds) that a client can be idle before authentication is
discontinued.
Group Key Update
Timer
Enter the interval (in seconds) at which the AP updates the group WPA2 encryption key.
Pre-Authentication Select Ena b le to allow pre-authentication. Otherwise, select Disa b le .
Management Frame
Protection
This field is available only when you select wpa 2 in the Se c urity Mo d e field and set Ciphe r
Type to a e s.
Data frames in 802.11 WLANs can be encrypted and authenticated with WEP, WPA or
WPA2. But 802.11 management frames, such as beacon/probe response, association
request, association response, de-authentication and disassociation are always
unauthenticated and unencrypted. IEEE 802.11w Protected Management Frames allows
APs to use the existing security mechanisms (encryption and authentication methods
defined in IEEE 802.11i WPA/WPA2) to protect management frames. This helps prevent
wireless DoS attacks.
Select the check box to enable management frame protection (MFP) to add security to
802.11 management frames.
Select O p tio na l if you do not require the wireless clients to support MFP. Management
frames will be encrypted if the clients support MFP.
Select Re q uire d and wireless clients must support MFP in order to join the Zyxel Device’s
wireless network.
OK Click O K to save your changes back to the Zyxel Device.
Cancel Click C a nc e l to exit this screen without saving your changes.
Table 47 Configuration > Object > AP Profile > SSID > Security List > AAdd/Edit Security Profile> Security
Mode: wpa3 (continued)
LABEL DESC RIPTIO N