
Chapter 10: Configuring Security
Comparison Of Security Modes For Key Management, Authentication And Encryption Algorithms
98 Psion Teklogix 9160 G2 Wireless Gateway User Manual
Recommendations
WPA Enterprise mode is the recommended mode. The CCMP (AES) and TKIP encryp-
tion algorithms used with WPA modes are far superior to the RC4 algorithm used for Static
WEP or IEEE 802.1x modes. Therefore, CCMP (AES) or TKIP should be used whenever
possible. All WPA modes allow you to use these encryption schemes, so WPA security
modes are recommended above the others when using WPA is an option. Additionally, this
mode incorporates a RADIUS server for user authentication which gives it an edge over
WPA Personal mode.
If you have an external RADIUS server on your network, we recommend using it rather
than the using the embedded RADIUS server on the AP. An external RADIUS server will
provide better security than the local authentication server.
Use the following guidelines for choosing options within the WPA Enterprise mode security
mode:
1. The best security you can have to date on a wireless network is WPA Enterprise mode
using CCMP (AES) encryption algorithm. AES is a symmetric 128-bit block data
encryption technique that works on multiple layers of the network. It is the most effec-
tive encryption system currently available for wireless networks. If all clients or other
APs on the network are WPA/CCMP compatible, use this encryption algorithm. (If all
clients are WPA2 compatible, choose to support only WPA2 clients.)
2. The second best choice is WPA Enterprise with the encryption algorithm set to both
TKIP and CCMP. This lets WPA client stations without CCMP associate, uses
TKIP for encrypting Multicast and Broadcast frames, and allows clients to select
whether to use CCMP or TKIP for Unicast (AP-to-single-station) frames. This
WPA configuration allows more interoperability, at the expense of some security.
Table 10.4 WPA Enterprise Security Mode
Key Management Encryption Algorithms User Authentication
WPA Enterprise mode provides
dynamically-generated keys
that are periodically refreshed.
There are different Unicast keys
for each station.
•
Temporal Key Integrity Protocol
(TKIP).
•
Counter mode/CBC-MAC Protocol
(CCMP)
Advanced Encryption Stan-
dard
(AES).
Remote Authentication Dial-In User Service
(
RADIUS
)
You have a choice of using the 9160 G2 Wireless
Gateway embedded RADIUS server or an exter-
nal RADIUS server. The embedded RADIUS
server supports Protected
EAP
(PEAP) and
MSCHAP V2.
Comentarios a estos manuales