
Chapter 10: Configuring Security
Security Modes
Psion Teklogix 9160 G2 Wireless Gateway User Manual 113
10.2.2.5 WPA Enterprise
Wi-Fi Protected Access Enterprise with Remote Authentication Dial-In User Service (RA-
DIUS) is an implementation of the Wi-Fi Alliance IEEE 802.11h standard, which includes
Advanced Encryption Standard (AES), Counter mode/CBC-MAC Protocol (CCMP), and
Temporal Key Integrity Protocol (TKIP) mechanisms. The Enterprise mode requires the use
of a RADIUS server to authenticate users, and configuration of user accounts via the Clus-
ter, User Management tab.
Cipher Suites
Select the cipher suite you want to use:
•TKIP
• CCMP (AES)
•Both
Temporal Key Integrity Protocol
(
TKIP
) is the default.
TKIP provides a more secure encryption solution than WEP keys. The TKIP process more frequently changes
the encryption key used and better ensures that the same key will not be re-used to encrypt data (a weakness
of WEP). TKIP uses a 128-bit “temporal key” shared by clients and access points. The temporal key is com-
bined with the client's MAC address and a 16-octet initialization vector to produce the key that will encrypt the
data. This ensures that each client station uses a different key to encrypt data. TKIP uses RC4 to perform the
encryption, which is the same as WEP. But TKIP changes temporal keys every 10,000 packets and distributes
them, thereby greatly improving the security of the network.
Counter mode/CBC-MAC Protocol
(
CCMP
) is an encryption method for IEEE
802.11i
that uses the
Advanced Encryption Algorithm
(
AES
). It uses a CCM combined with Cipher Block Chaining Counter mode
(CBC-CTR) and Cipher Block Chaining Message Authentication Code (CBC-MAC) for encryption and mes-
sage integrity.
If you select both TKIP and CCMP(AES), Pairwise cipher is AES and Groupwise cipher is TKIP. Pairwise cipher
is used for unicast traffic and Groupwise cipher is used for multicast/broadcast traffic. Both TKIP and AES cli-
ents can associate with the access point. WPA clients must have one of the following to be able to associate
with the AP:
• A valid TKIP key
• A valid CCMP (AES) key
Clients not configured to use a
WPA Personal
will not be able to associate with AP.
Key
The
Pre-shared Key
is the shared secret key for
WPA Personal
. Enter a string of at least 8 characters to a
maximum of 63 characters.
Table 10.8 WPA Personal Security Settings
Field Description
Comentarios a estos manuales