Enterasys Networks RBT-4102 manual Authentication

Page 118

Security

Pre‐Authentication. If Pre‐Authentication is enabled, a WPA2 wireless client can perform an 802.1X authentication with other wireless access points in its range when it is still connected to its current wireless access point.

To use Pre‐Authentication, you must have the following:

Wireless network adaptors that support WPA2.

Windows XP wireless network adaptor drivers that support the passing of WPA2 capabilities to Windows Wireless Auto Configuration.

Authentication

Open System (the default setting): Select this option if you plan to use WPA or 802.1x as a security mechanism. If you don’t set up any other security mechanism on the access point, the network has no protection and is open to all users.

Shared Key sets the access point to use WEP shared keys. If this option is selected, you must configure at least one key on the access point and all clients.

Note: To use 802.1x on wireless clients requires a network card driver and 802.1x client software that supports the EAP authentication type that you want to use. Windows XP provides native WPA support, other systems require additional software.

WPA (Wi‐Fi Protected Access) is a standards‐based, interoperable security enhancement that strongly increases the level of data protection and access control for existing and future wireless LAN systems. It is derived from and will be forward‐compatible with the upcoming IEEE 802.11i standard. WPA leverages TKIP (Temporal Key Integrity Protocol) for data protection and 802.1X for authenticated key management.

WPA‐PSK. Uses WPA key management, non‐root access point/bridges and the authentication server authenticate to each other using an EAP authentication method, and the non‐root access point/bridge and server generate a pairwise master key (PMK). Using WPA, the server generates the PMK dynamically and passes it to the root access point/ bridge. Using WPA‐PSK, however, you configure a pre‐shared key on both the non‐root access point/bridge and the root access point/bridge, and that pre‐shared key is used as the PMK.

WPA2 provides a stronger encryption mechanism through AES, which is a requirement for some corporate and government users. TKIP, the encryption mechanism in WPA, relies on RC4 instead of Triple Data Encryption Standard (3DES), AES, or another encryption algorithms.

WPA‐WPA2‐ Mixed permits the coexistence of WPA and WPA2 clients on a common SSID. WPA2 ‐mixed mode is a Wi‐Fi Certified feature. The access point advertises the encryption ciphers (TKIP, CCMP, other) that are available for use. The client selects the encryption cipher it would like to use, and the selected encryption cipher is used for encryption between the client and access point once it is selected by the client.

Data Encryption enables or disables the access point to use WEP shared keys for data encryption. If this option is selected, you must configure at least one key on the access point and all clients. (Default: Disable)

Note: You must enable WEP encryption in order to enable all types of encryption on the access point; however, you do not need to define WEP keys for WPA.

WPA Clients sets the specified radio interface or VAP to:

Required ‐ allows only WPA‐enabled clients to access the network.

4-82 Advanced Configuration

Image 118
Contents Enterasys RoamAbout Page Page Enterasys Networks, Inc. Firmware License Agreement Iii Page Enterasys Networks, Inc. Software License Agreement Page General Viii Contents Snmp Appendix a Default Settings Appendix B Troubleshooting IndexXii Firmware Version Support Purpose of This ManualIntended Audience Associated DocumentsGetting Help Convention DescriptionIntroduction OverviewFeatures PolicyApplications Applications Introduction Network Configuration Ad Hoc Wireless LAN no Access Point or Bridge Network TopologiesInfrastructure Wireless LAN Infrastructure Wireless LANInfrastructure Wireless LAN for Roaming Wireless PCs Infrastructure Wireless LAN for RoamingInfrastructure Wireless Bridge Infrastructure Wireless BridgeNetwork Topologies Network Configuration Initial Setup Using the CLI Required ConnectionsLogging Enter no ip dhcp to disable Dhcp Using Web Management Initial Setup Using the CLI ```` Initial Setup Using the CLI Initial Setup Using the CLI Initial Setup Using the CLI Initial Setup Using the CLI Using the Web Interface Using the Command Line Interface CLISnmp Using Web Management to Configure System Information IdentificationDisabled Using the CLI to Configure System InformationEnabled SG SingaporeTCP / IP Settings Using Web Management to Configure TCP/IP TCP / IP Settings Using the CLI to Configure TCP/IP TCP/IP ConfigurationSSH Configuration Ethernet Settings ConfigurationTCP / IP Settings Radius Using Web Management to Configure Radius Radius Attributes Radius Accounting Attribute Description Using the CLI to Configure Radius Authentication Using Web Management to Configure Authentication Local Using the CLI to Configure AuthenticationAllowed Using Web Management to Configure Filter Control and VLANs Filter Control and VLANsFilter Control and VLANs Using the CLI to Configure Filter Control and VLANs CLI Commands for Vlan SupportFilter Control and VLANs CLI Commands for Filtering SVP Commands CDP Settings Using Web Management to Configure CDPCDP Settings Using the CLI to Configure CDP Using Web Management to Configure Rogue AP Detection Rogue AP DetectionUsing the CLI to Configure Rogue AP Detection Ssid TT5Using Web Management to Configure Snmp SnmpSnmp Notifications Description Snmp Notifications Security Level Snmp Targets Using the CLI to Configure Snmp CLI Commands for SnmpCLI Commands for Configuring SNMPv3 Users and Groups TPSSnmp CLI Commands for Configuring SNMPv3 Targets CLI Commands for Configuring SNMPv3 Trap FiltersAdministration Changing the PasswordUsing Web Management to Change the Password Using the CLI to Enable and Disable Com Port Using the CLI to Change the PasswordUsing Web Management to Enable and Disable Com Port Enabling and Disabling Com PortUpgrading Firmware Using Web Management to Upgrade Firmware Using the CLI to Upgrade Firmware Using Web Management to Configure System Log System LogLogging Level Descriptions Error Level Using the CLI to Configure System Log Using Web Management to Configure Sntp Using the CLI to Configure Sntp TAIPEI, BeijingWDS and STP Using Web Management to Configure WDS and STP WDS and STP WDS and STP Using the CLI to Configure WDS Using the CLI to Configure STP Radio Signal Characteristics Radio InterfaceRadio Settings Using Web Management to Configure Interface Radio SettingsVlan ID Radius Attributes Number Value Radio Interface Radio Interface Radio Interface Example Not Supported WEPAES-TKIP DynamicAdmission Control No Example Required LongTkip PRE Shared KEYAC1Background Txop Limit 0.000 ms Wi-Fi Multimedia WMM Configuration WMM OperationUsing Web Management to Configure WMM WMM Backoff Wait timesUsing the CLI to Configure WMM Ssid SW-WDSAntenna Admission Control No AC2Video Txop Limit Virtual APs VAPs Configuration Using Web Management to Configure Virtual APsRadio Interface Using the CLI to Configure Virtual APs BIT Encryption WPA-ONLYAdmission Control No Security WEPWired Equivalent Privacy WEP Using Web Management to Configure Security SettingsSecurity Page Authentication 802.1x Authentication Security Security Using the CLI to Configure WPA Pre-Shared Key Using the CLI to Configure WPA over 802.1X SecurityQuality of Service AC1Background LogCwMin LogCwMax Nopassword Allowed Using the CLI to Configure Local MAC AuthenticationNopassword Allowed Local EmptySecurity Using the CLI to Configure Radius MAC Authentication Remote Using the CLI to Configure WEP Shared Key Security TKIP-WEP Ssid WPAShared Using the CLI to Configure WEP over 802.1x Security Ssid ETSAuthentication Parameters Using the CLI to Configure WPA2 Security AESWPA2-ONLY Using the CLI to Configure WPA2 Pre-Shared Key Security WPA2-PSK Status Information Status Menu DescriptionUsing Web Management to View AP Status Status Information Using the CLI to Display AP Status SQAUsing Web Management to View CDP Status Using the CLI to Display CDP Status Using Web Management to View Station Status Status Information Using Web Management to View Neighbor AP Detection Status Gtac LAB R2 Using the CLI to View Neighbor AP Detection StatusIbss DEMOWEP1Using Web Management to View WDS-STP Status Show bridge Using the CLI to View WDS-STP StatusSTP Show bridge link Child StatusRoot Bridge Status NoneUsing Web Management to View Event Logs Using the CLI to View Event Logs RoamAbout 4102#show eventsOct 101551 Status Information Advanced Configuration Default Settings CDP WDS & STP VAP1 Nopassword Preamble Length Long Wireless Interface 802.11b/g Troubleshooting Troubleshooting StepsTroubleshooting Steps Maximum Distance Tables 80 m 264 ftMaximum Distance Tables Troubleshooting Index Radius MAC WDS 4-50bridge 4-52CLI Index-4
Related manuals
Manual 78 pages 58.85 Kb