Silex technology SX-500-1402 manual Configuration, Required Setting, WPA2 AES-CCMP

Page 11

FIPS-140-2 Interface

Physical

Logical Interface

 

Interface

 

 

Button

Invoke configuration/status function

 

 

 

 

 

 

Status Output

Ethernet

Plaintext status response from console task

 

 

via Telnet

 

 

Plaintext status response from web config

 

 

via HTTP

 

Wireless

Status response from console task via

 

 

Telnet

 

 

Status response from web config via HTTP

 

 

 

 

Serial

Plaintext status response from button push

 

 

 

 

LEDs

Indicate link and unit error status

 

 

 

 

 

 

Power Interface

Power

 

 

 

 

 

Serial

 

 

 

 

When the module enters an error state, all Data Input and Data Output interfaces are disabled. If an error state is encountered, the LED interface will indicate the error by blinking for several seconds, and then the unit will reset. The unit will not send or receive any data until the reset is complete.

The SX-500 performs cryptographic self tests during initialization after power up or a firmware induced reset. Until the self tests are complete, no data input or output interfaces are active. If the self test fails, the unit will enter an error state.

Configuration

The Cryptographic Officer is responsible for configuring the unit for use in the target environment. See Chapter 3 and Appendix A for instructions on configuring the unit. The peripheral unit (usually a PC) being used to configure the SX-500 must be directly connected to the unit via a crossover cable or local hub which is not connected to any LAN, WLAN or other larger network. This will enable manual transport and electronic entry of secret and private keys (RSA private key and WPA Pre-Shared Key) in a plaintext form. Even if RSA private keys are protected with a PEM passphrase when entered, they are still considered to be in plaintext form.

For the SX-500 to operate in FIPS 140-2 approved mode, the wireless security configuration must be set as follows:

Item

Required Setting

Wireless Encryption Mode

WPA2 (AES-CCMP)

 

 

Wireless Authentication

PSK or TLS or PEAP

 

 

The SX-500 allows other security settings for interoperability in non FIPS 140 environments. However, use of the SX-500 with any settings other than those indicated above is not FIPS 140-2 compliant.

Introduction

Silex

Page 5

 

Part Number 140-00188-210A

 

Image 11 Contents
SX-500-1402 Serial Device Server Trademarks Page Contents Figures Contents Silex Part Number 140-00188-210A Emissions Disclaimer Safety Precautions About This Reference Guide 2009.08.13 Lee Aydelotte Initial Release Revision HistorySX-500 IntroductionFIPS-140-2 Interface Physical Logical Interface Logical PortsPort Name Description LEDWPA2 AES-CCMP ConfigurationRequired Setting Https Secure Operation Physical ProtectionInstalling the Serial Device Server Installing the Serial Device Server HardwareVerify Package Contents RS-232 connector pinouts and cabling Status Monitors Function State Monitoring Serial Device Server StatusWireless Configuration Settings Chapter Configuring the Serial Device ServerBasic Configuration Requirements TCP/IP SettingsConfiguration Methods First-Time IP Address Configuration Ping ipaddress Using a Web Browser to Configure the Serial Device Server Silex Authentication Server Certificate You can skip the remainder of this chapter AD-HOC Init Exit DisabledSerial Port Emulator Chapter Using the Serial Device Server with Your ApplicationTelnet ipaddress portnumber Raw TCP connectionRFC 2217 Remote Modem Control Support ECable ModeConsole Mode Switching Print Server ModeSET Port S1 Filter AT AT CommandsCTS/RTS Chapter Advanced ConfigurationFactory Default Settings Factory Default Settings Parameter DescriptionParameter Description Settings Default Setting Modifying TCP/IP SettingsDNS Using AT Modem CommandsTCP/IP Settings Parameter AT Commands Parameter Description Standard AT Commands SupportedAT#Cset nw ssid silex#Csave Parameter Command DescriptionExtended AT Commands Parameter Description Response Codes Numeric Code Description Response CodesChapter Troubleshooting Email Tech support support@silexamerica.com Radio Performance Specifications Parameter Chapter Product SpecificationsProduct Specifications Component Port Destination Device Parameter SpecificationsTCP Port Connections TCP Port ConnectionsTtls Leap Appendix a Advanced Security ConfigurationPSK EAPPre-Shared Key Wireless Security Only Encryption Mode Wireless Security OnlyKey Selection Wireless Security Only WEP Key Value Wireless Security OnlyPassword Wireless Authentication Type Wireless Security OnlyWired Authentication Type Wired Ethernet Networks Only Authentication AttemptsProduct Specifications Silex Part Number 140-00188-210A Signal Quality Signal Strength = Noise Level Appendix B Console CommandsWireless and Network Security Commands Network Commands DescriptionSET NW Ethauth Ttls TLS Peap Command DescriptionTLS PSK SET NW KEY# SET NW Certcn Wifi RTS Threshold =CL NW BSsid SET NW RTSSET NW ID SET NW CERTCN2SET NW Certexp SET NW CertkeySET NW Realm SET NW Wpagroup Enable DisableSET NW Inap PAPMSCHAPV2 XON/XOFF Port CommandsSET NW Reset Port Commands DescriptionSET Port S1 Size 7 Server Information CommandsServer Information Commands Description CL Port S1 JOBSH Serial SET SERVEr NAme NameSET Snmp CONtact String SET Snmp LOCation stringService Commands Description Service CommandsTWCFFFFFFP14 TwcffffffBINARYP1 TEXTP1String Commands String CommandsPOSTSCRIPT\0A TCP/IP CommandsTCP/IP Commands Description Enter LANGUAGE=SET IP Chksum ENable DIsable All hosts permitted accessSET ARP ENable DIsable SET IP BAnner ENable DIsableSET IP LPD Auto Bootp Rarp Dhcp StaticSET IP FTP SET IP HttpSET IP Tftp SET IP TCPXxxxxxS1A 9100 XxxxxxS1B 3001 SH IPAuto Firmware Update Command Description Firmware UpdateMiscellaneous Commands Description Miscellaneous CommandsHelp Commands Console Commands Silex Part Number 140-00188-210A Appendix C Firmware Update Procedures Firmware Update Procedures Silex Part Number 140-00188-210A Information for United States Users Appendix D Safety and Regulatory Notices FCC ID N6C-SX10WG Information for Canadian Users IC notice SX-500Declaration of Conformity CE SX-500 Information for European Users SX-500Silex Technology Beijing, Inc Appendix E Silex Contact InformationSilex Technology America, Inc Silex Technology Europe GmbHSilex Technology America, Inc