HomeSafe User’s Guide

 

Table 29-2 Menu 23.4 System Security : IEEE802.1x

 

 

FIELD

DESCRIPTION

 

 

PSK

Type a pre-shared key from 8 to 63 case-sensitive ASCII characters (including spaces

 

and symbols) when you select WPA-PSKin the Key Management Protocol field.

WPA Mixed

Select Enable to activate WPA mixed mode. Otherwise, select Disable and configure

Mode

Group Data Privacy field.

Data Privacy

Group Data Privacy allows you to choose TKIP (recommended) or WEP for broadcast

for

and multicast (“group”) traffic if the Key Management Protocol is WPA and WPA

Broadcast/Mult

Mixed Mode is disabled. WEP is used automatically if you have enabled WPA Mixed

icast packets

Mode.

 

All unicast traffic is automatically encrypted by TKIP when WPA or WPA-PSK Key

 

Management Protocol is selected.

WPA

The WPA Group Key Update Timer is the rate at which the AP (if using WPA-PSK

Broadcast/Mult

key management) or RADIUS server (if using WPA key management) sends a new

icast Key

group key out to all clients. The re-keying process is the WPA equivalent of

Update Timer

automatically changing the WEP key for an AP and all stations in a WLAN on a periodic

 

basis. Setting of the WPA Group Key Update Timer is also supported in WPA-PSK

 

mode. The HomeSafe default is 1800 seconds (30 minutes).

Authentication

The authentication database contains wireless station login information. The local user

Databases

database is the built-in database on the HomeSafe. The RADIUS is an external server.

 

Use this field to decide which database the HomeSafe should use (first) to authenticate

 

a wireless station.

 

Before you specify the priority, make sure you have set up the corresponding database

 

correctly first.

 

When you configure Key Management Protocol to WPA, the Authentication

 

Databases must be RADIUS Only. You can only use the Local User Database with

 

802.1x Key Management Protocol.

 

Select Local User Database Only to have the HomeSafe just check the built-in user

 

database on the HomeSafe for a wireless station's username and password.

 

Select RADIUS Only to have the HomeSafe just check the user database on the

 

specified RADIUS server for a wireless station's username and password.

 

Select Local first, then RADIUS to have the HomeSafe first check the user database

 

on the HomeSafe for a wireless station's username and password. If the user name is

 

not found, the HomeSafe then checks the user database on the specified RADIUS

 

server.

 

Select RADIUS first, then Local to have the HomeSafe first check the user database

 

on the specified RADIUS server for a wireless station's username and password. If the

 

HomeSafe cannot reach the RADIUS server, the HomeSafe then checks the local user

 

database on the HomeSafe. When the user name is not found or password does not

 

match in the RADIUS server, the HomeSafe will not check the local user database and

 

the authentication fails.

When you have completed this menu, press [ENTER] at the prompt “Press ENTER to confirm or ESC to cancel” to save your configuration or press [ESC] to cancel and go back to the previous screen.

Once you enable user authentication, you need to specify an external RADIUS server or create local user accounts on the HomeSafe for authentication.

29-4

System Security

Page 285
Image 285
ZyXEL Communications HS100/HS100W manual Psk, Group Data Privacy field, Mode, Management Protocol is selected