D-Link DWL-3500AP Administration Guide - Page 39

Configuring Access Point Security, Understanding Security on Wireless Networks - setup

Page 39 highlights

4 Configuring Access Point Security This chapter describes DWL-3500AP and DWL-8500AP security options and how to configure security on the virtual access points (VAPs) to prevent unauthorized and unauthenticated clients from accessing the WLAN. This chapter contains the following sections: • Understanding Security on Wireless Networks - Choosing a Security Mode - Comparing Security Modes - Enabling Station Isolation • Configuring Virtual Access Point Security - Static WEP - IEEE 802.1X - WPA Personal - WPA Enterprise - Prohibiting the SSID Broadcast Understanding Security on Wireless Networks The DWL-3500AP and DWL-8500AP access points provide several authentication and encryption schemes to ensure that your wireless infrastructure is accessed only by the intended users. The details of each security mode are described in the following sections. Some of the security modes use an external RADIUS server for client authentication. For information about configuring an external RADIUS server, see "Wireless Client Settings and RADIUS Server Setup" on page 101. Choosing a Security Mode In general, D-Link recommends that you use the most robust security mode that is feasible on your network. When configuring security on the access point, you first must choose the security mode, then in some modes you select an authentication algorithm and whether to allow clients not using the specified security mode to associate. Wi-Fi Protected Access (WPA) Enterprise with Remote Authentication Dial-In User Service (RADIUS) using the Advanced Encryption Standard (AES) encryption algorithm using Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) Understanding Security on Wireless Networks 39

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

Understanding Security on Wireless Networks
39
4
Configuring Access Point Security
This chapter describes DWL-3500AP and DWL-8500AP security options and how to
configure security on the virtual access points (VAPs) to prevent unauthorized and
unauthenticated clients from accessing the WLAN. This chapter contains the following
sections:
Understanding Security on Wireless Networks
-
Choosing a Security Mode
-
Comparing Security Modes
-
Enabling Station Isolation
Configuring Virtual Access Point Security
-
Static WEP
-
IEEE 802.1X
-
WPA Personal
-
WPA Enterprise
-
Prohibiting the SSID Broadcast
Understanding Security on Wireless Networks
The DWL-3500AP and DWL-8500AP access points provide several authentication and
encryption schemes to ensure that your wireless infrastructure is accessed only by the intended
users. The details of each security mode are described in the following sections.
Some of the security modes use an external RADIUS server for client authentication. For
information about configuring an external RADIUS server, see
“Wireless Client Settings and
RADIUS Server Setup”
on page 101.
Choosing a Security Mode
In general, D-Link recommends that you use the most robust security mode that is feasible on
your network. When configuring security on the access point, you first must choose the
security mode, then in some modes you select an authentication algorithm and whether to
allow clients not using the specified security mode to associate.
Wi-Fi Protected Access (
WPA
) Enterprise with Remote Authentication Dial-In User Service
(
RADIUS
) using the Advanced Encryption Standard (AES) encryption algorithm using
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP)