D-Link DWL-8500AP Product Manual - Page 143

Set Security to WPA/WPA2 Personal (PSK), WPA and WPA2, TKIP Only

Page 143 highlights

B CLI for AP Configuration and so on. To enable RADIUS accounting on the VAP, enter the following command: set bss wlan0bssvap0 radius-accounting on 3. View the security settings. Use the "get" command to view the updated security configuration and see the results of the new settings. DLINK-AP# get interface wlan0 security The following command gets details about how the internal network is configured, including security details. DLINK-AP# get bss wlan0bssvap0 detail The following command gets details about the interface and shows the WEP Key settings, specifically. DLINK-AP# get interface wlan0 detail Set Security to WPA/WPA2 Personal (PSK) To configure WPA/WPA2 Personal as the security mode, you need to issue multiple commands. This section describes the commands and procedures to configure WPA/WPA2 Personal. NOTE: This example shows how to configure WPA/WPA2 Personal on VAP 0 on radio 1 (wlan0). For VAPs 1-7, use wlanxvapy, where x is the radio, and y is the VAP ID. For example, to configure security on VAP 3 on radio 2, use wlan1vap3 instead of wlan0 in all of the following commands. 1. Set the Security Mode DLINK-AP# set interface wlan0 security wpa-personal 2. Set the WPA versions based on what types of client stations you want to support. - WPA-If all client stations on the network support the original WPA but none support the newer WPA2, then use WPA. set bss wlan0bssvap0 wpa-allowed on set bss wlan0bssvap0 wpa2-allowed off - WPA2-If all client stations on the network support WPA2, we suggest using WPA2 which provides the best security per the IEEE 802.11i standard. set bss wlan0bssvap0 wpa-allowed off set bss wlan0bssvap0 wpa2-allowed on - WPA and WPA2-If you have a mix of clients, some of which support WPA2 and others which support only the original WPA, select both. This lets both WPA and WPA2 client stations associate and authenticate, but uses the more robust WPA2 for clients who support it. This WPA configuration allows more interoperability, at the expense of some security. set bss wlan0bssvap0 wpa-allowed on set bss wlan0bssvap0 wpa2-allowed on 3. Set the Cipher Suite you want to use. - TKIP Only: Temporal Key Integrity Protocol (TKIP). Access Point CLI Commands 143

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

Access Point CLI Commands
143
B
CLI for AP Configuration
and so on. To enable RADIUS accounting on the VAP, enter the following command:
set bss wlan0bssvap0 radius-accounting on
3.
View the security settings.
Use the “get” command to view the updated security configuration and see the results of
the new settings.
DLINK-AP#
get interface wlan0 security
The following command gets details about how the internal network is configured,
including security details.
DLINK-AP#
get bss wlan0bssvap0 detail
The following command gets details about the interface and shows the WEP Key settings,
specifically.
DLINK-AP#
get interface wlan0 detail
Set Security to WPA/WPA2 Personal (PSK)
To configure WPA/WPA2 Personal as the security mode, you need to issue multiple
commands. This section describes the commands and procedures to configure WPA/WPA2
Personal.
NOTE:
This example shows how to configure WPA/WPA2 Personal on VAP 0 on
radio 1 (
wlan0
). For VAPs 1-7, use
wlan
x
vap
y
, where
x
is the radio, and
y
is
the VAP ID. For example, to configure security on VAP 3 on radio 2, use
wlan1vap3
instead of
wlan0
in all of the following commands.
1.
Set the Security Mode
DLINK-AP#
set interface wlan0 security wpa-personal
2.
Set the WPA versions based on what types of client stations you want to support.
-
WPA
—If all client stations on the network support the original WPA but none support
the newer WPA2, then use WPA.
set bss wlan0bssvap0 wpa-allowed on
set bss wlan0bssvap0 wpa2-allowed off
-
WPA2
—If all client stations on the network support WPA2, we suggest using WPA2
which provides the best security per the IEEE 802.11i standard.
set bss wlan0bssvap0 wpa-allowed off
set bss wlan0bssvap0 wpa2-allowed on
-
WPA and WPA2
—If you have a mix of clients, some of which support WPA2 and
others which support only the original WPA, select both. This lets both WPA and
WPA2 client stations associate and authenticate, but uses the more robust WPA2 for
clients who support it. This WPA configuration allows more interoperability, at the
expense of some security.
set bss wlan0bssvap0 wpa-allowed on
set bss wlan0bssvap0 wpa2-allowed on
3.
Set the Cipher Suite you want to use.
-
TKIP Only
: Temporal Key Integrity Protocol (TKIP).