D-Link DWL-8500AP Product Manual - Page 144

Set Security to WPA/WPA2 Enterprise (RADIUS), CCMP AES Only, TKIP and CCMP AES

Page 144 highlights

D-Link Unified Access Point Administrator's Guide set bss wlan0bssvap0 wpa-cipher-tkip on set bss wlan0bssvap0 wpa-cipher-ccmp off - CCMP (AES) Only-Counter mode/CBC-MAC Protocol (CCMP) is an encryption method for IEEE 802.11i that uses the Advanced Encryption Algorithm (AES). set bss wlan0bssvap0 wpa-cipher-tkip off set bss wlan0bssvap0 wpa-cipher-ccmp on - TKIP and CCMP (AES)-When you enable both authentication algorithms, both TKIP and AES clients can associate with the access point. WPA clients must have either a valid TKIP key or a valid CCMP (AES) key to be able to associate with the AP. set bss wlan0bssvap0 wpa-cipher-tkip on set bss wlan0bssvap0 wpa-cipher-ccmp on 4. Set the Pre-shared key. The Pre-shared Key is the shared secret key for WPA-PSK. Enter a string of at least 8 characters to a maximum of 63 characters. Following are two examples; the first sets the key to "SeCret !", the second sets the key to "KeepSecret". DLINK-AP# set interface wlan0 wpa-personal-key "SeCret !" or DLINK-AP# set interface wlan0 wpa-personal-key KeepSecret Shared secret keys can include spaces and special characters if the key is placed inside quotation marks as in the first example above. If the key is a string of characters with no spaces or special characters in it, the quotation marks are not necessary as in the second example above. 5. View the security settings. Use the "get" command to view the updated security configuration and see the results of the new settings. DLINK-AP# get interface wlan0 security The following command gets details about how the internal network is configured, including security details. DLINK-AP# get bss wlan0bssvap0 detail The following command gets details about the interface and shows the WEP Key settings, specifically. DLINK-AP# get interface wlan0 detail Set Security to WPA/WPA2 Enterprise (RADIUS) To configure WPA/WPA2 Enterprise as the security mode, you need to issue multiple commands. This section describes the commands and procedures to configure WPA/WPA2 Enterprise. NOTE: This example shows how to configure WPA/WPA2 Personal on VAP 0 on radio 1 (wlan0). For VAPs 1-7, use wlanxvapy, where x is the radio, and y is the VAP ID. For example, to configure security on VAP 3 on radio 2, use wlan1vap3 instead of wlan0 in all of the following commands. 144 © 2001-2008 D-Link Corporation. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

144
© 2001-2008 D-Link Corporation. All Rights Reserved.
D-Link Unified Access Point Administrator’s Guide
set bss wlan0bssvap0 wpa-cipher-tkip on
set bss wlan0bssvap0 wpa-cipher-ccmp off
-
CCMP (AES) Only
—Counter mode/CBC-MAC Protocol (CCMP) is an encryption
method for IEEE 802.11i that uses the Advanced Encryption Algorithm (AES).
set bss wlan0bssvap0 wpa-cipher-tkip off
set bss wlan0bssvap0 wpa-cipher-ccmp on
-
TKIP and CCMP (AES)
—When you enable both authentication algorithms, both
TKIP and AES clients can associate with the access point. WPA clients must have
either a valid TKIP key or a valid CCMP (AES) key to be able to associate with the
AP.
set bss wlan0bssvap0 wpa-cipher-tkip on
set bss wlan0bssvap0 wpa-cipher-ccmp on
4.
Set the Pre-shared key.
The
Pre-shared Key
is the shared secret key for WPA-PSK. Enter a string of at least 8
characters to a maximum of 63 characters. Following are two examples; the first sets the
key to “
SeCret !
“, the second sets the key to “
KeepSecret
”.
DLINK-AP#
set interface wlan0 wpa-personal-key "SeCret !"
or
DLINK-AP#
set interface wlan0 wpa-personal-key KeepSecret
Shared secret keys can include spaces and special characters if the key is placed inside
quotation marks as in the first example above. If the key is a string of characters with no
spaces or special characters in it, the quotation marks are not necessary as in the second
example above.
5.
View the security settings.
Use the “get” command to view the updated security configuration and see the results of
the new settings.
DLINK-AP#
get interface wlan0 security
The following command gets details about how the internal network is configured,
including security details.
DLINK-AP#
get bss wlan0bssvap0 detail
The following command gets details about the interface and shows the WEP Key settings,
specifically.
DLINK-AP#
get interface wlan0 detail
Set Security to WPA/WPA2 Enterprise (RADIUS)
To configure WPA/WPA2 Enterprise as the security mode, you need to issue multiple
commands. This section describes the commands and procedures to configure WPA/WPA2
Enterprise.
NOTE:
This example shows how to configure WPA/WPA2 Personal on VAP 0 on
radio 1 (
wlan0
). For VAPs 1-7, use
wlan
x
vap
y
, where
x
is the radio, and
y
is
the VAP ID. For example, to configure security on VAP 3 on radio 2, use
wlan1vap3
instead of
wlan0
in all of the following commands.