D-Link DWL-8500AP Product Manual - Page 42

When to Use WPA Personal, When to Use WPA Enterprise, recommended mode

Page 42 highlights

D-Link Unified Access Point Administrator's Guide When to Use WPA Personal Wi-Fi Protected Access Personal Pre-Shared Key (PSK) is an implementation of the Wi-Fi Alliance IEEE 802.11i standard, which includes AES-CCMP and TKIP mechanisms. This mode offers the same encryption algorithms as WPA 2 with RADIUS but without the ability to integrate a RADIUS server for user authentication. This security mode is backwards-compatible for wireless clients that support only the original WPA. Key Management WPA Personal provides dynamically-generated keys that are periodically refreshed. There are different Unicast keys for each station. Encryption Algorithms TKIP AES-CCMP User Authentication The use of a PSK provides user authentication similar to that of shared keys in WEP. Recommendations WPA Personal is not recommended for use with the Unified Access Point when WPA Enterprise is an option. We recommend that you use WPA Enterprise mode instead, unless you have interoperability issues that prevent you from using this mode. For example, some devices on your network might not support WPA or WPA2 with EAP talking to a RADIUS server. Embedded printer servers or other small client devices with very limited space for implementation might not support RADIUS. For such cases, we recommend that you use WPA Personal. When to Use WPA Enterprise Wi-Fi Protected Access Enterprise with RADIUS is an implementation of the Wi-Fi Alliance IEEE 802.11i standard, which includes AES-CCMP and TKIP mechanisms. This mode requires the use of a RADIUS server to authenticate users. On the Unified Access Point, WPA Enterprise provides the best security available for wireless networks. This security mode also provides backwards-compatibility for wireless clients that support only the original WPA. Key Management WPA Enterprise mode provides dynamically-generated keys that are periodically refreshed. There are different Unicast keys for each station. Encryption Algorithms TKIP AES-CCMP User Authentication RADIUS Recommendations WPA Enterprise mode is the recommended mode. The AES-CCMP and TKIP encryption algorithms used with WPA modes are far superior to the RC4 algorithm used for Static WEP or IEEE 802.1X modes. Therefore, AES-CCMP or TKIP should be used whenever possible. All WPA modes allow you to use these encryption schemes, so WPA security modes are recommended above the other modes when using WPA is an option. 42 © 2001-2008 D-Link Corporation. All Rights Reserved.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

42
© 2001-2008 D-Link Corporation. All Rights Reserved.
D-Link Unified Access Point Administrator’s Guide
When to Use WPA Personal
Wi-Fi Protected Access Personal Pre-Shared Key (
PSK
) is an implementation of the Wi-Fi
Alliance IEEE
802.11i
standard, which includes
AES
-CCMP and
TKIP
mechanisms. This
mode offers the same encryption algorithms as WPA 2 with RADIUS but without the ability to
integrate a RADIUS server for user authentication.
This security mode is backwards-compatible for wireless clients that support only the original
WPA
.
Recommendations
WPA Personal is not recommended for use with the Unified Access Point when WPA
Enterprise is an option.
We recommend that you use WPA Enterprise mode instead, unless you have interoperability
issues that prevent you from using this mode. For example, some devices on your network
might not support WPA or WPA2 with
EAP
talking to a
RADIUS
server. Embedded printer
servers or other small client devices with very limited space for implementation might not
support RADIUS. For such cases, we recommend that you use WPA Personal.
When to Use WPA Enterprise
Wi-Fi Protected Access Enterprise with
RADIUS
is an implementation of the Wi-Fi Alliance
IEEE
802.11i
standard, which includes AES-
CCMP
and
TKIP
mechanisms. This mode
requires the use of a RADIUS server to authenticate users. On the Unified Access Point, WPA
Enterprise provides the best security available for wireless networks.
This security mode also provides backwards-compatibility for wireless clients that support
only the original
WPA
.
Recommendations
WPA Enterprise mode is the
recommended mode
. The
AES-CCMP
and
TKIP
encryption
algorithms used with WPA modes are far superior to the
RC4
algorithm used for Static
WEP
or IEEE 802.1X modes. Therefore,
AES-CCMP
or TKIP should be used whenever possible.
All WPA modes allow you to use these encryption schemes, so WPA security modes are
recommended above the other modes when using WPA is an option.
Key Management
Encryption Algorithms
User Authentication
WPA Personal provides
dynamically-generated keys
that are periodically refreshed.
There are different
Unicast
keys for each station.
TKIP
AES-CCMP
The use of a
PSK
provides user
authentication similar to that of
shared keys in
WEP
.
Key Management
Encryption Algorithms
User Authentication
WPA Enterprise mode provides
dynamically-generated keys
that are periodically refreshed.
There are different
Unicast
keys for each station.
TKIP
AES-CCMP
RADIUS