Netgear WAX620 User Manual - Page 73

Allow Devices to Connect with Open, WPA2 Personal, Passphrase, WPA2 Enterprise, Encryption, TKIP + AES

Page 73 highlights

Insight Cloud Managed WiFi 6 AX3600 Access Point Model WAX620 and clients that do not. For clients that do not support the WiFi open enhanced feature, traffic is not encrypted. If you clear the Allow Devices to Connect with Open check box, the WiFi network can only accept clients that support the WiFi enhanced open feature. • WPA2 Personal: This option, which is the same as WPA2-PSK, is the default setting and uses AES encryption. This type of security enables only WiFi devices that support WPA2 to join the VAP. WPA2 provides a more secure connection than WPA but some legacy WiFi devices do not detect WPA2 and support only WPA. If your network includes such older devices, select WPA2/WPA Personal authentication. In the Passphrase field, enter a phrase of 8 to 63 characters. To join the VAP, a user must enter this passphrase. To view the passphrase in clear text, click the eye icon. • WPA2/WPA Personal: This option, which is the same as WPA2-PSK/WPA-PSK, enables WiFi devices that support either WPA2 or WPA to join the VAP. This option uses AES and TKIP encryption. WPA-PSK (which uses TKIP) is less secure than WPA2-PSK (which uses AES) and limits the speed of WiFi devices to 54 Mbps. In the Passphrase field, enter a phrase of 8 to 63 characters. To join the VAP, a user must enter this passphrase. To view the passphrase in clear text, click the eye icon. • WPA2 Enterprise: This enterprise-level security uses RADIUS for centralized Authentication, Authorization, and Accounting (AAA) management. For WPA2 Enterprise security to function, you must set up RADIUS servers (see Set up RADIUS servers on page 129). From the Encryption menu, select the data encryption mode: - TKIP + AES: This type of data encryption enables WiFi devices that support either WPA or WPA2 to join the access point's WiFi network. This is the default mode. - AES: This type of data encryption provides a secure connection but some older WiFi devices do not detect WPA2 and support only WPA. Therefore, if your network includes such older devices, select TKIP + AES encryption. When you select WPA2 Enterprise authentication, the Dynamic VLAN radio buttons display: - Enable: The RADIUS server can assign a VLAN ID to clients. If the RADIUS server does not do so, the clients are automatically assigned the VLAN ID that you configured for the SSID. - Disable: The clients are assigned the VLAN ID that you configured for the SSID. This is the default setting. Manage the Basic WiFi Features 73 for a WiFi network User Manual

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266

and clients that do not. For clients that do not support the WiFi open enhanced
feature, traffic is not encrypted.
If you clear the
Allow Devices to Connect with Open
check box, the WiFi
network can only accept clients that support the WiFi enhanced open feature.
WPA2 Personal
: This option, which is the same as WPA2-PSK, is the default
setting and uses AES encryption. This type of security enables only WiFi devices
that support WPA2 to join the VAP.
WPA2 provides a more secure connection than WPA but some legacy WiFi devices
do not detect WPA2 and support only WPA. If your network includes such older
devices, select
WPA2/WPA Personal
authentication.
In the
Passphrase
field, enter a phrase of 8 to 63 characters. To join the VAP, a
user must enter this passphrase. To view the passphrase in clear text, click the
eye icon.
WPA2/WPA Personal
: This option, which is the same as WPA2-PSK/WPA-PSK,
enables WiFi devices that support either WPA2 or WPA to join the VAP. This
option uses AES and TKIP encryption.
WPA-PSK (which uses TKIP) is less secure than WPA2-PSK (which uses AES) and
limits the speed of WiFi devices to 54 Mbps.
In the
Passphrase
field, enter a phrase of 8 to 63 characters. To join the VAP, a
user must enter this passphrase. To view the passphrase in clear text, click the
eye icon.
WPA2 Enterprise
: This enterprise-level security uses RADIUS for centralized
Authentication, Authorization, and Accounting (AAA) management. For WPA2
Enterprise security to function, you must set up RADIUS servers (see Set
up
RADIUS
servers
on page 129).
From the
Encryption
menu, select the data encryption mode:
-
TKIP + AES
: This type of data encryption enables WiFi devices that support
either WPA or WPA2 to join the access point’s WiFi network. This is the default
mode.
-
AES
: This type of data encryption provides a secure connection but some
older WiFi devices do not detect WPA2 and support only WPA. Therefore, if
your network includes such older devices, select
TKIP + AES
encryption.
When you select
WPA2 Enterprise
authentication, the
Dynamic VLAN
radio
buttons display:
-
Enable
: The RADIUS server can assign a VLAN ID to clients. If the RADIUS
server does not do so, the clients are automatically assigned the VLAN ID that
you configured for the SSID.
-
Disable
: The clients are assigned the VLAN ID that you configured for the
SSID. This is the default setting.
User Manual
73
Manage the Basic WiFi Features
for a WiFi network
Insight Cloud Managed WiFi 6 AX3600 Access Point Model WAX620