TRENDnet TEW-453APB User Guide - Page 47

Using WPA-802.1x, Wireless Station Configuration, Radius Server Configuration

Page 47 highlights

Wireless Access Point User Guide Using WPA-802.1x This is the most secure and most complex system. 802.1x mode provides greater security and centralized management, but it is more complex to configure. Wireless Station Configuration For each of the following items, each Wireless Station must have the same settings as the Wireless Access Point. Mode SSID (ESSID) 802.1x Authentication 802.1x Encryption On each PC, the mode must be set to Infrastructure. This must match the value used on the Wireless Access Point. The default value is wireless Note! The SSID is case sensitive. Each client must obtain a Certificate which is used for authentication for the Radius Server. Typically, EAP-TLS is used. This is a dynamic key system, so keys do NOT have to be entered on each Wireless station. However, you can also use a static WEP key (EAP-MD5); the Wireless Access Point supports both methods simultaneously. Radius Server Configuration If using WPA-802.1x mode, the Radius Server on your network must be configured as follow: • It must provide and accept Certificates for user authentication. • There must be a Client Login for the Wireless Access Point itself. • The Wireless Access Point will use its Default Name as its Client Login name. (However, your Radius server may ignore this and use the IP address instead.) • The Shared Key, set on the Security Screen of the Access Point, must match the Shared Secret value on the Radius Server. • Encryption settings must be correct. 44

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115

Wireless Access Point User Guide
Using WPA-802.1x
This is the most secure and most complex system.
802.1x mode provides greater security and centralized management, but it is more complex to
configure.
Wireless Station Configuration
For each of the following items, each Wireless Station must have the same settings as the
Wireless Access Point.
Mode
On each PC, the mode must be set to
Infrastructure
.
SSID (ESSID)
This must match the value used on the Wireless Access Point.
The default value is
wireless
Note! The SSID is case sensitive.
802.1x
Authentication
Each client must obtain a Certificate which is used for authentication for
the Radius Server.
802.1x
Encryption
Typically, EAP-TLS is used. This is a dynamic key system, so keys do
NOT have to be entered on each Wireless station.
However, you can also use a static WEP key (EAP-MD5); the Wireless
Access Point supports both methods simultaneously.
Radius Server Configuration
If using
WPA-802.1x
mode, the Radius Server on your network must be configured as follow:
It must provide and accept
Certificates
for user authentication.
There must be a
Client Login
for the Wireless Access Point itself.
The Wireless Access Point will use its Default Name as its Client Login name. (How-
ever, your Radius server may ignore this and use the IP address instead.)
The
Shared Key
, set on the
Security
Screen of the Access Point, must match the
Shared Secret
value on the Radius Server.
Encryption
settings must be correct.
44