ZyXEL NWA50AX User Guide - Page 114

Show Advanced Settings, LABEL, DESCRIPTION, enhanced-open, wpa2-mix, Security Mode

Page 114 highlights

Chapter 12 AP Profile Table 47 Configuration > Object > AP Profile > SSID > Security List > AAdd/Edit Security Profile> Security Mode: wpa3 (continued) LABEL DESCRIPTION Security Mode Select a security mode from the list: none, enhanced-open, wep, wpa2, wpa2-mix or wpa3. Authentication Settings Personal enhanced-open uses Opportunistic Wireless Encryption (OWE) which encrypts the wireless connection when possible. This field is available when you select the wpa2, wpa2-mix or wpa3 security mode. Pre-Shared Key Transition Mode Select this option to use a Pre-Shared Key (PSK) with WPA2 encryption or Simultaneous Authentication of Equals (SAE) with WPA3 encryption. Enter a pre-shared key of between 8 and 63 case-sensitive ASCII characters (including spaces and symbols) or 64 hexadecimal characters. Enable this for backwards compatibility. This option is only available if the Security Mode is wpa3 or enhanced-open. This creates two virtual APs (VAPs) with a primary (wpa3 or enhanced-open) and fallback (wpa2 or none) security method. Advance If the Security Mode is wpa3, enabling this will force Management Frame Protection to be set to Optional. If this is disabled or if the Security Mode is enhanced-open, Management Frame Protection will be set to Required. Note: Click on the Show Advanced Settings button to show the fields describe below. Idle Timeout Group Key Update Timer Pre-Authentication Management Frame Protection Enter the idle interval (in seconds) that a client can be idle before authentication is discontinued. Enter the interval (in seconds) at which the AP updates the group WPA2 encryption key. Select Enable to allow pre-authentication. Otherwise, select Disable. This field is available only when you select wpa2 in the Security Mode field and set Cipher Type to aes. Data frames in 802.11 WLANs can be encrypted and authenticated with WEP, WPA or WPA2. But 802.11 management frames, such as beacon/probe response, association request, association response, de-authentication and disassociation are always unauthenticated and unencrypted. IEEE 802.11w Protected Management Frames allows APs to use the existing security mechanisms (encryption and authentication methods defined in IEEE 802.11i WPA/WPA2) to protect management frames. This helps prevent wireless DoS attacks. Select the check box to enable management frame protection (MFP) to add security to 802.11 management frames. Select Optional if you do not require the wireless clients to support MFP. Management frames will be encrypted if the clients support MFP. OK Cancel Select Required and wireless clients must support MFP in order to join the Zyxel Device's wireless network. Click OK to save your changes back to the Zyxel Device. Click Cancel to exit this screen without saving your changes. NWA50AX User's Guide 114

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256

Chapter 12 AP Profile
NWA50AX User’s Guide
114
Security Mode
Select a security mode from the list:
none
,
enhanced-open
,
wep
,
wpa2
,
wpa2-mix
or
wpa3
.
enhanced-open
uses Opportunistic Wireless Encryption (OWE) which encrypts the
wireless connection when possible.
Authentication Settings
Personal
This field is available when you select the
wpa2
,
wpa2-mix
or
wpa3
security mode.
Select this option to use a Pre-Shared Key (PSK) with WPA2 encryption or Simultaneous
Authentication of Equals (SAE) with WPA3 encryption.
Pre-Shared Key
Enter a pre-shared key of between 8 and 63 case-sensitive ASCII characters (including
spaces and symbols) or 64 hexadecimal characters.
Transition Mode
Enable this for backwards compatibility. This option is only available if the
Security Mode
is
wpa3
or
enhanced-open
. This creates two virtual APs (VAPs) with a primary (
wpa3
or
enhanced-open
) and fallback (
wpa2
or
none
) security method.
If the
Security Mode
is
wpa3
, enabling this will force
Management Frame Protection
to be
set to
Optional
. If this is disabled or if the
Security Mode
is
enhanced-open
,
Management
Frame Protection
will be set to
Required
.
Advance
Note: Click on the
Show Advanced Settings
button to show the fields describe below.
Idle Timeout
Enter the idle interval (in seconds) that a client can be idle before authentication is
discontinued.
Group Key Update
Timer
Enter the interval (in seconds) at which the AP updates the group WPA2 encryption key.
Pre-Authentication
Select
Enable
to allow pre-authentication. Otherwise, select
Disable
.
Management Frame
Protection
This field is available only when you select
wpa2
in the
Security Mode
field and set
Cipher
Type
to
aes
.
Data frames in 802.11 WLANs can be encrypted and authenticated with WEP, WPA or
WPA2. But 802.11 management frames, such as beacon/probe response, association
request, association response, de-authentication and disassociation are always
unauthenticated and unencrypted. IEEE 802.11w Protected Management Frames allows
APs to use the existing security mechanisms (encryption and authentication methods
defined in IEEE 802.11i WPA/WPA2) to protect management frames. This helps prevent
wireless DoS attacks.
Select the check box to enable management frame protection (MFP) to add security to
802.11 management frames.
Select
Optional
if you do not require the wireless clients to support MFP. Management
frames will be encrypted if the clients support MFP.
Select
Required
and wireless clients must support MFP in order to join the Zyxel Device’s
wireless network.
OK
Click
OK
to save your changes back to the Zyxel Device.
Cancel
Click
Cancel
to exit this screen without saving your changes.
Table 47
Configuration > Object > AP Profile > SSID > Security List > AAdd/Edit Security Profile> Security
Mode: wpa3 (continued)
LABEL
DESCRIPTION