SMC Networks EliteConnect SMC2891W-AG User Manual page 123

802.11a/g outdoor enterprise access point
Hide thumbs Also See for EliteConnect SMC2891W-AG:
Table of Contents

Advertisement

To improve wireless network security, you have to implement two main functions:
• Authentication: It must be verified that clients attempting to connect to the network
are authorized users.
• Traffic Encryption: Data passing between the access point and clients must be
protected from interception and eavesdropping.
For a more secure network, the access point can implement one or a combination of
the following security mechanisms:
• Wired Equivalent Privacy (WEP)
• IEEE 802.1X
• Wireless MAC address filtering
• Wi-Fi Protected Access (WPA or WPA2)
Both WEP and WPA security settings are configurable separately for each virtual
access point (VAP) interface. MAC address filtering, and RADIUS server settings
are global and apply to all VAP interfaces.
The security mechanisms that may be employed depend on the level of security
required, the network and management resources available, and the software
support provided on wireless clients.
A summary of wireless security considerations is listed in the following table.
Security
Client Support
Mechanism
WEP
Built-in support on all 802.11a
and 802.11g devices
WEP over 802.1X Requires 802.1X client support
in system or by add-in software
(support provided in Windows
2000 SP3 or later and Windows
XP)
MAC Address
Uses the MAC address of client
Filtering
network card
WPA over 802.1X
Requires WPA-enabled system
Mode
and network card driver
(native support provided in
Windows XP)
Table 6-2. Wireless Security Considerations
page 6-71
page 6-86
page 6-13
page 6-81
Implementation Considerations
• Provides only weak security
• Requires manual key management
• Provides dynamic key rotation for improved WEP
security
• Requires configured RADIUS server
• 802.1X EAP type may require management of
digital certificates for clients and server
• Provides only weak user authentication
• Management of authorized MAC addresses
• Can be combined with other methods for improved
security
• Optionally configured RADIUS server
• Provides robust security in WPA-only mode
(i.e., WPA clients only)
• Offers support for legacy WEP clients, but with
increased security risk (i.e., WEP authentication
keys disabled)
• Requires configured RADIUS server
• 802.1X EAP type may require management of
digital certificates for clients and server
6
Radio Interface
6-71

Advertisement

Table of Contents
loading

This manual is also suitable for:

Eliteconnect smc2890w-ag2890w-ag2891w-ag

Table of Contents