When To Use Wpa Personal - Psion Teklogix 9160 G2 User Manual

Wireless gateway
Hide thumbs Also See for 9160 G2:
Table of Contents

Advertisement

Chapter 10: Configuring Security
Comparison Of Security Modes For Key Management, Authentication And Encryption Algorithms
Table 10.2 IEEE 801.1x Security Mode
Key Management
IEEE 802.1x provides dynami-
cally-generated keys that are
periodically refreshed.
There are different Unicast keys
for each station.
Recommendations
IEEE 802.1x mode is a better choice than Static WEP because keys are dynamically gener-
ated and changed periodically. However, the encryption algorithm used is the same as that of
Static WEP and is therefore not as reliable as the more advanced encryption methods such as
TKIP and CCMP (AES) used in Wi-Fi Protected Access (WPA) or WPA2.
Additionally, compatibility issues may be cumbersome because of the variety of authentica-
tion methods supported and the lack of a standard implementation method.
Therefore, IEEE 802.1x mode is not as secure a solution as Wi-Fi Protected Access (WPA)
or WPA2. If you cannot use WPA because some of your client stations do not have WPA,
then a better solution than using IEEE 802.1x mode is to use WPA Enterprise mode.
If you have an external
than the using the embedded RADIUS server on the AP. An external RADIUS server will
provide better security than the local authentication server.
See Also
For information on how to configure IEEE 802.1x security mode, see "IEEE 802.1x" on
page 108.

10.1.2.4 When To Use WPA Personal

Wi-Fi Protected Access Personal Pre-Shared Key (PSK) is an implementation of the Wi-Fi
Alliance IEEE 802.11h standard, which includes Advanced Encryption Algorithm (AES),
Counter mode/CBC-MAC Protocol (CCMP), and Temporal Key Integrity Protocol (TKIP)
mechanisms. This mode offers the same encryption algorithms as WPA 2 with RADIUS but
without the ability to integrate a RADIUS server for user authentication.
96
Psion Teklogix 9160 G2 Wireless Gateway User Manual
Encryption Algorithm
An RC4 stream cipher is used to
encrypt the frame body and cyclic
redundancy checking (CRC) of each
802.11 frame.
RADIUS
server on your network, we recommend using it rather
User Authentication
IEEE 802.1x mode supports a variety of authenti-
cation methods, like certificates, Kerberos, and
public key authentication with a RADIUS server.
You have a choice of using the 9160 G2 Wireless
Gateway embedded RADIUS server or an external
RADIUS server. The embedded RADIUS server
supports Protected EAP (PEAP) and
MSCHAP V2.

Advertisement

Table of Contents
loading

Table of Contents