Security - 3Com 3CRWEASYA73 User Manual

3com outdoor 11a building to building bridge and 11bg access point
Hide thumbs Also See for 3CRWEASYA73:
Table of Contents

Advertisement

C
5: S
C
HAPTER
YSTEM
ONFIGURATION
S
ECURITY
The access point is configured by default as an "open system," which broadcasts
a beacon signal including the configured SSID. Wireless clients with an SSID
setting of "any" can read the SSID from the beacon and automatically set their
SSID to allow immediate connection to the nearest access point.
To improve wireless network security, you have to implement two main functions:
For a more secure network, the access point can implement one or a combination
of the following security mechanisms:
Both WEP and WPA security settings are configurable separately for each virtual
access point (VAP) interface. MAC address filtering, and RADIUS server settings
are global and apply to all VAP interfaces.
The security mechanisms that may be employed depend on the level of security
required, the network and management resources available, and the software
support provided on wireless clients.
A summary of wireless security considerations is listed in the following table.
Table 4 Wireless Security Considerations

Security

Mechanism
WEP
WEP over 802.1X
MAC Address
Filtering
Authentication: It must be verified that clients attempting to connect to the
network are authorized users.
Traffic Encryption: Data passing between the access point and clients must be
protected from interception and eavesdropping.
Wired Equivalent Privacy (WEP)
IEEE 802.1x
Wireless MAC address filtering
Wi-Fi Protected Access (WPA or WPA2)
Client Support
Built-in support on all 802.11a
and 802.11g devices
Requires 802.1X client support
in system or by add-in software
(support provided in Windows
2000 SP3 or later and Windows
XP)
Uses the MAC address of client
network card
page 5-50
page 5-57
page 5-12
page 5-57
Implementation Considerations
• Provides only weak security
• Requires manual key management
• Provides dynamic key rotation for improved WEP
security
• Requires configured RADIUS server
• 802.1X EAP type may require management of
digital certificates for clients and server
• Provides only weak user authentication
• Management of authorized MAC addresses
• Can be combined with other methods for
improved security
• Optionally configured RADIUS server
5-50

Advertisement

Table of Contents
loading

This manual is also suitable for:

Wl-575

Table of Contents