178
DWS-1008 User’s Manual
D-Link Systems, Inc.
Configuring User Encryption
178
D-Link Systems, Inc.
Configuring WPA
Wi-Fi Protected Access (WPA) is a security enhancement to the IEEE 802.11 wireless
standard. WPA provides enhanced encryption with new cipher suites and provides per-packet
message integrity checks. WPA is based on the 802.11i standard. You can use WPA with
802.1X authentication. If the client does not support 802.1X, you can use a preshared key on
the DWL-8200AP access point and the client for authentication.
WPA Cipher Suites
WPA supports the following cipher suites for packet encryption, listed from most secure to
least secure:
• Counter Mode with Cipher Block Chaining Message Authentication Code Protocol
(CCMP) - CCMP provides Advanced Encryption Standard (AES) data encryption.
To provide message integrity, CCMP uses the Cipher Block Chaining Message
Authentication Code (CBC-MAC).
• Temporal Key Integrity Protocol (TKIP) - TKIP uses the RC4 encryption algorithm, a
128-bit encryption key, a 48-bit initialization vector (IV), and a message integrity code
(MIC) called Michael.
• Wired Equivalent Privacy (WEP) with 104-bit keys - 104-bit WEP uses the RC4
encryption algorithm with a 104-bit key.
• WEP with 40-bit keys - 40-bit WEP uses the RC4 encryption algorithm with a 40-bit
key.
You can configure DWL-8200AP access points to support one or more of these cipher suites.
For all of these cipher suites, MSS dynamically generates unique session keys for each
session. MSS periodically changes the keys to reduce the likelihood that a network intruder
can intercept enough frames to decode a key.
TKIP Countermeasures
WPA access points and clients verify the integrity of a wireless frame received on the network
by generating a keyed message integrity check (MIC). The Michael MIC used with TKIP
provides a holddown mechanism to protect the network against tampering.
• If the recalculated MIC matches the MIC received with the frame, the frame passes
the integrity check and the access point or client processes the frame normally.
Summary of Contents for DWS-1008
Page 1: ......