3 Detailed checklist
Checklist
Article ID: 109745536, V2.0, 05/2022
21
©
S
iem
e
n
s A
G
2
0
2
2
A
ll r
igh
ts
re
se
rv
e
d
3.12
Wireless LAN
3.12.1
WLAN encryption
Menu path
You can find this information in IWLAN devices in the following menu:
"Security > WLAN > Basic".
Recommendation
Enable "WPA2 with AES" encryption.
Note
Do not use WEP encryption due to its severe design flaws. WEP is generally no
longer selectable as of firmware V6.0.
"Preshared Key" encryption only protects against external threats. Other clients
that use the same password could still decrypt the data traffic.
Use secure protocols over the wireless link as well.
3.12.2
WLAN layer-2 tunnel
Menu path
You can find this information in IWLAN devices in the following menu:
"Interfaces > WLAN > Client ".
Recommendation
Set the MAC mode to "Layer 2 Tunnel" if the client and the access point are
SCALANCE W devices.
Note
As of firmware V6.0, "Layer 2 Tunnel" is the default setting once you enable the
"iPCF" function.
Note
The "Layer 2 Tunnel" setting causes the access point to receive the real MAC
addresses of the devices behind the client, not just the client MAC address.
If you use the "Layer 2 Tunnel" MAC mode, you can connect up to eight nodes or
MAC addresses to the client.
Note
This function is proprietary on SCALANCE devices and cannot be used with
access points from third-party vendors.