in

WPA security

Last post Sun, Jul 5 2009 3:27 AM by nics. 9 replies.
Page 1 of 1 (10 items)
Sort Posts: Previous Next
  • Wed, Nov 12 2008 2:50 PM

    • jnaker
    • Top 50 Contributor
    • Joined on Thu, Aug 21 2008
    • Posts 16

    WPA security

    The access point i am associated with uses WPA Aes security.  I set my cpe 2-15 to WPA psk and things seem to run fine, but where can i find an explination as to all the other optional wpa and wpa2 modes the 2-15 offers? 

     

    Filed under: , ,
  • Wed, Nov 12 2008 3:55 PM In reply to

    • ScottReed
    • Top 25 Contributor
    • Joined on Thu, Jan 31 2008
    • Montana
    • Posts 40

    Re: WPA security

    The main difference between WPA and WPA2 is the underlying encryption method. A Google search for wpa wpa2 differences will give you some clues. Whatever the encryption method is set to on the AP your CPE needs to mimic to be able to connect. All the WPA and WPA2 are doing is encrypting the traffic between your site and the AP so someone sniffing wireless traffic cannot decypher your communications - but nothing is fool proof. You cannot change your encryption method at your CPE if the AP does not change to the same method. Understand?

    Keep in mind that the only secure method of wireless connectivity is terminating with some sort of authentication and then passing all the traffic through a VPN solution.

    Scott

    --
    Scott Reed
    Bozeman, MT
    scott [dot] srts [at] gmail [dot] com
  • Wed, Nov 12 2008 4:10 PM In reply to

    • jnaker
    • Top 50 Contributor
    • Joined on Thu, Aug 21 2008
    • Posts 16

    Re: WPA security

    I understand all that, my question is the different versions of WPA and WPA2 the the cpe lists ie: peap,eap,ccmp etc?  We understand making the ap and cpe the same and have been heavily involved in setting our AP's to be compatible with VISTA.  Vista machines connecting via usb adapters were very unstable using TKIP and after changing to AES they all connected and stayed associated.  But I was uncertain what the other deliberant cpe modes stated above were for.  No documentation seems available explaining those. The AP does not have the peap,eap or ccmp otions, just TKIP and AES other than using a radius server which we don’t.  So any ideas what the extra modes are?
    Thanks
    JIm

     

  • Wed, Nov 12 2008 4:18 PM In reply to

    Re: WPA security

    There are different types of authentication (802.1x) that you can use in conjuction with WPA/WPA2, if you don't want to use a pre-shared key. If the AP supports these authentication methods, you can set the CPE to associate with a username/password rather than one preshared key. These are authenticated against RADIUS at the AP level, and this controls associations.

    The current AP software does not include the 802.1x features yet in the wireless security, but it will be added soon. What will the configuration of your AP look like? Will it just be an AP in bridge mode, or will it have any other configurations?

  • Sat, Jun 27 2009 1:26 AM In reply to

    • nics
    • Top 150 Contributor
    • Joined on Sat, May 2 2009
    • Posts 4

    Re: WPA security

     Hi Matt,

     Do you mean current firmware is not supporting WPA EAP? 

     Your AP-2i product  manual states that you support WPA/WPA2 Personal/Enterprise?

     http://www.deliberant.com/estore/web/datasheets/Deliberant%20AP%202i%20Datasheet.pdf

     Can you please advise how to set AP2i operating at WPA EAP? Current list box only states PSK versions:

     -WPA-PSK-CCMP 

     -WPA-PSK-TKIP

     -WPA2-PSK-CCMP 

     -WPA2-PSK-TKIP

     

  • Mon, Jun 29 2009 10:51 AM In reply to

    Re: WPA security

    Well, technically it does support it. However, it's not listed as a security option in the drop down in the currently loaded GUI.

    There are two ways to add WPA2 Enterprise:

    • By using Expert mode and adding appropriate AAA sections
    • You can load the simple AP skin which allows creating virtual interfaces, setting up UAM (hotspot), and creating 802.1x AAA profiles. However the simple AP skin does not contain Router mode, or allow setting interfaces to client mode etc. 

    Will one of these methods work?

    -Matt

  • Tue, Jun 30 2009 10:24 PM In reply to

    • nics
    • Top 150 Contributor
    • Joined on Sat, May 2 2009
    • Posts 4

    Re: WPA security

    Hi Matt,

    Thanks for prompt reply.

    Can you please point to any documentation that explains setting up AAA section in Expert mode?

    Any recommendation of 'simple AP skin' and where to download from?

    THanks.

     

  • Tue, Jun 30 2009 10:40 PM In reply to

    Re: WPA security

    Hi,

    Here's the latest simple AP skin (see attachment)...

  • Tue, Jun 30 2009 10:55 PM In reply to

    And here is documentation for AAA:

    http://wiligear.com/wiki/index.php/WILI-S_5.24_Reference_Manual#AAA_.28Authentication_Authorization_and_Accounting.29

    Also see attached for a configuration file example for WPA2 Enterprise against RADIUS server. 

    -Matt

  • Sun, Jul 5 2009 3:27 AM In reply to

    • nics
    • Top 150 Contributor
    • Joined on Sat, May 2 2009
    • Posts 4

    Re: WPA security

    Hi Matt,

    Looks like the link to the cfg file is not working. =(

    I did play around with WILI-S AP skin, but got lost when setting up VLAN config. I understand the concept of VLAN, but am quite lost when setting the config up. Is there any tutorial that outlines different set of network config and how to set them up?

     Do you know any skin that would expose the full functionality of WILI-s product, i.e. WILI AP + WILI O + WILI MESH?

     Thanks

Page 1 of 1 (10 items)
Copyright Deliberant LLC. All rights reserved.