Siemens EF 711 Series Podręcznik Użytkownika Strona 24

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 492
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 23
Overview of the SCALANCE WLC711 Solution
SCALANCE WLC711 and Your Network
SCALANCE WLC711
1-8 C79000-G8976-C260-03, 07/2012, User Guide, V8.11
encapsulates the packets and forwards them to the SCALANCE IWLAN Controller. The
SCALANCE IWLAN Controller decapsulates the packets and routes these to destinations on the
network. In a typical configuration, access points can be configured to locally bridge traffic (to a
configured VLAN) directly at their network point of attachment.
The SCALANCE IWLAN Controller functions like a standard L3 router or L2 switch. It is
configured to route the network traffic associated with wireless connected users. The SCALANCE
IWLAN Controller can also be configured to simply forward traffic to a default or static route if
dynamic routing is not preferred or available.
Network Security
The SCALANCE WLC711 system provides features and functionality to control network access.
These are based on standard wireless network security practices.
Current wireless network security methods provide protection. These methods include:
Shared Key authentication that relies on Wired Equivalent Privacy (WEP) keys
Open System that relies on Service Set Identifiers (SSIDs)
802.1x that is compliant with Wi-Fi Protected Access (WPA)
Captive Portal based on Secure Sockets Layer (SSL) protocol
The SCALANCE WLC711 system provides the centralized mechanism by which the
corresponding security parameters are configured for a group of users.
Wired Equivalent Privacy (WEP) is a security protocol for wireless local area networks
defined in the 802.11b standard
Wi-Fi Protected Access version 1 (WPA1™) with Temporal Key Integrity Protocol (TKIP)
Wi-Fi Protected Access version 2 (WPA2™) with Advanced Encryption Standard (AES) and
Counter Mode with Cipher Block Chaining Message Authentication Code (CCMP)
Authentication
The SCALANCE IWLAN Controller relies on a RADIUS server, or authentication server, on the
enterprise network to provide the authentication information (whether the user is to be allowed or
denied access to the network). A RADIUS client is implemented to interact with infrastructure
RADIUS servers.
The SCALANCE IWLAN Controller provides authentication using:
Captive Portal — a browser-based mechanism that forces users to a Web page
RADIUS (using IEEE 802.1x)
The 802.1x mechanism is a standard for authentication developed within the 802.11 standard. This
mechanism is implemented at the wireless port, blocking all data traffic between the wireless
device and the network until authentication is complete. Authentication by 802.1x standard uses
Extensible Authentication Protocol (EAP) for the message exchange between the SCALANCE
IWLAN Controller and the RADIUS server.
When 802.1x is used for authentication, the SCALANCE IWLAN Controller provides the
capability to dynamically assign per-wireless-device WEP keys (called per session WEP keys in
802.11). In the case of WPA, the SCALANCE IWLAN Controller is not involved in key assignment.
Instead, the controller is involved in the information exchange between RADIUS server and the
users wireless device to negotiate the appropriate set of keys. With WPA2 the material exchange
Przeglądanie stron 23
1 2 ... 19 20 21 22 23 24 25 26 27 28 29 ... 491 492

Komentarze do niniejszej Instrukcji

Brak uwag