Setup WPA2 (Wi Fi Protected Access 2)

·         Introduction

·         Setting up the Access Point

·         Setting up the Station


Introduction

WPA2 is the short name of WiFi Protected Access 2 and it was developed by Wi Fi alliance.

WPA2 is based on IEEE 802.11i standard and launched in Sep. 2004.The obvious differentiation from WPA2 compare to WEP is adding the “Access control” and “Data Encryption algorithm” enhancement. The authentication utility can be based on 802.1x external authentication server or using pre-share key. WPA2 employed AES(Advanced Encryption Standard) as his data encryption algorithm.

How it works?

The AP blocks access to the network until the user can be authenticated. The user provides credentials which are communicated to the authentication server. The authentication process is enabled by the IEEE 802.1X/EAP framework. With EAP, IEEE 802.1X creates a framework in which client workstations and the authentication server mutually authenticate with one another via the AP. Mutual authentication helps to ensure that only authorized users access the network and confirms that the client is authenticating to an authorized server. It helps to protect users from accidentally connecting to unauthorized ‘rogue’ APs.

If the authentication server accepts the user’s credentials, the client joins the WLAN. If not, the client remains blocked. Once the user has been authenticated, the authentication server and the client simultaneously generate a Pairwise Master Key (PMK).

A 4-way handshake then takes place between the client and the AP, to complete the process of authenticating the AP with the client, establishing and installing the TKIP (WPA) or AES (WPA2) encryption keys. As the client begins communicating on the LAN, encryption protects the data exchanged between the client and the AP.

Figure 1. The 4-way handshake process



Setting up the Access Point

User can set up the Access Point by Web GUI configuration and there are two types of WPA2 support.


  • WPA2

User needs to set up an external authentication server when using WPA2 encryption method.

User has to input the authentication server IP address and port number under Wireless>Security>Authentication Server. User can input a shared secret for authorized purpose between AP and external authentication server or leave blank when no demand.

For security concern, the AP will request the station do a reauthentication after specific time period and user can adjust the reauthentication time according to the security sensitive level.

For example,

 

 


  • WPA2 - PSK

The WPA2 – PSK is used the pre-share key for data encryption and this deployment is based on the AP and stations all known the key before associate.

The WPA2 is using the AES encryption algorithm and this is more security than WEP that was already known an insecurity algorithm. We still recommend user who has high security level desired used the WPA2-PSK when they didn’t have an external authentication server in the network architecture.

For example,




Setting up the Station

We will provide user an application guide to setup the station to associate with AP that WPA2 and WPA2 enabled.

The station utility is the Windows XP SP2 build-in one.

For the utility download, please visit official Microsoft website

Link: http://support.microsoft.com/?id=893357#appliesto 


  • Station enable WPA2

I. Enable the wireless utility

  Step 1.Double click the wireless icon at the windows toolbar

  Step 2.Click the “Change advanced settings” option

 

II. Configure the Authentication mode and data encryption algorithm

  Step 1.Move to the “Wireless Networks” sub menu.

  Step 2.Click “Add..” button

  Step 3.The new window pop up and then fill in the SSID in the “Network name” field.

  Step 4.Select the Network Authentication type as WPA2.

  Step 5.Select the AES in the Data encryption option, the configuration will be WPA2 with AES encryption algorithm.

III. Setup the external authentication server type

  Step 1.Move to “Authentication” sub menu.

  Step 2.Select Protected EAP(PEAP) as EAP type.

  Step 3.Click the “Properties” button.

  Step 4.Uncheck the “Validate server certificate” check box.

  Step 5.Click the “Configure..” button.

  Step 6.Uncheck the “Automatically use my Windows login name and password(and domain if any)” check box.

IV. Associate with the AP

  Step 1.The station will start to associate with AP and the authentication reminder will popup once the station get the signal from AP.

  Step 2.Input the user name.

  Step 3.Input the password.

  Step 4.The success connection message will popup after user successful pass the authentication check.

V. Done and station can associate with AP using WPA2 with external authentication server.


  • Station enable WPA2 - PSK

The step by step configuration for WPA2 – PSK is easier then pervious one and the steps list as follow;

I. Enable the wireless utility

  Step 1.Double click the wireless icon at the windows toolbar

  Step 2.Click the “Change advanced settings” option

 

II. Configure the Authentication mode and data encryption algorithm

  Step 1.Move to the “Wireless Networks” sub menu.

  Step 2.Click “Add..” button

  Step 3.The new window pop up and then fill in the SSID in the “Network name” field.

  Step 4.Select the Network Authentication type as WPA2 - PSK.

  Step 5.Select the AES in the Data encryption option and the configuration will be WPA2 - PSK with AES encryption algorithm.

  Step 6.Input and double confirm the pre share key in these two fields and please make sure this key is exactly same as the associated AP.

III. Done and station can associate with AP using WPA2 - PSK.

 


All contents copyright © 2006 ZyXEL Communications Corporation.