Extreme AP Wifi security question

  • 0
  • 2
  • Question
  • Updated 11 months ago
  • Answered
I am looking at all the various methods of Authentication and Encryption and am a bit confused after reading up about it. I havent seen anything saying how I can just set "WPA2-Personal" evel of security.

Can anyone point out which combo I should use to accomplish this?
Photo of Jacob Airov

Jacob Airov

  • 308 Points 250 badge 2x thumb

Posted 11 months ago

  • 0
  • 2
Photo of Christoph S.

Christoph S., Employee

  • 2,804 Points 2k badge 2x thumb
Hello Jacob,

Please advise model of AP and firmware version.

Regards
Photo of Jacob Airov

Jacob Airov

  • 308 Points 250 badge 2x thumb
Sorry about that!

We're using AP7532, WiNG v5.8
Photo of Christoph S.

Christoph S., Employee

  • 2,804 Points 2k badge 2x thumb
Thank you. 

Are these APs using Enterprise or Swift UI?
Photo of Jacob Airov

Jacob Airov

  • 308 Points 250 badge 2x thumb
No clue what either of those things are.  These were purchased from Zebra before Extreme bought the company...

We have a VX9000 controller that they are connected to and controlled by.
Photo of Christopher Frazee

Christopher Frazee, Employee

  • 1,782 Points 1k badge 2x thumb
For WPA2-Personal encryption, from the VX9000 UI, proceed to Wireless/Wireless LANs and add/edit WLAN. Proceed to Security and 'Select Authentication' should be PSK/NONE (WPA-Personal is encryption only). Scroll down to 'Select Encryption' and enable 'WPA2-CCMP' and under 'Key Settings', add the pre-shared key (passphrase). Once done, click on OK button then Commit/Save. 
Photo of Jacob Airov

Jacob Airov

  • 308 Points 250 badge 2x thumb
I knew the place in the UI, just didnt know the correct combo of authentication and encryption. Thank you.

So just so I have this straight-
At the top, the authentication section is only for using "WPA2-Enterprise", which is in connection to a RADIUS server
Then at the bottom, the encryption section is for other methods of security- WPA, WPA2, WEP (and all their current varieties)

Correct?
Photo of Christoph S.

Christoph S., Employee

  • 2,804 Points 2k badge 2x thumb
Hello Jacob,

From the "Select Authentication" option you can choose either personal (PSK / None) or Enterprise (EAP, etc..). Once you select PSK / None you scroll down to "Select Encryption" and in your case choose the WPA2-CCMP radio button. After you do this, the page will expand to allow you to add the Pre-shared key (passphase). At this point configure your pre-shared key and hit OK first, then commit and Save. 



I hope this helps.

Thank you,
Photo of Ondrej Lepa

Ondrej Lepa, Employee

  • 5,280 Points 5k badge 2x thumb
HI Jacob,

for deep understanding of this topic I'd recommend you to read CWSP book.

In short - WPA2-PSK (pre-shared key / personal) is always recommended choice unless you need to deploy Enterprise grade of security (WPA2-Enterprise)
By "unless you need" you can understand "AAA solution is available / required"

Regards,
Ondrej