Madge Networks 802.11b Bedienungsanleitung Seite 2

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 3
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 1
The WLAN Enterprise Access
Server has two modes of
operation:
• In Gateway Mode the WLAN
Enterprise Access Server requires
two network interfaces, one for
connection to the wired network
and the other for connecting to
the wireless network (i.e. to the
Access Points). This is the most
secure installation method as the
wired network is separated from
the Wireless network using the
included Firewall functionality.
• In Controller Mode the
WLAN Enterprise Access Server
requires only a single network
interface for connecting to the
LAN. This mode provides greater
scalability than Gateway Mode
and is recommended for larger
installations.
©2005 Madge Limited
Enterprise Class Security
Management
The WLAN Enterprise Access Server
implements industry standard
security mechanisms that guard
the enterprise data from wireless
intrusion – for example it fully
supports 802.1x using EAP-TLS,
which, with its mutual certificate
authentication, is recognized as the
strongest authentication solution.
Put simply, once an Access Point is
under the control of the Enterprise
Access Server, and 802.1x policy is
applied, that Access Point will block
any non-authenticated wireless
client from connecting to your wired
network.
Simple Set Up
By integrating both RADIUS
server and Certificate Authority
functionality into the Access Server,
the user can create certificates for
clients and choose overall policy
with a few mouse clicks. The
RADIUS server, which is used to
authenticate clients, is completely
transparent and requires no user
configuration, while the Certificate
Authority lets you generate
certificates for clients within seconds
of starting the server for the first
time – a real benefit compared to
other systems.
As part of your security regime, you
can also set up the following:
• MAC address Access Control Lists
allowing or denying specific clients
to connect to your Access Points.
Radius MAC is supported.
• The type of WEP encryption to
use for all clients. Note that under
802.1x you can rely on automatic
WEP key management, so there is
no more typing long key strings into
all your devices.
• Firewall Services to enable or deny
access to particular IP ports and
services.
• Virtual Private Networking
(VPN) to allow IPSec clients
to communicate using highly
secure tunnels over the wireless
connection.
Integrates Easily Into An
Existing Network
The WLAN Enterprise Access Server
can be integrated into existing
network management systems using
the SNMP interface. The Wireless
network can be closely monitored
and easily maintained using the
comprehensive statistics and event
logging, group management and
software upgrade features.
802.11 Access Point
Management
New Loadable Modules, supporting
the control and monitoring of
additional 802.11a/b/g Access
Points from multiple vendors can be
added at any time without having
to re-load the entire software
application. Access Points from
Cisco, Proxim, Symbol, D-Link,
3Com, Intel, Avaya and Madge can
currently be managed.
Management Tools
Policy-Based Management
The administration of wireless
networks with multiple users,
wireless devices and Access Points
is simplified by using policy-based
management. This allows users,
wireless devices and Access Points
to have key features and platform
parameters set up for each group,
rather than having to set each
element individually.
Secure Web-Based Management
The wireless network can be
managed from a web browser using
its web management interface. This
can be run over a secure link using
HTTPS to prevent unauthorized
users attempting to change the
configuration of the wireless
network.
Statistics and Event Logging
Events and alerts are automatically
logged and can be viewed from
the browser user interface. This
can be used for monitoring the
performance of the wireless network
and logging, for example, user
connections and disconnections.
Security Features
Certificate Management
Standard digital certificates are
used in order to provide the highest
levels of security using 802.1x. The
WLAN Enterprise Access Server
includes a Certificate Authority (CA)
for generating the certificates (for
both clients and servers) and it also
allows certificates to be imported
from external Certificate Authorities.
Security Wizard
A Security Wizard is included to
allow different security policies
to be rapidly implemented. Three
standard settings, ultra-secure,
normal and low are pre-configured,
but of course, the user can also
customize the settings. The Security
Wizard guides the Network Manager
through all the tasks required to
implement each level of security.
The WLAN Enterprise Access Server
provides central management of
the entire wireless network avoiding
the need to manage each access
point individually (except where
desirable; for example, setting up
an RF channel allocation plan to
avoid cross-AP interference).
Admin Security
As all management of the Access
Server is executed through a
standard Web Browser, Network
Managers must use a username and
password to gain access. HTTPS
can be specified to allow secure
management of the server.
Device
Wireless clients are denied a
connection to the wireless network
until authorized. All wireless devices
are identified by a unique number
(i.e. MAC address of an 802.11
device) and the WLAN Enterprise
Access Server centrally manages
these addresses and configures the
Access Points accordingly, thereby
providing the protection at the
Seitenansicht 1
1 2 3

Kommentare zu diesen Handbüchern

Keine Kommentare