Wpa/wpa2 enterprise (radius) – Allied Telesis AT-WA7400/EU User Manual
Page 123

AT-WA7400 Management Software User’s Guide
123
mode (CBC-CTR) and Cipher Block Chaining Message Authentication 
Code (CBC-MAC) for encryption and message integrity.
Both - When the authentication algorithm is set to Both, both TKIP and 
AES clients can associate with the access point. WPA clients must 
have one of the following to be able to associate with the access point:
A valid TKIP key
A valid CCMP (AES) key
Clients not configured to use a
WPA
-PSK cannot associate with the
access point.
Key
The Pre-shared Key is the shared secret key for 
WPA
-PSK. Enter a
string of at least 8 characters to a maximum of 63 characters.
2. Click Update to save your settings.
WPA/WPA2
Enterprise
(RADIUS)
Wi-Fi Protected Access 2 (
WPA2
) with Remote Authentication Dial-In User
Service (
RADIUS
) is an implementation of the Wi-Fi Alliance IEEE
802.11i
standard, which includes Advanced Encryption Standard (
AES
), Counter
mode/CBC-MAC Protocol (
CCMP
), and Temporal Key Integrity Protocol
(
TKIP
) mechanisms. The Enterprise mode requires the use of a RADIUS
server to authenticate users, and the configuration of user accounts using 
the Cluster > User Management page.
This security mode is backwards-compatible with wireless clients that 
support the original 
WPA
.
When you configure WPA2 Enterprise (RADIUS) mode, you have a choice 
of whether to use the built-in RADIUS server or an external RADIUS 
server that you provide. The AT-WA7400 Management Software built-in 
RADIUS server supports Protected 
EAP
(PEAP) and MSCHAP V2.
If you select the WPA/WPA2 Enterprise (RADIUS)
security mode
, the
settings in Table 39 are displayed:
