Ch. 5 – Access Points. Overview Access Point Connection.

Slides:



Advertisements
Similar presentations
Quick Installation Guide for Hurricane8800P
Advertisements

CY-SWR1100 Dual Band Wireless N Router
DSL-2730B, DSL-2740B, DSL-2750B.
Filtering and Security By Mohammad Shanehsaz June 2004.
Networking By: Matt Motl… Programmer Brent Everson… Programming Mentor.
1 Basic Installation and GUI Tech Basic Installation and GUI : Objectives  Installing the Quadro  Configuring the Quadro  Installing IP phones.
Fundamentals of Wireless LANs 1.2 Module 5: Access Points.
Ch. 6 – Switch Configuration CCNA 3 version Overview Identify the major components of a Catalyst switch Monitor switch activity and status using.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.1 Module 6 Switch Configuration.
Allied Telesyn Wireless LAN Solutions AT-WL2411 Access Point AT-WR2411 Wireless LAN PCMCIA Card.
© 2003, Cisco Systems, Inc. All rights reserved. FWL 1.0— © 2003, Cisco Systems, Inc. All rights reserved.
Ch. 7 – Switch Configuration
DIR-505 All-in-One Mobile Companion Greg Quinlan Technical Trainer.
CCNA 2 v3.1 Module 2.
D-Link International Call Center Training and Staff Development Department Module: DAP-1350 Module: DAP-1350.
1 © 2004, Cisco Systems, Inc. All rights reserved. Wireless Access Points (WAPs) or (APs)
1 © 2004, Cisco Systems, Inc. All rights reserved. Wireless LAN bridge.
© 2007 Cisco Systems, Inc. All rights reserved.ICND1 v1.0—2-1 Module Summary  Ethernet cables and segments can span only a limited physical distance,
1 Configuring Linksys Wireless Router Prof. Valencia Community College.
Wireless Network Security Lab Last Update Copyright 2011 Kenneth M. Chipps Ph.D.
1. A router is a device in computer networking that forwards data packets to their destinations, based on their addresses. The work a router does it called.
TEW-691GR Training TEW-691GR Training TEW-691GR 450Mbps Wireless N Gigabit Router.
Technical Training: DAP-1360 Wireless N Access Point DAP-1360.
DIR-510L FAQ’s Wi-Fi AC750 Portable Router and Charger.
TAX-AIDE Network Router Setup Network Printer Setups July SMT/TCS Training - Dallas1.
Wireless Networking 102.
DWR-113 FAQ’s 3G WiFi Router.
Course 201 – Administration, Content Inspection and SSL VPN
DSL 305 Series ADSL Modem. Types of DSL305 series DSL305E ADSL Modem  PPP Half-Bridge (Default)  Transparent Bridge DSL305EU ADSL Router/Modem.
Linksys LNKWET11 Setup b Ethernet Converter Step 1. Annotate your Computer’s ethernet IP address. Step 2. Change the Ethernet IP Address/subnet/router.
Ch. 5 – Access Points Cisco Fundamentals of Wireless LANs version 1.1 Rick Graziani Cabrillo College.
Uniflair pCOWeb Ethernet interface card.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Troubleshooting Your Network Networking for Home and Small Businesses.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Troubleshooting Your Network Networking for Home and Small Businesses.
DVG-G5402SP D-Link VoIP Wireless Router
Module 6 – Switch Configuration CCNA 3 Cabrillo College.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 6 Switch Configuration.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 6 Switch Configuration Cisco Networking Academy.
Lexmark Wireless Printer Adaptor Instructions Step 1. For a Mac, go to network preferences/ select built-in-ethernet and click on TCP/IP tab and annotate.
Ch. 6 – Switch Configuration
Lesson 20-Wireless Security. Overview Introduction to wireless networks. Understanding current wireless technology. Understanding wireless security issues.
Mod 8.1 – Security Cisco Fundamentals of Wireless LANs version 1.2.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Configure a Wireless Router LAN Switching and Wireless – Chapter 7.
Laboratoires & Matériels WiFi
CCNA 3 Week 6 Switch Configuration. Copyright © 2005 University of Bolton Physical Details Available in variety of sizes –12 port, 16 port, up to 48 port.
DSL-2544N Dual Band Wireless N600 Gigabit ADSL2+ Modem Router
1. Upgrading via the Network Booting Preparing Materials -PC server with a wired LAN port -Upgrade file for the network booting(bin type) Upgrade Procedure.
1. Insert the Resource CD into your CD-ROM drive, click Start and choose Run. In the field that appears, enter F:\XXX\Setup.exe (if “F” is the letter of.
Saeed Darvish Pazoki – MCSE, CCNA Abstracted From: Cisco Press – ICND 1 – Chapter 9 Ethernet Switch Configuration 1.
Ch. 2 – and NICs Part 2 – MAC This presentation was originally developed by Prof. Rick Graziani, and modified by Prof Yousif.
Smart Switches FS526T / FS750T / GS748T / GS724T
CWSP Guide to Wireless Security Chapter 2 Wireless LAN Vulnerabilities.
Cisco Aironet Wireless LAN Products. Cisco Aironet 350 Series Product Family 2.4 GHZ DS 11 Mbps (802.11b) Access Points Client Adapters Wireless Bridges.
1350 TAC Training © 2000, Cisco Systems, Inc. Wireless Lab.
DHP Agenda: How to Access Web Interface of the DHP-1320 on Access Point Mode How to Access Web Interface of the DHP-1320 on Router Mode How to Change.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Basic Switch Configurations.
Lesson 10: Configuring Network Settings MOAC : Configuring Windows 8.1.
WLAN Security Condensed Version. First generation wireless security Many WLANs used the Service Set Identifier (SSID) as a basic form of security. Some.
Summary: Unlike WindowsXP, Windows2000 wireless client utilities are different from vendor to vendor and even within versions of a vendor’s client utility.
1 © 2004, Cisco Systems, Inc. All rights reserved. Wireless LAN (network) security.
How to Use LINCWorks as a Wireless Repeater For additional help please contact: Paul Peterson
© 2003, Cisco Systems, Inc. All rights reserved. FWL 1.0— © 2003, Cisco Systems, Inc. All rights reserved.
Understand Wireless Security LESSON Security Fundamentals.
IFIP-UNU ADVANCED COURSE ON NETWORKING AND SECURITY Module II-Wireless Communications Section 5 Access Points.
Instructor Materials Chapter 6 Building a Home Network
Wireless Modes.
Chapter 5: Switch Configuration
Chapter 5: Switch Configuration
Laboratoires & Matériels WiFi
Presentation transcript:

Ch. 5 – Access Points

Overview

Access Point Connection

Radio Upgrade g is chip just now shipping

Cable and Power Cisco Aironet 1100 and 1200 Series, can be powered over Ethernet with: –Switch with inline power (Option 1) –Inline power patch panel (Option 2) –Optional inline power injector (Option3) –Universal power supply (Option 4)

Cable and Power WARNING Never connect both the DC power to the AP power port and inline power simultaneously

AP Installation

LED indicators The LED lights on an access point convey status information. When the access point is powering on, all three LEDs normally blink. After bootup, the colors of the LEDs represent the following: –Green LEDs indicate normal activity. –Amber LEDs indicate errors or warnings. –Red LEDs mean the unit is not operating correctly or is being upgraded AP1200 AP

Reset the AP (Power On) When beginning a lab, to make sure the AP has the default settings, you will reset the AP. Follow these steps to reset the access point to factory default settings using the access point MODE button: Step 1 Disconnect power (the power jack for external power or the Ethernet cable for in-line power) from the access point. Step 2 Press and hold the MODE button while power to the access point is reconnected. Step 3 Hold the MODE button until the Status LED turns amber (approximately 1 to 2 seconds), and release the button. All access point settings return to factory defaults AP1200 AP

Connecting to the AP (Configuration) WiredWireless: Requires Association

Connecting to the AP (Console) ConsoleSerial Rollover Cable IOS CLI

Connecting to the AP (Telnet) Requires a network connection either Ethernet or Wireless AP Defaults –IP Address = /24 –Username and Password = Cisco (“C” not “c”) –This password is the privilege password, not the WEP password. Cisco

Connecting to the AP (Browser) WiredWireless: Requires Association Preferred Method!

Connecting to the AP (Wireless) Wireless adapter: –If configuring using the wireless adapter, you must first associate with the AP. –Make sure the settings on the ACU match the AP. –Cisco 1100 and 1200 Aps have the following defaults: IP Address = /24 SSID = tsunami Password = Cisco (“C” not “c”) SSID = tsunami

Connecting to the AP (Wired) Wired Ethernet: –No association necessary –Make sure the IP Address on the Ethernet interface is on the same subnet as the AP. –AP Defaults IP Address = /24 Password = Cisco (“C” not “c”) Preferred Method! SSID = tsunami

Connecting to the AP (Wired) Wired Ethernet: –We will use the browser via wired method to initially configure APs during labs so we do not configure the wrong AP via wireless. IOS CLI – Optional, but you can do those labs if you wish. We will cover some of the basic commands. Preferred Method! SSID = tsunami

Basic Configuration The labs will really help you understand this. Lab 5.4.4: Configuring Radio Interfaces Through the GUI Skip step # 4 Refer to the next few slides to complete the lab

The AP’s IP address Same IP address whether you are connecting via the wired or wireless interface. (For configuring the AP.)

ACU - Verifying Right click

Network Interfaces – Radio B (Settings)

PLCP frame!

Network Interfaces – Radio B (Settings)

Using the CLI

Lab Page 118 Configuring Radio Interfaces through the IOS CLI Stop at step # 10

Wired equivalent privacy (WEP) The IEEE standard includes WEP to protect authorized users of a WLAN from casual eavesdropping. The IEEE WEP standard specified a 40-bit key, so that WEP could be exported and used worldwide. Most vendors have extended WEP to 128 bits or more. When using WEP, both the wireless client and the access point must have a matching WEP key. WEP is based upon an existing and familiar encryption type, Rivest Cipher 4 (RC4). 128 bit WEP is sometimes referred to, and more accurately, as 104 bit WEP. Also, be sure that Transmit Key numbers match, I.e. Key 1 on both AP and ACU. AP ACU

Authentication Process (Review) On a wired network, authentication is implicitly provided by the physical cable from the PC to the switch. Authentication is the process to ensure that stations attempting to associate with the network (AP) are allowed to do so specifies two types of authentication: –Open-system –Shared-key (makes use of WEP)

Open Authentication Typical Open Authentication on both AP and Client with No WEP keys

Open Authentication and WEP Remember there are three steps to Association: –Probe –Authentication –Association A client can associate with an AP, but use WEP to send the encrypted data packets. Authentication and data encryption are two different things. –Authentication – Is the client allowed to associate with this AP? –Encryption – Encrypts the data (payload) and ICV (Integrity Check Value) fields of the MAC, not the other fields. So a client could Associate with the AP, using Open Authentication (basically no authentication), but use WEP to encrypt the data frames sent after its associated.

Open Authentication and WEP In some configurations, a client can associate to the access point with an incorrect WEP key or even no WEP key. –The AP must be configured to allow this (coming). A client with the wrong WEP key will be unable to send or receive data, since the packet payload will be encrypted. Keep in mind that the header is not encrypted by WEP. Only the payload or data is encrypted. Associated but data cannot be sent or received, since it cannot be unencrypted.

Open Authentication - Optional WEP Encryption (AP) allows client to associate with AP. Cisco AP must have WEP Encryption set to Optional Association successful with any of these options on the client: –Matching WEP key –Non-matching WEP key –No WEP key

Encryption Modes Indicates whether clients should use data encryption when communicating with the device. The three options are: None - The device communicates only with client devices that are not using WEP. WEP Encryption - Choose Optional or Mandatory. If optional, client devices can communicate with this access point or bridge with or without WEP. If mandatory, client devices must use WEP when communicating with the access point. Devices not using WEP are not allowed to communicate. WEP (Wired Equivalent Privacy) is an standard encryption algorithm originally designed to provide with a level of privacy experienced on a wired LAN. The standard defines WEP base keys of size 40 bits or 104 bits.

In Summary Client –Use Open Authentication on the client (does not use WEP, challenge transaction, during authentication). –Use WEP for Data Encryption. AP –Use Open Authentication –Use Mandatory WEP Encryption, Devices not using WEP are not allowed to communicate.

Lab : Page 225 Configuring WEP on AP and client

MAC Authentication/MAC Filters Allows you to accept/deny specific MAC or IP addresses.

Lab 8.3.2: Page 218 Configuring Filters on AP

Services We will not configure all of these options or use all of the features.

Services The Services Summary page shows whether all of the main services are currently enabled or disabled.

Telnet/SSH

Lab Page 198 Configuring Basic AP Security Via GUI

Event Log

Lab : page 335 Configuring Syslog on AP

HTTP This feature enables Web-based GUI management by providing support for HTML Web pages and Common Gateway Interface (CGI) scripts using common Web browsers. The Services>Web Server page is used to enable browsing to the web-based management system, specify the location of the Help files, and enter settings for a custom-tailored web system for management. With the Allow Web-based Configuration Management enabled, access to the GUI management system is permitted. If HTTP is disabled, the management system is accessible only through Telnet or the console

Configure an AP as a repeater Lab 5.4.8: Configure an AP as a repeater through the GUI – Page 127 Lab : Configure an AP as a repeater using WEP through the GUI – page 230

Ch. 5 – Access Points