User's Manual

Table Of Contents
Wireless Configuration for ISA550W and ISA570W
Configuring the Access Points
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 164
5
WPA Wi-Fi Protected Access (WPA) provides better security than
WEP because it uses dynamic key encryption. This
standard was implemented as an intermediate measure to
replace WEP, pending final completion of the 802.11i
standard for WPA2.
The following WPA security modes are supported on your
security appliance. Choose one of them if you need to allow
access to devices that do not support WPA2.
WPA-Personal: WPA-Personal supports TKIP
(Temporal Key Integrity Protocol) or AES (Advanced
Encryption System) encryption mechanisms for data
encryption (default is TKIP). TKIP uses dynamic keys
and incorporates Message Integrity Code (MIC) to
provide protection against hackers. AES uses
symmetric 128-bit block data encryption.
WPA-Enterprise: WPA-Enterprise uses an external
RADIUS server for client authentication. WPA-
Enterprise supports TKIP and AES encryption
mechanisms (default is TKIP). This security mode is
only available when a RADIUS server is connected to
the SSID.
WPA2 WPA2 provides the best security for wireless transmissions.
This method implements the security standards specified in
the final version of 802.11i.
The following WPA2 security modes are supported on your
security appliance:
WPA2-Personal: WPA2-Personal always uses AES
encryption mechanism for data encryption.
WPA2-Enterprise: WPA2-Enterprise uses an
external RADIUS server for client authentication.
WPA2-Enterprise always uses AES encryption
mechanism for data encryption. This security mode is
only available when a RADIUS server is connected to
the SSID.
Security
Mode
Description