Bekijk de volledige versie : WPA - PSK key rotation interval ?
Craigster
23-02-2005, 01:22
Using firmware 1.8.1.9 and settings in attached screenshot, I find that WPA NETWORK KEY ROTATION INTERVAL field is greyed out (and reverts to zero) suggesting no key rotation is happening (the whole point).
Yet when I set WEP ENCRYPTION to "None" so that key rotation field becomes active, the speed increase over wireless tells me no encryption is happening at all (i.e. its faster than using WEP alone and pretty much instantaneous). Am a non technical user, moving from WEP to WPA-PSK.
Is this behaviour by design? Am I misinterpreting something?
Although its a simple setup (wl500g + 1 pc running XP+SP2 on WLAN, sometimes extra devices on LAN), I'm trying to run WPA-PSK as standard but fall back to WEP if that's not working.
Appreciate any help !
rgds :confused:
tomilius
24-02-2005, 08:40
OK, I'm sort of a newbie at wireless encryption, but from the way I understand it, having encryption on shouldn't actually slow down your speed too much. However, you seemed to have WPA-PSK and WEP on which, from my limited experience, is not very useful. Also, and this may be completely wrong, from what I'm guessing having WEP enabled along with WPA just allows either to be used on a client device (for compatibility) which would explain the slow-down.
Anyway, as far as I know, it's unnecessary to have WPA-PSK and WEP going at the same time in ordinary circumstances. And, this is just a guess, but the reason the WPA rotation key interval is faded out when you turn on WEP could be a script trigger set up to assume if you're using WEP you're not using WPA so the key interval can't apply to you and they don't want to confuse you... ?
You don't need to have WPA-PSK and WEP on at the same time, AFAIK. Just keep WEP off. The encryption you have with WPA-PSK is TKIP, as you've selected, and it's much better than WEP. AES is even better than TKIP but hey, if your devices don't support it, don't use it. Not that big of a deal.
So, finally, my advice would be to leave on WPA-PSK and TKIP, turn off the unnecessary WEP and set the key interval to 1800 for 30 minutes. But again, I'm pretty much a newbie.
Craigster
25-02-2005, 01:20
Thanks tomilius. With my simple setup (wl500g + 1 pc on wireless lan) turning off WEP is fine (though I believed WEP could be enabled as a fall back encryption for devices that couldn't run the WPA-PSK). Anyway, WPA-PSK is all I need right now.
Real issue then is when only wpk-psk is enabled, network runs faster than WEP only, so I think there's no encryption happening at all (encryption *IS* a performance overhead, usually noticable).
How can I tell that WPA-PSK is working? I don't want to mistakenly believe I'm secure if I'm misconfigured and open for all to see !
tomilius
25-02-2005, 02:21
Well, Craigster, I know with my Pocket PC and that alone when I tried setting the rotation interval to 5 or 10 seconds I would notice that streaming music would start buffering every 5 or 10 seconds. My PCs didn't seem to be affected.
A simpler way to check is uh, well, if it wasn't working then you wouldn't be able to connect with WPA-PSK parameters, now would you? :eek: ... though I can understand your concern over security. I don't know what to think of WPA-PSK being faster than WEP. Maybe WEP isn't implemented as intelligently as WPA-PSK in that version? Or maybe however you're determining network speed isn't very efficient. My network "speed" as reported by Windows fluctuates depending on how much I need to use with wireless. It usually stays around 24mbps or 36mbps, though it sometimes goes up to 48 or 54. The signal strength is always full or near it, though, and when I begin to transfer a file to another computer, the speed jumps to that 48 or 54 again and stays at either. Interesting find.
Does this mean that the 500g supports WEP and WPA at the same time???? Can I connect a client using WEP and a client using WPA to one 500g?
tomilius
26-02-2005, 06:53
Why don't you try it, morrow? That's what I'm under the assumption of, but I'm still testing 1.9.3.5 beta's stability with WPA-PSK: TKIP so I can't do any other testing.
Craigster
01-03-2005, 08:50
well, if it wasn't working then you wouldn't be able to connect with WPA-PSK parameters, now would you?
So when both are enabled, which is used? Really, this wouldn't be the first device to accept and report that certain settings are in use when really its ignoring them because they're not set consistently! :eek:
So, I've disabled the WEP, now running at v. good speed using WPA-PSK. I installed Ethereal packet sniffing software on WLAN PC and I can see the key being echanged at the right interval. (Can't actually see the encrypted packets of course as the sniffer is using the NIC which is actually doing the decryption).
So I'm (mostly) satisfied. Thanks
:)
Why don't you try it, morrow? That's what I'm under the assumption of, but I'm still testing 1.9.3.5 beta's stability with WPA-PSK: TKIP so I can't do any other testing.
I don't own a wl-500g, but i would be interested in buying one if both WEP and WPA can be used at the same time! let me know if it works...
Hi,
I'm just finished with testing it, and I can confirm that it works!
If you want more information, let me know, I will tell you tomorow. Now I'm going to bed...
Regards,
k7g2lm3
Does this mean that the 500g supports WEP and WPA at the same time???? Can I connect a client using WEP and a client using WPA to one 500g?
I have tried this because I needed it. I have one win XP sp2 client with WPA
And I wanted to connect a labtop with only WEP.
I didn't work when I wanted to use both :(