| Transport encryption |
|---|
| KeyGuard, WEP 40/128 (RC4), WPA2-CCMP (AES), WPA-TKIP |
| | RADIUS support (standard and Motorola vendor specific attributes) |
|---|
| Allowed ESSIDs (Motorola VSA), Location-based authentication (Motorola VSA), MAC-based authentication (standard), User-based QoS (Motorola VSA), User-based VLANs (standard) |
|
| Authentication |
|---|
| Pre-shared keys (PSK);: 802.1x/EAP — transport layer security (TLS), tunneled transport layer security (TTLS), protected EAP(PEAP); Kerberos Integrated AAA/RADIUS Server with native support for EAP-TTLS, EAP-PEAP (includes a built-in user name/password database; supports LDAP) and EAP-SIM |
| | Secure guest access (Hotspot provisioning) |
|---|
| Customizable login/welcome pages, Local web-based authentication, Support for external authentication/billing systems, URL redirection for user login, Usage based charging |
|
| Access control lists |
|---|
| L2/3/4 ACLs |
| | Wireless IDS/IPS |
|---|
| Multi-mode rogue AP detection and Rogue AP Containment, 802.11n Rogue Detection, Ad-Hoc Network Detection, Denial of Service Protection against wireless attacks, detect de-auth from Broadcast Source MAC, detect frames with invalid sequence number, client blacklisting, excessive authentication, /associations; excessive probes; excessive disassociation/deauthentications; excessive decryption errors; excessive authentication failures; excessive 802.11 replay; excessive crypto IV failures( TKIP/CCMP replay), Suspicious AP, Authorized device in Adhoc mode, Unauthorized AP using authorized SSID, EAP flood, Fake AP flood, ID theft, Adhoc advertising authorized SSID. |
|
| Anomaly analysis |
|---|
| Source Media Access Control (MAC) = Destination MAC; illegal frame sizes; Source MAC is multicast; TKIP countermeasures; all zero addresses |
| | IPSec VPN gateway |
|---|
Supports DES, 3DES, AES-128 and AES-256 encryption, with site-to-site and client-to-site VPN capabilities. Supports 2, 048 concurrent IPSEC tunnels per switch; 24, 576 per cluster. |
|
| RADIUS support (standard and Motorola vendor specific attributes) |
|---|
| Allowed ESSIDs (Motorola VSA), Location-based authentication (Motorola VSA), MAC-based authentication (standard), User-based QoS (Motorola VSA), User-based VLANs (standard) |
| | Network address translation (NAT) support |
|---|
| Yes |
|
| WIPS sensor conversion |
|---|
| Yes. Supported on the AP300 and the Adaptive AP-5131 and AP-7131 |
| | Role-based wired/wireless firewall (L2-L7) with stateful inspection |
|---|
Protects against attacks between: Wired and Wired Wired and Wireless Wireless and Wired Wireless and Wireless Supports 205, 000 active firewall sessions per switch; 2, 460, 000 per cluster Protection from IP Spoofing and ARP Cache Poisoning |
|
| Geofencing |
|---|
| Add location of users as a parameter that defines access control to the network |
| |