Note:On the Edit Profile (Basic) or Edit Profile (Group-X) screen, for any selection from the NetworkAuthentication menu that requires a RADIUS server, authentication is not restricted to a RADIUS server; you can also use an internal authentication server or an external LDAP server. Note:You can configure either MAC authentication with an external RADIUS server or network authentication with an external RADIUS server, but not both. That is, if you configure external MAC authentication, you cannot use an external RADIUS server with WPA, WPA2, or WPA & WPA2.
Network Authentication Selection
Data Encryption Options
Configuration Steps
Open
None
WEP
You can use an open system without any encryption or with WEP encryption:
• No encryption. An open system without encryption is the default setting. No further authentication and encryption configuration is required.
• WEP encryption. To configure an open system with WEP encryption, see the Shared Key and WEP information further down in this table.
Shared Key
64-bit WEP
128-bit WEP
152-bit WEP
To configure Shared Key authentication with WEP:
From the DataEncryption menu, select a level of WEP encryption:
- 64-bit WEP. Uses 40/64-bit encryption.
- 128-bit WEP. Uses 104/128-bit encryption.
- 152-bit WEP. A proprietary mode that works only with other wireless devices that support this mode.
(Optional) Select the ShowKey check box to display the characters in the key fields.
Select a key radio button (Key1, Key2, Key3, or Key4).
Enter a key in the corresponding field:
64-bit WEP requires a key with 10 characters.
128-bit WEP requires a key with 26 characters.
152-bit WEP requires a key with 32 characters.
Note: For information about requirements for WEP keys, see Table 11 on page 306.
Legacy 802.1x
None
To configure legacy 802.1x authentication:
Set up and enable an internal or external (RADIUS or LDAP) authentication server.
Select the Local or External radio button.
If you select the External radio button, select the authentication server that you wish to use from the menu.
WPA with Radius
TKIP
TKIP + AES
To configure WPA authentication with a RADIUS server:
Set up and enable an internal or external (RADIUS or LDAP) authentication server.
From the Data Encryption menu, select the type of encryption:
- TKIP. Supports Temporal Key Integrity Protocol (TKIP) only.
- TKIP+AES. Supports both TKIP and Advanced Encryption Standard (AES).
Select the Local or External radio button.
If you select the External radio button, select the authentication server that you wish to use from the menu.
WPA2 with Radius
AES
TKIP + AES
To configure WPA2 authentication with a RADIUS server:
Set up and enable an internal or external (RADIUS or LDAP) authentication server.
From the Data Encryption menu, select the type of
encryption:
- AES. Supports AES only.
- TKIP + AES. Supports both TKIP and AES.
Select the Local or External radio button.
If you select the External radio button, select the authentication server that you wish to use from the menu.
WPA & WPA2 with Radius Note: Use this option if the network includes both WPA and WPA2 clients.
TKIP + AES
To configure WPA & WPA2 authentication with a RADIUS server:
Set up and enable an internal or external (RADIUS or LDAP) authentication server.
Select the Local or External radio button.
If you select the External radio button, select the authentication server that you wish to use from the menu. Note: The Data Encryption menu displays TKIP + AES, which
is the only available option. Both TKIP and AES are supported.
WPA-PSK
TKIP
TKIP + AES
To configure WPA-PSK authentication:
From the DataEncryption menu, select the type of encryption:
- TKIP. Supports TKIP only.
- TKIP+AES. Supports both TKIP and AES.
(Optional) Select the ShowPassphrase check box to display the characters in the WPA Passphrase (Network Key) field.
Type a passphrase of at least eight characters in the WPAPassphrase (NetworkKey) field. Note: For information about requirements for a WPA
passphrase, see Table 11 on page 306.
WPA2-PSK
AES
TKIP + AES
To configure WPA2-PSK authentication:
From the DataEncryption menu, select the type of encryption:
- AES. Supports AES only.
- TKIP+AES. Supports both TKIP and AES.
(Optional) Select the ShowPassphrase check box to display the characters in the WPA Passphrase (NetworkKey) field.
Type a passphrase of at least eight characters in the WPAPassphrase (NetworkKey) field. Note: For information about requirements for a WPA
passphrase, see Table 11 on page 306.
WPA-PSK & WPA2-PSK Note: Use this option if
the network includes both
WPA and WPA2 clients.
TKIP + AES
To configure WPA-PSK & WPA2-PSK authentication:
(Optional) Select the ShowPassphrase check box to display the characters in the WPAPassphrase (NetworkKey) field.
Type a passphrase of at least eight characters in the WPAPassphrase (NetworkKey) field. Note: The DataEncryption menu displays TKIP+AES, which
is the only available option. Both TKIP and AES are supported. Note: For information about requirements for a WPA
passphrase, see Table 11 on page 306.
Last Updated:10/17/2025
|
Article ID: 25695
Recently Viewed Articles
Our team is here to help!
Phone
Chat
Email
Contact NETGEAR by email
To request product support by email, follow the link below to the Contact Us page, then:
Click Get Support
Click OPEN A SUPPORT CASE
Sign in or create a NETGEAR account
Select an eligible product to request hardware support
If you prefer to call or chat with us, select the buttons next to Email.