3e–525C–3 Wireless Access Point Chapter 1: Introduction8 29000171-001 Adanger of compromise, or policy. 3eTI products implementstandards-based 802.1X with absolutely no custom modi-fications, again ensuring interoperability with 802.11i andWPA2 certified equipment.• 4-way handshake: The 4-way handshake defined in 802.11iachieves the following important goals within the securityprotocol:– it confirms the PMK between the supplicant (3e client) andauthenticator (3e Access Point)– it establishes the temporal keys to be used by the data-confi-dentiality protocol– it authenticates the security parameters that were negotiated– it provides keying material to implement the group keyhandshake within 802.11i3eTI implements the 4-way handshake within its wire-less product line per the 802.11i specification, again withabsolutely no custom modifications, in order to maximizeinteroperability with 3rd party 802.11i and WPA2 compliantequipment.• AES CCMP: 802.11i and WPA2 employ AES CCM, which is a com-bination of AES Counter (CTR) mode per packet data encryption,combined with AES Cipher Block Chaining – Message Authentica-tion Code (CBC-MAC) per packet data integrity / authenticationof the entire packet including the MAC header. AES CCMP hasbeen deemed to surpass the RC4 stream cipher, upon which theolder WEP and WPA security protocols are based. 3eTI was thefirst company to take it’s AES algorithm through the NIST CCMalgorithm certification process, thereby ensuring that 3eTI’s AESCCMP is standards-based, non-proprietary, and ready for wideWPA2 interoperability usage.Wireless VLANAccording to the IEEE, VLANs define broadcast domains in a Layer2 network. VLANs have the same attributes as physical LANs with theadditional capability to group end stations physically to the same LANsegment regardless of the end stations' geographical locationTo interconnect two different VLANs, routers or Layer 3 switches areused. These routers or Layer 3 switches execute inter-VLAN routing orrouting of traffic between VLANs. Broadcast traffic is then terminatedand isolated by these Layer 3 devices (for example, a router or Layer 3switch will not route broadcast traffic from one VLAN to another).Wireless VLAN is an extension of Layer 2 wired VLANs in wirelessLAN (WLAN) environment. As with wired VLANs, wireless VLANssegregate the WLAN network into disjointed sections, each of whichcan serve a different purpose or users, such as engineering, accountingor guest. To get the same network configuration, with VLAN incapable