WAPI allows only robust security network association (RSNA), providing higher security than WEP or WPA/WPA2.
WAPI-PSK applies to home networks or small-scale enterprise networks. No additional certificate system is required.
WAPI defines a dynamic key negotiation mechanism, but there are still security risks if a STA uses the same encryption key for a long time. Both the unicast session key (USK) and multicast session key (MSK) have a lifetime. The USK or MSK needs to be updated when its lifetime ends. To enhance security, WAPI provides the time-based key update mechanism.
The AP7030DE and AP9330DN do not support WAPI.
The system view is displayed.
The WLAN view is displayed.
The security profile view is displayed.
The security policy is set to WAPI-PSK.
The interval for updating a Base Key (BK) and the BK lifetime percentage are set.
The value obtained by multiplying the interval for updating a BK by the BK lifetime percentage should be greater than or equal to 300 seconds. If the interval for updating a BK is less than 300s, the BK may be updated before negotiation is complete due to low STA performance. In this case, some STAs may be forced offline or cannot go online.
By default, the interval for updating a BK is 43200s, and the BK lifetime percentage is 70%.
The timeout period of a security association is set.
By default, the timeout period for a SA is 60s.
If a STA is not authenticated within the timeout period, no SA is established and the STA cannot go online.
The WAPI USK or MSK update mode is set.
By default, USKs and MSKs are updated based on time.
The interval for updating a USK, and number of retransmissions of USK negotiation packets are set.
By default, the interval for updating a USK is 86400s; the number of retransmissions of USK negotiation packets is 3.
The interval for updating an MSK, and number of retransmissions of MSK negotiation packets are set.
By default, the interval for updating an MSK is 86400s; the number of retransmissions of MSK negotiation packets is 3.