Configuring Security on MT Wireless

Hoping someone can offer some advice on WEP configuration;
For a point-point link, using Station Private Keys, is it necessary to select encryption=required in the Winbox interface in order to enable WEP, or does setting a private key at the station, and entering the station + it’s key in the Registration table at the ‘Bridge’ end, automatically enable WEP? I tried setting both, and throughput dropped to 4Mbps UDP Uni-dir, wherease with encryption set to ‘none’ throughput is up at 25Mbps UDP Uni-dir.
Thanks if anyone can offer advice - I don’t know if it is (easily) possible to actually check if data is being WEP encoded over the link?

Hi there,

Yes WEP really slows things down - even on a fast ~1.5GHz CPU, using WEP slows the whole thing down to much lower speeds.
I guess the MT software doesn’t “pipeline” the security and wireless sections as one would hope.

I guess turn WEP off, turn off SSID and use the MAC authentication to provide high speed with security

Regards

Stephen

hardware WEP/AES are also supported if your card supports them. that solves the performance issues

I’ve got the WEP turned on properly now - UDP UNI throughput drops from 24Mbps to 10Mbps for an old RB230 233Mhz with v2.8rc6, and from 24Mbps to about 12Mbps with later RB230 266MHz with v2.8.11

Yes, I want to try hardware WEP, but my current systems only have 5211 Atheros Cards and v2.8 software. I am nervous to upgrade because a) the systems are in service and b) I have seen reports that some of the later releases of 2.8/2.9 actually seems to make wireless performance worse - or has that just been with certain hardware etc? I don’t know if you are able to highlight which later releases are considered ‘safe’ for RB230 made Atheros 5211 and/or whether they would benefit me anyway?

Hi Normis,

Which cards have HW-supported WEP/AES?

Would like to know very much as that will please some customers …

Regards

Stephen

here: http://www.mikrotik.com/Documentation/nstreme_spec.pdf