5-71
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 5 Configuring Security Solutions
Configuring Management Frame Protection
4.
To enable or disable client MFP on a specific WLAN, enter this command:
config wlan mfp client
{
enable
|
disable
}
wlan_id
[
required
]
If you enable client MFP and use the optional
required
parameter, clients are allowed to associate
only if MFP is negotiated.
Using the CLI to View MFP Settings
Use these commands to view MFP settings using the controller CLI.
1.
To see the controller’s current MFP settings, enter this command:
show wps mfp summary
Information similar to the following appears:
Global Infrastructure MFP state.... Enabled
Controller Time Source Valid....... False
WLAN Infra. Client
WLAN ID WLAN Name Status Protection Protection
------- ---------- -------- ---------- -----------
1 test1 Enabled Disabled Disabled
2 open Enabled Enabled Required
3 testpsk Enabled *Enabled Optional but inactive (WPA2 not configured)
Infra. Operational --Infra. Capability--
AP Name Validation Radio State Protection Validation
-------- ----------- ----- ----------- ----------- -----------
mapAP Disabled a
Up Full Full
b/g
Up Full Full
rootAP2 Enabled a
Up Full Full
b/g
Up Full Full
HReap *Enabled b/g
Up
Full Full
a Down
Full Full
2.
To see the current MFP configuration for a particular WLAN, enter this command:
show wlan
wlan_id
Information similar to the following appears:
WLAN Identifier........................... 1
Profile Name.............................. test1
Network Name (SSID)....................... test1
Status.................................... Enabled
MAC Filtering............................. Disabled
Broadcast SSID............................ Enabled
...
Local EAP Authentication.................. Enabled (Profile 'test')
Diagnostics Channel....................... Disabled
Security
802.11 Authentication:................. Open System
Static WEP Keys........................ Disabled
802.1X................................. Enabled
Encryption:.............................. 104-bit WEP
Wi-Fi Protected Access (WPA/WPA2)...... Disabled
CKIP .................................. Disabled
IP Security............................ Disabled
IP Security Passthru................... Disabled
Web Based Authentication............... Disabled
Web-Passthrough........................ Disabled