AP Authentication and Encryption Options
Authentication and encryption schemes are set up within the wireless LAN. VLANs are configured in the
network and on the APs and specify different combinations of authentication and encryption. An SSID
associates with a VLAN and the particular authentication and encryption scheme. In order for wireless client
devices to authenticate successfully, you must configure the same SSIDs with their authentication and encryption
schemes on the APs and on the Cisco Unified IP Phone.
Some authentication schemes require specific types of encryption. With Open authentication, you can use
static WEP for encryption for added security. But if you are using Shared Key authentication, you must set
static WEP for encryption, and you must configure a WEP key on the phone.
When you use Authenticated Key Management (AKM) for the Cisco Unified IP Phone, several choices for
both authentication and encryption can be set up on the APs with different SSIDs. When the phone attempts
to authenticate, it chooses the AP that advertises the authentication and encryption scheme that the phone can
support. Auto (AKM) mode can authenticate by using WPA, WPA2, WPA Pre-shared key, or CCKM.
Note
•
When you use WPA pre-shared key or WPA2 pre-shared key, the pre-shared key must be statically
set on the phone. These keys must match the keys that are on the AP.
•
When you use Auto (AKM), encryption options are automatically configured for WPA, WPA2,
WPA Pre-shared key, WPA2 Pre-shared key, or CCKM.
•
In AKM mode, the phone authenticates with LEAP if the phone is configured with WPA, WPA2,
or CCKM key management, or if 802.1x is used.
•
The Cisco Unified IP Phone does not support auto EAP negotiation; to use EAP-FAST mode, you
must specify it.
The following table provides a list of authentication and encryption schemes that are configured on the Cisco
Aironet APs that the Cisco Unified IP Phone supports. The table shows the network configuration option for
the phone that corresponds to the AP configuration.
Table 13: Authentication and Encryption Schemes
Cisco Unified IP Phone
configuration
Cisco AP configuration
Authentication
Common
encryption
Key management
Authentication
Open
None
Open
Open+WEP
WEP
Open (Static WEP)
WEP
WEP
Shared key (Static WEP)
LEAP or Auto (AKM)
WEP
Optional CCKM
LEAP
802.1x
Cisco Unified IP Phone 8961, 9951, and 9971 Administration Guide for Cisco Unified Communications Manager
10.0 (SIP)
96
VoIP Wireless Network
AP Authentication and Encryption Options
REVIEW DRAFT - CISCO CONFIDENTIAL