Chapter 4 Security Setup
Enabling Additional WEP Security Features
4-14
Cisco Aironet 1200 Series Access Point Software Configuration Guide
OL-2159-03
Note
Access points do not use the SNMP variable
dot11PrivacyInvoked
, so it is always
set to disabled.
Enabling Additional WEP Security Features
You can enable three advanced security features to protect against sophisticated
attacks on your wireless network’s WEP keys. This section describes how to set
up and enable these features:
•
Enabling Message Integrity Check (MIC)
•
Enabling Temporal Key Integrity Protocol (TKIP)
•
Enabling Broadcast WEP Key Rotation
Enabling Message Integrity Check (MIC)
MIC prevents attacks on encrypted packets called
bit-flip
attacks. During a bit-flip
attack, an intruder intercepts an encrypted message, alters it slightly, and
retransmits it, and the receiver accepts the retransmitted message as legitimate.
The MIC, implemented on both the access point and all associated client devices,
adds a few bytes to each packet to make the packets tamper-proof.
Note
You must set up and enable WEP with full encryption before MIC takes effect.
Table 4-2
SNMP Variable Settings and Corresponding WEP Levels
SNMP Variable
WEP Full
WEP Off
WEP Optional
dot11ExcludeUnencrypted.2
true
false
false
awcDot11AllowEncrypted.2
true
false
true