Privacy Settings for WPAv2 with PSK
WPAv2 with PSK — Network access is allowed to any client that knows the pre-shared key (PSK).
Configure the following privacy settings:
•
TKIP-CCMP — Select this option to use Temporal Key Integrity Protocol (TKIP) and Counter Mode
with Cipher Block Chaining Message Authentication Code Protocol (CCMP). This option is selected
by default to enable mixed TKIP-CCMP encryption.
•
Protected Management Frames — Management Frames are the signaling packets used in the 802.11
wireless standard to allow a device to negotiate with an AP. PMF adds an integrity check to control
packets being sent between the client and the access point. This setting is enabled by default. Valid
values are:
•
Enabled. Supports PMF format but does not require it.
•
Disabled. Does not address PMF format. Clients connect regardless of format.
•
Required. Requires all devices use PMF format. This could result in older devices not connecting.
•
WPAv2Key. The password to access this wireless network.
Related Links
Privacy Settings for WPAv2 Enterprise with RADIUS
WPA2 Enterprise w/ RADIUS — Supports 802.1X authentication with a RADIUS server, using AES
encryption. This is the highest level of network security, particularly when used in conjunction with
client certificate-based authentication (EAP-TLS). All 802.1X protocols are supported.
Note
MBA and Captive Portal are not supported when using WPA2 Enterprise w/ RADIUS. The
devices with 802.1X use Default Auth role only.
Configure the following privacy settings:
•
TKIP-CCMP — Select this option to use Temporal Key Integrity Protocol (TKIP) and Counter Mode
with Cipher Block Chaining Message Authentication Code Protocol (CCMP). This option is selected
by default to enable mixed TKIP-CCMP encryption.
•
Protected Management Frames — Management Frames are the signaling packets used in the 802.11
wireless standard to allow a device to negotiate with an AP. PMF adds an integrity check to control
packets being sent between the client and the access point. This setting is enabled by default. Valid
values are:
•
Enabled. Supports PMF format but does not require it.
•
Disabled. Does not address PMF format. Clients connect regardless of format.
•
Required. Requires all devices use PMF format. This could result in older devices not connecting.
•
Fast Transition — Provides faster roaming by authenticating the device before roaming occurs. This
setting is enabled by default.
•
Mobility Domain ID — Used by 802.11r, this setting defines a network scope that supports 11r fast
roaming. Master keys are shared within the Mobility Domain, allowing clients to support fast
roaming.
Related Links
Configure
ExtremeCloud Appliance User Guide for version 4.36.03
121