31
Configuring WLAN security
Configuration task list
To configure WLAN security in a service template, map the service template to a radio policy, and add
radios to the radio policy. The SSID name, advertisement setting (beaconing), and encryption settings are
configured in the service template. You can configure an SSID to support any combination of WPA, RSN,
and Pre-RSN clients
Complete these tasks to configure WLAN security configuration tasks.
Task
Remarks
Enabling an authentication method
Required
Configuring the PTK lifetime
Optional
Configuring the GTK rekey method
Optional
Configuring security IE
Required
Configuring cipher suite
Required
Configuring port security
Optional
Enabling an authentication method
You can enable open system or shared key authentication or both.
To enable an authentication method:
To do…
Use the command…
Remarks
Enter system view
system-view
—
1.
Enter WLAN service
template view.
wlan service-template
service-template-number
crypto
—
2.
Enable the authentication
method.
authentication-method
{
open-system
|
shared-key
}
Optional.
Open system authentication
method is used by default.
Shared key authentication is
usable only when WEP
encryption is adopted. In this
case, you must configure the
authentication-method
shared-key
command.
For RSN and WPA, open
system authentication is
required.
Configuring the PTK lifetime
A PTK is generated through a four-way handshake, during which, the PMK, an AP random value (ANonce),
a site random value (SNonce), the AP’s MAC address and the client’s MAC address are used.
To configure the PTK lifetime: