4 - 56 WiNG 4.4 Switch System Reference Guide
Configuring WPA/WPA2 using TKIP and CCMP
Wi-Fi Protected Access
(WPA) is a robust encryption scheme specified in the
IEEE Wireless Fidelity
(Wi-Fi) standard,
802.11i. WPA provides more sophisticated data encryption than WEP. WPA is designed for corporate networks and small-
business environments where more wireless traffic allows quicker discovery of encryption keys by an unauthorized person.
WPA's encryption method is
Temporal Key Integrity Protocol (TKIP).
TKIP addresses WEP’s weaknesses with a re-keying
mechanism, a per-packet mixing function, a message integrity check, and an extended initialization vector. WPA also
provides strong user authentication based on 802.1x EAP.
WPA2 is a newer 802.11i standard that provides even stronger wireless security than WPA and WEP. CCMP is the security
standard used by the
Advanced Encryption Standard
(AES). AES serves the same function TKIP does for WPA-TKIP. CCMP
computes a
Message Integrity Check
(MIC) using the proven
Cipher Block Chaining
(CBC) technique. Changing just one bit
in a message produces a totally different result.
WPA2-CCMP is based on the concept of a
Robust Security Network
(RSN), which defines a hierarchy of keys with a limited
lifetime (similar to TKIP). Like TKIP, the keys the administrator provides are used to derive other keys. Messages are
encrypted using a 128-bit secret key and a 128-bit block of data. The end result is an encryption scheme as secure as any
the switch provides.
To configure WPA/WPA2-TKIP/CCMP encryption:
1. Select
Network
>
Wireless LANs
from the main menu tree.
2. Select an existing WLAN from those displayed within the
Configuration
tab and click the
Edit
button.
A WLAN screen displays with the WLAN’s existing configuration. Refer to the
Authentication
and
Encryption
columns to assess the WLAN’s existing security configuration.
3. Select either the
WPA/WPA2-TKIP
or
WPA2-CCMP
button from within the
Encryption field.
4. Click the
Config
button to the right of the WPA/WPA2-TKIP and WPA2-CCMP checkboxes.
The
WPA/WPA2-TKIP/CCMP
screen displays. This single screen can be used to configure either WPA/WPA2-TKIP,
or WPA-CCMP.
5. Select the
Broadcast Key Rotation
checkbox to enable periodically changing the broadcast key for this WLAN.
Only broadcast key changes when required by associated MUs to reduce the transmissions of sensitive key
information. This value is enabled by default.
Summary of Contents for WiNG 4.4
Page 1: ...Motorola Solutions WiNG 4 4 SYSTEM REFERENCE GUIDE ...
Page 2: ......
Page 3: ...MOTOROLA SOLUTIONS WING 4 4 SYSTEM REFERENCE GUIDE 72E 157062 01 Revision A January 2012 ...
Page 6: ...iv WiNG 4 4 Switch System Reference Guide ...
Page 14: ...xii WiNG 4 4 Switch System Reference Guide ...
Page 48: ...1 32 WiNG 4 4 Switch System Reference Guide ...
Page 58: ...2 10 WiNG 4 4 Switch System Reference Guide ...
Page 280: ...4 176 WiNG 4 4 Switch System Reference Guide ...
Page 352: ...5 72 WiNG 4 4 Switch System Reference Guide ...
Page 476: ...6 124 WiNG 4 4 Switch System Reference Guide ...
Page 506: ...7 30 WiNG 4 4 Switch System Reference Guide ...
Page 532: ...8 26 WiNG 4 4 Switch System Reference Guide ...
Page 536: ...A 4 WiNG 4 4 Switch System Reference Guide ...
Page 544: ...B 12 WiNG 4 4 Switch System Reference Guide ...
Page 558: ...B 26 WiNG 4 4 Switch System Reference Guide ...
Page 574: ...C 16 WiNG 4 4 Switch System Reference Guide ...
Page 596: ...E 4 WiNG 4 4 Switch System Reference Guide ...
Page 597: ......