![Allen-Bradley 1783-WAPAK9 Скачать руководство пользователя страница 398](http://html1.mh-extra.com/html/allen-bradley/1783-wapak9/1783-wapak9_user-manual_2900827398.webp)
398
Rockwell Automation Publication 1783-UM006A-EN-P - May 2014
Chapter 13
Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services
Protection of Broadcast Management Frames
To prevent attacks by using broadcast frames, access points supporting CCXv5
don’t emit any broadcast class 3 management frames. An access point in
workgroup bridge, repeater, or non-root bridge mode discards broadcast class 3
management frames if Client MFP is enabled. Client MFP is enabled only for
autonomous access points if the encryption is AES-CCMP or TKIP and key
management WPA version 2.
Client MFP for Access Points
in Root Mode
Autonomous access points in root mode support mixed mode clients. Clients
capable of CCXv5 with negotiated cipher suite AES or TKIP with WPAv2 are
Client MFP enabled. Client MFP is disabled for clients that are not CCXv5
capable. By default, Client MFP is optional for a particular SSID on the access
point, and can be enabled or disabled by using CLI in SSID configuration mode.
Client MFP can be configured as either required or optional for a particular
SSID. To configure Client MFP as required, you must configure the SSID with
key management WPA version 2 mandatory. If the key management is not
WPAv2 mandatory, an error message is displayed and your CLI command is
rejected. If you attempt to change the key management with Client MFP
configured as required and key management WPAv2, an error message appears
and rejects your CLI command. When configured as optional, Client MFP is
enabled if the SSID is capable of WPAv2, otherwise Client MFP is disabled.
Configuring Client MFP
The following CLI commands are used to configure Client MFP for access
points in root mode.
ids mfp client required
This SSID configuration command enables Client MFP as required on a
particular SSID. The Dot11Radio interface is reset when the command is
executed if the SSID is bound to the Dot11Radio interface. The command also
expects that the SSID is configured with WPA version 2 mandatory. If the SSID
is not configured with WPAv2 mandatory, an error message appears and the
command is rejected.
no ids mfp client
This ssid configuration command disables Client MFP on a particular SSID. The
Dot11Radio interface is reset when the command is executed if the SSID is
bound to the Dot11Radio interface.
ids mfp client optional
Содержание 1783-WAPAK9
Страница 240: ...240 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 6 Administering the WAP Access Notes...
Страница 300: ...300 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 8 Configuring Multiple SSIDs Notes...
Страница 440: ...440 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 14 Configuring RADIUS and TACACS Servers Notes...
Страница 456: ...456 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 15 Configuring VLANs...
Страница 476: ...476 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 16 Configuring QoS Notes...
Страница 482: ...482 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 17 Configuring Filters...
Страница 489: ...Rockwell Automation Publication 1783 UM006A EN P May 2014 489 Configuring Filters Chapter 17...
Страница 520: ...520 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 19 Configuring SNMP Notes...
Страница 572: ...572 Rockwell Automation Publication 1783 UM006A EN P May 2014 Chapter 21 Troubleshooting Notes...
Страница 578: ...578 Rockwell Automation Publication 1783 UM006A EN P May 2014 Appendix A Protocol Filters Notes...
Страница 594: ...594 Rockwell Automation Publication 1783 UM006A EN P May 2014 Appendix C Error and Event Messages Notes...
Страница 600: ...600 Rockwell Automation Publication 1783 UM006A EN P May 2014 Glossary Notes...
Страница 610: ...610 Rockwell Automation Publication 1783 UM006A EN P May 2014 Index Notes...
Страница 611: ......