Cipher Suites and WEP
Configuring Cipher Suites
6
Cisco 3200 Series Wireless MIC Software Configuration Guide
The following example sets up a cipher suite for SSID sample_ssid that enables CKIP, CMIC, and
128-bit WEP as the encryption mode:
bridge# configure terminal
bridge(config)# dot11 ssid sample_ssid
bridge(config-ssid)# encryption mode ciphers ckip-cmic wep128
bridge(config-ssid)# end
The following example sets up a cipher suite for ssid sample_ssid that enables AES as the encryption
mode:
bridge# configure terminal
bridge(config)# dot11 ssid sample_ssid
bridge(config-ssid)# encryption mode ciphers aes-ccm
bridge(config-ssid)# end
Step 3
encryption mode ciphers
{[
aes-ccm | ckip
|
cmic
|
ckip-cmic
|
tkip
]} {[
wep128
|
wep40
]}
Enables a cipher suite containing the WEP protection you need.
(
Table 3
lists guidelines for selecting a cipher suite to match the
type of authenticated key management you configure.)
•
Set the cipher options.
Note
You can combine TKIP with 128-bit or 40-bit WEP.
Note
You can combine AES with TKIP. In this case, AES is
the unicast cipher and TKIP becomes the group cipher.
Note
If you enable a cipher suite with two elements (such as
TKIP and 128-bit WEP), the second cipher becomes the
group cipher.
Note
You can also use the
encryption mode wep
command
to set up static WEP. However, you should use
encryption mode wep
only if none of the non-root
bridges that associate to the root device are capable of
key management. See the
Cisco IOS Command
Reference for Cisco Access Points and Bridges
for a
detailed description of the
encryption mode wep
command.
Note
When you configure TKIP-only, AES-only, or the
combination of AES and TKIP (no WEP included) on
any radio interface or VLAN, the SSID on that radio or
VLAN must be set to use WPA or CCKM key
management. If you do not configure key management
on the SSID, non-root bridge authentication fails on the
SSID.
Note
Cisco Key Integrity Protocol (CKIP) and
CKIP-Cisco Message Integrity Protocol (CMIP) are
supported only on the 2.4-GHz (802.11b/g) WMIC.
Step 4
end
Returns to privileged EXEC mode.
Step 5
copy running-config startup-config
(Optional) Saves your entries in the configuration file.
Command
Purpose
Содержание 3200 Series
Страница 14: ...xiv Cisco 3200 Series Wireless MIC Software Configuration Guide OL 6415 04 ...
Страница 120: ...Administering the WMIC Managing the System Time and Date 56 Cisco 3200 Series Wireless MIC Software Configuration Guide ...
Страница 136: ...Dynamic Frequency Selection Additional Information 6 Radio Channels and Transmit Frequencies OL 11491 03 ...
Страница 254: ...WIMIC Troubleshooting Error and Event Messages 12 Cisco 3200 Series Wireless MIC Software Configuration Guide ...
Страница 272: ...Supported MIBs Using FTP to Access the MIB Files 4 Cisco 3200 Series Wireless MIC Software Configuration Guide ...
Страница 314: ...Index IN 12 Cisco 3200 Series Wireless MIC Software Configuration Guide OL 6415 04 ...