Specifications
Wireless LAN Configuration 277
Chapter 13
The equivalent CLI configuration to add the SSID shown above is:
ap location 0.0.0 phy-type a virtual-ap "NewSSID" vlan-id 0 opmode
staticWep,dynamicWep deny-bcast enable
ap location 0.0.0 phy-type g virtual-ap "NewSSID" vlan-id 0 opmode
staticWep,dynamicWep deny-bcast enable
WPA,TKIP, and AES Encryption
TKIP (Temporal Key Integrity Protocol) is a replacement for WEP, and along
with 802.1x forms the basis for WPA (Wi-Fi Protected Access). TKIP provides
a number of advantages over WEP, including per-frame key rotation, a longer
initialization vector, and a cryptographically-secure message integrity check.
TKIP may be configured in two different ways: Pre-Shared Key (PSK) or WPA.
PSK TKIP is designed for very small networks that do not contain an
authentication server and cannot use 802.1x. In PSK TKIP, a pre-shared key is
used by all clients in the network to establish initial communication. Once an
initial exchange has taken place, standard TKIP key rotation begins so that
each client uses a different key.
WPA TKIP requires the use of 802.1x for authentication and, similar to
dynamic WEP, provides a mechanism for the authentication server to assign a
unique encryption key to each client. WPA TKIP provides the best available L2
encryption available today.
To e n a b l e T K I P, select the appropriate radio button as shown in the figure
below.