Specifications

Command Groups
RoamAbout Access Point 3000 Configuration Guide A-143
multicast-cipher
Thiscommanddefinesthecipheralgorithmusedforbroadcastingandmulticastingwhenusing
WiFiProtectedAccess(WPA)security.
Syntax
multicast-cipher <AES | TKIP | WEP>
AES‐AdvancedEncryptionStandard
TKIP‐TemporalKeyIntegrityProtocol
WEP‐WiredEquivalentPrivacy
Default Setting
WEP
Command Mode
InterfaceConfiguration(Wireless)
InterfaceConfiguration(Wireless):VAP
Command Usage
UsethiscommandforthedefaultinterfaceoranyofthesevenVAPsconfigurableperradio
interface.
WPAenablestheaccesspointtosupportdifferentunicastencryptionkeysforeachclient.
However,theglobalencryptionkeyformulticastandbroadcasttrafficmustbe thesamefor
allclients.This
commandsetstheencryptiontypethatissupportedbyallclients.
IfanyclientssupportedbytheaccesspointarenotWPAenabled,themulticastcipher
algorithmmustbesettoWEP.
WEPisthefirstgenerationsecurityprotocolusedtoencryptdatacrossingthewireless
mediumusingafairly
shortkey.CommunicatingdevicesmustusethesameWEPkeyto
encryptanddecryptradiosignals.WEPhasmanysecurityflaws,andisnotrecommended
fortransmittinghighlysensitivedata.
TKIPprovidesdata encryptionenhancementsincludingperpacketkeyhashing(i.e.,
changingtheencryptionkeyoneachpacket),amessage
integritycheck,anextended
initializationvectorwithsequencingrules,anda rekeyingmechanism.
TKIPdefendsagainstattacksonWEPinwhichtheunencryptedinitializationvectorin
encryptedpacketsisusedtocalculatetheWEPkey.TKIPchangestheencryptionkeyon
eachpacket,androtatesnotjust
theunicastkeys,butthebroadcastkeysaswell.TKIPisa
replacementforWEPthatremovesthepredictabilitythatintrudersreliedontodete rmine
theWEPkey.
AEShasbeendesignatedbytheNationalInstituteofStandardsandTe chnology asthe
successortotheDataEncryptionStandard(DES)encryption
algorithm,andwillbeusedby
theU.S.governmentforencryptingallsens itive,nonclassifiedinformation.Becauseofits
strength,andresistancetoattack,AESisalsobeingincorporatedaspartofthe802.11
standard.