Specifications
Command Groups
RoamAbout Access Point 3000 Configuration Guide A-143
multicast-cipher
Thiscommanddefinesthecipheralgorithmusedforbroadcastingandmulticastingwhenusing
Wi‐FiProtectedAccess(WPA)security.
Syntax
multicast-cipher <AES | TKIP | WEP>
•AES‐AdvancedEncryptionStandard
•TKIP‐TemporalKeyIntegrityProtocol
•WEP‐WiredEquivalentPrivacy
Default Setting
WEP
Command Mode
InterfaceConfiguration(Wireless)
InterfaceConfiguration(Wireless):VAP
Command Usage
•UsethiscommandforthedefaultinterfaceoranyofthesevenVAPsconfigurableperradio
interface.
•WPAenablestheaccesspointtosupportdifferentunicastencryptionkeysforeachclient.
However,theglobalencryptionkeyformulticastandbroadcasttrafficmustbe thesamefor
allclients.This
commandsetstheencryptiontypethatissupportedbyallclients.
•IfanyclientssupportedbytheaccesspointarenotWPAenabled,themulticast‐cipher
algorithmmustbesettoWEP.
•WEPisthefirstgenerationsecurityprotocolusedtoencryptdatacrossingthewireless
mediumusingafairly
shortkey.CommunicatingdevicesmustusethesameWEPkeyto
encryptanddecryptradiosignals.WEPhasmanysecurityflaws,andisnotrecommended
fortransmittinghighlysensitivedata.
•TKIPprovidesdata encryptionenhancementsincludingper‐packetkeyhashing(i.e.,
changingtheencryptionkeyoneachpacket),amessage
integritycheck,anextended
initializationvectorwithsequencingrules,anda re‐keyingmechanism.
•TKIPdefendsagainstattacksonWEPinwhichtheun‐encryptedinitializationvectorin
encryptedpacketsisusedtocalculatetheWEPkey.TKIPchangestheencryptionkeyon
eachpacket,androtatesnotjust
theunicastkeys,butthebroadcastkeysaswell.TKIPisa
replacementforWEPthatremovesthepredictabilitythatintrudersreliedontodete rmine
theWEPkey.
•AEShasbeendesignatedbytheNationalInstituteofStandardsandTe chnology asthe
successortotheDataEncryptionStandard(DES)encryption
algorithm,andwillbeusedby
theU.S.governmentforencryptingallsens itive,nonclassifiedinformation.Becauseofits
strength,andresistancetoattack,AESisalsobeingincorporatedaspartofthe802.11
standard.