Specifications
Command Groups
RoamAbout Access Point 3000 Configuration Guide A-145
wpa-clients
ThiscommanddefineswhetherWi‐FiProtectedAccess(WPA)isrequired,optionallysupported,
ornotsupportedforclientstations.
Syntax
wpa-clients <not-supported | required | supported>
•not‐supported‐AccesspointdoesnotsupportclientsusingWPA.
•required‐Supportsonlyclientsusing WPA.
•supported‐SupportclientswithorwithoutWPA.
Default Setting
Supported
Command Mode
InterfaceConfiguration(Wireless)
InterfaceConfiguration(Wireless):VAP
Command Usage
•UsethiscommandforthedefaultinterfaceoranyofthesevenVAPsconfigurableperradio
interface.
•Wi‐FiProtectedAccess(WPA)providesimproveddataencryption,whichwasweakin
WEP,anduserauthentication,whichwaslargelymissinginWEP.WPAusesthefollowing
securitymechanisms.
•EnhancedDataEncryption
throughTKIP
•WPAusesTemporalKeyIntegrityProtocol(TKIP).TKIPprovidesdataencryption
enhancementsincludingper‐packetkeyhashing(i.e.,changingtheencryptionkeyoneach
packet),amessageintegritycheck,anextendedinitializationvectorwithsequencingrules,
andare‐keyingmechanism.
•Enterprise‐levelUserAuthenticationvia802.1x
andEAP
•Tostrengthenuserauthentication,WPAuses802.1xandtheExtensibleAuthentication
Protocol(EAP).Usedtogether,theseprotocolsprovidestronguserauthenticationviaa
centralRADIUSauthenticationserverthatauthenticateseachuseronthenetworkbefore
theyjoinit.WPAalsoemploys“mutualauthentication”topreventawirelessclient
from
accidentallyjoiningaroguenetwork.