Specifications
Configuring Access Points
9-36 Configuring Access Points
Encryption Options
Bydefault,MSSdoesnotencryptmanagementcommunicationbetweentheRoamAboutSwitch
andAPs,eveniftheAPmodelsupportsencryption.Thedefaultsettingisnone.
YoucanconfiguretheRoamAboutSwitchtouseencryptionbysettingsecuritytooptionalor
require:
• optional—APscanbemanagedbytheswitch
eveniftheydonothaveencryptionkeysor
theirkeyshavenotbeenverifiedbyanadministrator.
• require—AllAPsmusthaveencryptionkeys.TheRoamAboutSwitchdoesnotestablisha
managementsessionwithanAPunlesstheAPhasakey,andyouhaveverifiedthekey’s
fingerprintin
MSSusingthesetdapfingerprintcommand.
Table 9‐8liststheAPsecurityoptionsandwhetheranAPcanestablishamanagementsession
withaRoamAboutSwitchbasedontheoptionsettings.
Note: A change to AP security support does not affect management sessions that are already
established. To apply the new setting to an AP, restart the AP.
Table 9-8 AP Security Requirements
AP Security
Setting
AP Has
Fingerprint?
Fingerprint
Verified in MSS?
AP Can Establish Management Session
with Switch?
AP Security
Required
Yes Yes Yes
No No
No Not Applicable No
AP Security
Optional
Yes Yes Yes
1
1. MSS generates a log message listing the AP serial number and fingerprint so you can verify the AP’s identity.
(Refer to “Fingerprint Log Message” on page 9-38.)
No Yes
1
No Not Applicable Yes