Specifications
Configuring Access Points
9-38 Configuring Access Points
Verifying a Fingerprint on the Switch
ToverifyanAP’sfingerprintonaRoamAbout Switch,usethefollowingcommand:
set dap num fingerprint hex
wherehexisthe16‐digithexadecimalnumberofthefingerprint.Useacolonbetweeneachdigit.
MakesurethefingerprintyouentermatchesthefingerprintusedbytheAP.
Example
ThefollowingexamplesetsthefingerprintforDistributedAP8:
RBT-8100# set dap 8 fingerprint b4:f9:2a:52:37:58:f4:d0:10:75:43:2f:45:c9:52:c3
success: change accepted.
Setting the AP Security Requirement on a RoamAbout Switch
ToconfigureAPsecurityrequirements,usethefollowingcommand:
set dap security {require | optional | none}
TherequireoptionenforcesencryptionofmanagementtrafficforallDistributedAPs,and
requiresthekeyfingerprintstobeconfirmedinMSS.Thenoneoptiondisablesencryptionof
managementtrafficforallDistributedAPs.Thedefaultisoptional,whichallowsconnectionto
APswithorwithoutencryption
Example
ThefollowingcommandconfiguresaRoamAboutSwitchtorequireDistributedAPstohave
encryptionkeys:
RBT-8100# set dap security require
Fingerprint Log Message
IfAPencryptionisoptional,andanAPwhosefingerprinthasnotbeenverifiedinMSSestablishes
amanagementsessionwiththeRoamAboutSwitch,MSSgeneratesalogmessagesuchasthe
following:
DAP-HS:(secure optional)configure DAP 0335301065 with fingerprint
c6:98:9c:41:32:ab:37:09:7e:93:79:a4:ca:dc:ec:fb
ThemessageliststheserialnumberandfingerprintoftheAP.Youcancheckthisinformation
againstyourrecordstoverifythattheAPisauthentic.
Note: A change to AP security support does not affect management sessions that are already
established. To apply the new setting to an AP, restart the AP.