Specifications

RoamAbout Mobility System Software Configuration Guide 10-1
10
Configuring User Encryption
MobilitySystemSoftware(MSS)encryptswirelessusertrafficforalluserswhoaresuccessfully
authenticatedtojoinan encryptedSSIDandwhoarethenauthorizedtojoinaVLAN.MSS
supportsthefollowingtypesofencryptionforwirelessusertraffic:
802.11i
•WiFiProtectedAccess(WPA)
•RobustSecurityNetwork(RSN)
•NonWPA
dynamicWiredEquivalentPrivacy(WEP)
•NonWPAstaticWEP
WEPisdescribedintheIEEE802.11standardandWPAisdescribedinthe802.11istandard.
WPAand802.11iprovidestrongersecuritythanWEP.(802.11iusesRobustSecurityNetwork(RSN),
andissometimescalledWPA2.)
TouseWPAorRSN,aclient
mustsupportit.FornonWPAclients,MSSsupportsWEP.Ifyour
networkcontainsacombinationofWPA,RSN,clientsandnonWPAclients,youcanconfigure
MSStoprovideencryptionforbothtypesofclients.
ToconfigureencryptionparametersforanSSID,createoreditaserviceprofile,mapthe
service
profiletoaradioprofile,andaddradiostotheradioprofile.TheSSIDname,advertisement
setting(beaconing),andencryptionsettingsareconfiguredintheserviceprofile.
YoucanconfigureanSSIDtosupportanycombinationofWPA,RSN,andnonWPAclients.For
example,aradiocansimultaneouslyuse
TemporalKeyIntegrityProtocol(TKIP)encryptionfor
WPAclientsandWEPencryptionfornonWPAclients.
TheSSIDtypemustbecrypto(encrypted)forencryptiontobeused.IftheSSIDtypeisclear,
wirelesstrafficisnotencrypted,regardlessoftheencryptionsettings.
For information about...
Refer to page...
Configuring WPA 10-3
Configuring RSN (802.11i) 10-12
Configuring WEP 10-15
Encryption Configuration Scenarios 10-18
Note: MSS does not encrypt traffic in the wired part of the network. MSS does not encrypt wireless
or wired traffic for users who associate with an unencrypted (clear) SSID.