Specifications
Configuring WPA
RoamAbout Mobility System Software Configuration Guide 10-3
Figure 10-1 Default Encryption
Thisrestofthischapterdescribestheencryptiontypesandhowtoconfigurethem,andprovides
configurationscenarios.
Configuring WPA
Wi‐FiProtectedAccess(WPA)isasecurityenhancementtotheIEEE802.11wirelessstandard.
WPAprovidesenhancedencryptionwithnewciphersuitesandprovidesper‐packetmessage
integritychecks.WPAisbasedonthe802.11istandard.YoucanuseWPAwith802.1X
authentication.Iftheclientdoesnotsupport802.1 X,
youcanuseapresharedkeyontheAPand
theclientforauthentication.
WPA Cipher Suites
WPAsupportsthefollowingciphersuitesforpacketencryption,listedfrommostsecuretoleast
secure:
• CounterModewithCipherBlockChainingMessageAuthenticationCodeProtocol(CCMP)—
CCMPprovidesAdvancedEncryptionStandard(AES)dataencryption.Toprovidemessage
integrity,CCMPusestheCipherBlockChainingMessageAuthenticationCode(CBC‐MAC).
•TemporalKey
IntegrityProtocol(TKIP)—TKIPusestheRC4encryptionalgorithm,a128‐bit
encryptionkey,a48‐bitinitializationvector(IV),andamessageintegritycode(MIC)called
Michael.
•WiredEquivalentPrivacy(WEP)with104‐bitkeys—104‐bitWEPusestheRC4encryption
algorithmwitha104‐bitkey.
Encryption settings:
-WPA disabled
-Dynamic WEP enabled
-Static WEP disabled
User D
TKIP
WPA
User C
Static WEP
Non-WPA
User B
Dynamic 40-bit WEP
WPA
User A
Dynamic WEP
Non-WPA
RoamAbout Switch
AP
Layer 2