Specifications

Configuring WPA
RoamAbout Mobility System Software Configuration Guide 10-3
Figure 10-1 Default Encryption
Thisrestofthischapterdescribestheencryptiontypesandhowtoconfigurethem,andprovides
configurationscenarios.
Configuring WPA
WiFiProtectedAccess(WPA)isasecurityenhancementtotheIEEE802.11wirelessstandard.
WPAprovidesenhancedencryptionwithnewciphersuitesandprovidesperpacketmessage
integritychecks.WPAisbasedonthe802.11istandard.YoucanuseWPAwith802.1X
authentication.Iftheclientdoesnotsupport802.1 X,
youcanuseapresharedkeyontheAPand
theclientforauthentication.
WPA Cipher Suites
WPAsupportsthefollowingciphersuitesforpacketencryption,listedfrommostsecuretoleast
secure:
CounterModewithCipherBlockChainingMessageAuthenticationCodeProtocol(CCMP)—
CCMPprovidesAdvancedEncryptionStandard(AES)dataencryption.Toprovidemessage
integrity,CCMPusestheCipherBlockChainingMessageAuthenticationCode(CBCMAC).
•TemporalKey
IntegrityProtocol(TKIP)—TKIPusestheRC4encryptionalgorithm,a128bit
encryptionkey,a48bitinitializationvector(IV),andamessageintegritycode(MIC)called
Michael.
•WiredEquivalentPrivacy(WEP)with104bitkeys—104bitWEPusestheRC4encryption
algorithmwitha104bitkey.
Encryption settings:
-WPA disabled
-Dynamic WEP enabled
-Static WEP disabled
User D
TKIP
WPA
User C
Static WEP
Non-WPA
User B
Dynamic 40-bit WEP
WPA
User A
Dynamic WEP
Non-WPA
RoamAbout Switch
AP
Layer 2