Specifications
Configuring WEP
RoamAbout Mobility System Software Configuration Guide 10-15
Configuring WEP
Wired‐EquivalentPriva c y(WEP)isasecurityprotocoldefinedinthe802.11standard.WEPuses
theRC4encryptionalgorithmtoencryptdata.
Toprovideintegritychecking,WEPaccesspointsandclientschecktheintegrityofaframe’scyclic
redundancycheck(CRC),generateanintegritycheckvalue(ICV),andappendthevalue
tothe
framebeforesendingit.TheradioorclientthatreceivestheframerecalculatestheICVand
comparestheresulttotheICVintheframe.Ifthevaluesmatch,theframeisprocessed.Ifthe
valuesdonotmatch,theframeisdiscarded.
WEPiseitherdynamicorstatic
dependingonhowtheencryptionkeysaregenerated.APs
supportdynamicWEPandstaticWEP.
•FordynamicWEP,MSSdynamicallygenerateskeysforbroadcast,multicast,andunicast
traffic.MSSgeneratesuniq ueunicastkeysforeachclientsessionandperiodicallyregenerates
(rotates)thebroadcastandmulticastkeysforallclients.You
canchangeordisablethe
broadcastormulticastrekeyinginterval.
•ForstaticWEP,MSSusesstatically configuredkeystypedintheRoamAboutSwitch’s
configurationandonthewirelessclientanddoesnotrotatethekeys.
DynamicWEPencryptionisenabledbydefault.YoucandisabledynamicWEPsupportby
enablingWPA
andleavingtheWEP‐40orWEP‐104ciphersuitesdisabled.Ifyouusedynamic
WEP,802.1XmustalsobeconfiguredontheclientinadditiontoWEP.
StaticWEPencryptionisdisabledbydefault.ToenablestaticWEPencryption,configurethestatic
WEPkeysandassignthemtounicastand
multicasttraffic.Makesureyouconfigurethesame
statickeysontheclients.
TosupportdynamicWEPinaWPAenvironment,enableWPAandenabletheWEP‐40orWEP‐
104ciphersuite.(SeeConfiguringWPAonpage 10‐7.)
ThissectiondescribeshowtoconfigureandassignstaticWEPkeys.(To
changeotherkey‐related
settings,see“Managing802.1XEncryptionKeys”onpage 19‐3.)
Figure 10‐4onpage 10‐16showsanexampleofaradioconfiguredtoprovidestaticanddynamic
WEPencryptionfornon‐WPAclients.Theradiousesdynamicallygeneratedkeystoencrypt
trafficfordynamicWEPclients.The
radioalsoencryptstrafficforstaticWEPclientswhosekeys
matchthekeysconfiguredontheradio.