Specifications

Configuring WEP
RoamAbout Mobility System Software Configuration Guide 10-15
Configuring WEP
WiredEquivalentPriva c y(WEP)isasecurityprotocoldefinedinthe802.11standard.WEPuses
theRC4encryptionalgorithmtoencryptdata.
Toprovideintegritychecking,WEPaccesspointsandclientschecktheintegrityofaframe’scyclic
redundancycheck(CRC),generateanintegritycheckvalue(ICV),andappendthevalue
tothe
framebeforesendingit.TheradioorclientthatreceivestheframerecalculatestheICVand
comparestheresulttotheICVintheframe.Ifthevaluesmatch,theframeisprocessed.Ifthe
valuesdonotmatch,theframeisdiscarded.
WEPiseitherdynamicorstatic
dependingonhowtheencryptionkeysaregenerated.APs
supportdynamicWEPandstaticWEP.
•FordynamicWEP,MSSdynamicallygenerateskeysforbroadcast,multicast,andunicast
traffic.MSSgeneratesuniq ueunicastkeysforeachclientsessionandperiodicallyregenerates
(rotates)thebroadcastandmulticastkeysforallclients.You
canchangeordisablethe
broadcastormulticastrekeyinginterval.
•ForstaticWEP,MSSusesstatically configuredkeystypedintheRoamAboutSwitch’s
configurationandonthewirelessclientanddoesnotrotatethekeys.
DynamicWEPencryptionisenabledbydefault.YoucandisabledynamicWEPsupportby
enablingWPA
andleavingtheWEP40orWEP104ciphersuitesdisabled.Ifyouusedynamic
WEP,802.1XmustalsobeconfiguredontheclientinadditiontoWEP.
StaticWEPencryptionisdisabledbydefault.ToenablestaticWEPencryption,configurethestatic
WEPkeysandassignthemtounicastand
multicasttraffic.Makesureyouconfigurethesame
statickeysontheclients.
TosupportdynamicWEPinaWPAenvironment,enableWPAandenabletheWEP40orWEP
104ciphersuite.(SeeConfiguringWPAonpage 107.)
ThissectiondescribeshowtoconfigureandassignstaticWEPkeys.(To
changeotherkeyrelated
settings,seeManaging802.1XEncryptionKeysonpage 193.)
Figure 104onpage 1016showsanexampleofaradioconfiguredtoprovidestaticanddynamic
WEPencryptionfornonWPAclients.Theradiousesdynamicallygeneratedkeystoencrypt
trafficfordynamicWEPclients.The
radioalsoencryptstrafficforstaticWEPclientswhosekeys
matchthekeysconfiguredontheradio.