Specifications

Encryption Configuration Scenarios
10-20 Configuring User Encryption
Enabling Dynamic WEP in a WPA Network
ThefollowingexampleshowshowtoconfigureMSStoprovideauthenticationandencryptionfor
801.XdynamicWEPclients,andfor801.XWPAclientsusingTKIP.Thisexampleassumesthat
passthroughauthenticationisusedforallusers.Thecommandsarethesameasthosein
EnablingWPAwithTKIPon
page 1018,withtheadditionofacommandtoenableaWEP
ciphersuite.TheWEPciphersuiteallowsauthenticationandencryptionforbothWPAandnon
WPAclientsthatwanttoauthenticateusingdynam icWEP.
1. Createanauthenticationrulethatsendsall802.1XusersofSSIDmycorpintheEXAMPLE
domaintotheservergroupshorebirdsforauthentication.Typethefollowingcommand:
RBT-8100# set authentication dot1x ssid thiscorp EXAMPLE\* pass-throughhwork
shorebirds
2. CreateaserviceprofilenamedwpawepfortheSSID.Typethefollowingcommand:
RBT-8100# set service-profile wpa-wep
3. SettheSSIDintheserviceprofiletothiscorp.Typethefollowingcommand:
RBT-8100# set service-profile wpa-wep ssid-name thiscorp
4. EnableWPAinserviceprofilewpawep.Typethefollowingcommand:
RBT-8100# set service-profile wpa-wep wpa-ie enable
5. EnabletheWEP40ciphersuiteinserviceprofilewpawep.Typethefollowingcommand:
RBT-8100# set service-profile wpa-wep cipher-wep40 enable
6. Displaytheserviceprofilewpaweptoverifythechanges.Typethefollowingcommand:
RBT-8100# show service-profile sp1
ssid-name: mycorp ssid-type: crypto
Beacon: yes Proxy ARP: no
DHCP restrict: no No broadcast: no
Short retry limit: 5 Long retry limit: 5
Auth fallthru: none Sygate On-Demand (SODA): no
Enforce SODA checks: yes SODA remediation ACL:
Custom success web-page: Custom failure web-page:
Custom logout web-page: Custom agent-directory:
Static COS: no COS: 0
CAC mode: none CAC sessions: 14
User idle timeout: 180 Idle client probing: yes
Keep initial vlan: no Web Portal Session Timeout: 5
Web Portal ACL:
WEP Key 1 value: <none> WEP Key 2 value: <none>
WEP Key 3 value: <none> WEP Key 4 value: <none>
WEP Unicast Index: 1 WEP Multicast Index: 1
Shared Key Auth: NO
WPA enabled:
ciphers: cipher-tkip, cipher-wep40
authentication: 802.1X
TKIP countermeasures time: 60000ms
7. Mapserviceprofilewpaweptoradioprofilerp2.Typethefollowingcommands:
RBT-8100# set radio-profile rp2 service-profile wpa-wep