Specifications
Managing 802.1X Encryption Keys
19-4 Managing 802.1X on the RoamAbout Switch
Managing WEP Keys
Wired‐EquivalentPriva c y(WEP)ispartofthesystemsecurityof802.1X. MSSusesWEPto
provideconfidentialitytopacketsastheyaresentovertheair.WEPoperatesontheaccesspoint.
WEPusesasecretkeysharedbetweenthecommunicators.WEPrekeyingincreasesthesecurityof
thenetwork.New
unicastkeysaregeneratedeverytimeaclientperforms802.1Xauthentication.
Therekeyingprocesscanbeperformedautomaticallyonaperiodicbasis.BysettingtheSession‐
TimeoutRADIUSattrib ute,youmakethereauthenticationtransparenttotheclient,whois
unawarethatreauthenticationisoccurring.AgoodvalueforSession‐Timeout
is30 minutes.
WEPbroadcastrekeyingcausesthebroadcastandmulticastkeysforWEPtoberotatedevery
WEPrekeyperiodforeachradiotoeachconnectedVLAN.TheRASgeneratesthenewbroadcast
andmulticastkeysandpushesthekeystotheclientsviaEAPoLkeymessages.WEPkeysarecase‐
insensitive.
Usethesetdot1xwep‐rekeyandthesetdot1xwep‐rekey‐periodcommandstoenableWEPkey
rotationandconfigurethetimeintervalforWEPkeyrotation.
Configuring 802.1X WEP Rekeying
WEPrekeyingisenabledbydefaultontheRoamAboutSwitch.DisableWEPrekeyingonlyifyou
needtodebugyour802.1Xnetwork.
Examples
UsethefollowingcommandtodisableWEPrekeyingforbroadcastandmulticastkeys:
RBT-8100# set dot1x wep-rekey disable
success: wep rekeying disabled
ToreenableWEPrekeying,typethefollowingcommand:
RBT-8100# set dot1x wep-rekey enable
success: wep rekeying enabled
Configuring the Interval for WEP Rekeying
ThefollowingcommandsetstheintervalforrotatingtheWEPbroadcastandmulticastkeys:
set dot1x wep-rekey-period seconds
Thedefaultis1800 seconds(30 minutes).Youcansettheintervalfrom30 to1,641,600 seconds
(19 days).
Example
TypethefollowingcommandtosettheWEP‐rekeyperiodto900 seconds:
RBT-8100# set dot1x wep-rekey-period 900
success: dot1x wep-rekey-period set to 900
Note: Reauthentication is not required for using this command. Broadcast and multicast keys are
always rotated at the same time, so all members of a given radio and VLAN receive the new keys at
the same time.