User Guide

Table Of Contents
Configuring User Encryption 199
Nortel WLAN Security Switch 2300 Series Configuration Guide
WPA Authentication Methods
You can configure an SSID to support one or both of the following authentication methods for WPA clients:
802.1X—The AP access point and client use an Extensible Authentication Protocol (EAP) method to authenticate
one another, then use the resulting key in a handshake to derive a unique key for the session. The 802.1X
authentication method requires user information to be configured on AAA servers or in the WSS switch’s local
database. This is the default WPA authentication method.
Preshared key (PSK)—An AP radio and a client authenticate one another based on a key that is statically
configured on both devices. The devices then use the key in a handshake to derive a unique key for the session. For
a given service profile, you can globally configure a PSK for use with all clients. You can configure the key by
entering an ASCII passphrase or by entering the key itself in raw (hexadecimal) form.
Note. For a MAC client that authenticates using a PSK, the RADIUS servers or
local database still must contain an authentication rule for the client, to assign the
client to a VLAN.
Note. The Web-based AAA fallthru authentication type is not supported in
conjunction with WPA encryption using preshared keys (PSK) for the same SSID.
These options are configurable together but are not compatible. Web-based AAA
traffic is not encrypted, whereas the PSK four-way handshake requires a client to
already be authenticated and for encryption to be in place.