User's Guide

Table Of Contents
Configuring a VNS
hwc_vnsconfiguration.fm
Configuring WLAN Services
9034530-02, March 2010
316 HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide
Pre-authentication
Opportunistic Keying & Pre-auth
The following sections explain the key management options.
None
The wireless client device performs a complete 802.1x authentication each time
it associates or tries to connect to a Wireless AP.
Opportunistic Keying
Opportunistic Keying or opportunistic key caching (OKC) enables the client
devices to roam fast and securely from one Wireless AP to another in 802.1X
authentication setup.
The client devices that run applications such as video streaming and VoIP require
rapid reassociation during roaming. OKC helps such client devices by enabling
them to rapidly reassociate with the Wireless APs. This avoids delays and gaps
in transmission and thus helps in secure fast roaming (SFR).
Note: The client devices should support OKC to use the OKC feature in the
HiPath WLAN.
Pre-authentication
Pre-authentication enables a client device to authenticate simultaneously with
multiple Wireless APs in 802.1X authentication setup. When the client device
roams from one Wireless AP to another, it does not have to perform the complete
802.1X authentication to reassociate with the new Wireless AP as it is already
pre-authenticated with it. This reduces the reassociation time and thus helps in
seamless roaming.
Note: The client devices should support pre-authentication to use the pre-
authentication feature in HiPath WLAN.
Opportunistic Keying & Pre-auth
Opportunistic Keying and Pre-auth options is meant for the device clients that
support both the authentication processes. For example, the Microsoft-operated
device clients support opportunistic keying by default, but they can be configured
to support pre-authentication too.