10-4
Cisco IOS Software Configuration Guide for Cisco Aironet Access Points
OL-11350-01
Chapter10 Configuring Cipher Suites and WEP
Configuring Cipher Suites and WEP
Beginning in privileged EXEC mode, follow these steps to create a WEP key and set the key properties:
This example shows how to create a 128-bit WEP key in slot 3 for VLAN 22 and sets the key as the
transmit key:
ap1200# configure terminal
ap1200(config)# interface dot11radio 0
ap1200(config-if)# encryption vlan 22 key 3 size 128 12345678901234567890123456
transmit-key
ap1200(config-if)# end
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 interface dot11radio { 0 | 1 } Enter interface configuration mode for the radio interface. The
2.4-GHz radio is radio 0, and the 5-GHz radio is radio 1.
Step3 encryption
[vlan vlan-id]
key 1-4
size { 40 | 128 } encryption-key
[ 0 | 7 ]
[transmit-key]
Create a WEP key and set up its properties.
(Optional) Select the VLAN for which you want to create
a key.
Name the key slot in which this WEP key resides. Up to 16
VLANs can be assigned. You can assign up to 4 WEP keys
for each VLAN4 WEP keys to one of the VLANs.
Enter the key and set the size of the key, either 40-bit or
128-bit. 40-bit keys contain 10 hexadecimal digits; 128-bit
keys contain 26 hexadecimal digits.
(Optional) Specify whether the key is encrypted (7) or
unencrypted (0).
(Optional) Set this key as the transmit key. The key in slot
1 is the transmit key by default.
Note If you configure static WEP with MIC or CMIC, the
access point and associated client devices must use the
same WEP key as the transmit key, and the key must be
in the same key slot on the access point and the clients.
Note Using security features such as authenticated key
management can limit WEP key configurations. See the
“WEP Key Restrictions” section on page 10-5 for a list
of features that impact WEP keys.
Step4 end Return to privileged EXEC mode.
Step5 copy running-config startup-config (Optional) Save your entries in the configuration file.