Cisco Systems CB21AG Synchronizing Security Features, Additional WEP Key Security Features, Ssid

Models: CB21AG

1 286
Download 286 pages 35.03 Kb
Page 86
Image 86

Chapter 5 Configuring the Client Adapter

Setting Security Parameters

Additional WEP Key Security Features

The three security features discussed in this section (MIC, TKIP, and broadcast key rotation) are designed to prevent sophisticated attacks on your wireless network’s WEP keys. These features do not need to be enabled on the client adapter; they are supported automatically in the client adapter software. However, they must be enabled on the access point.

Note Refer to the documentation for your access point for instructions on enabling these security features.

Message Integrity Check (MIC)

MIC prevents bit-flip attacks on encrypted packets. During a bit-flip attack, an intruder intercepts an encrypted message, alters it slightly, and retransmits it, and the receiver accepts the retransmitted message as legitimate. The MIC adds a few bytes to each packet to make the packets tamper-proof.

The Advanced Status window indicates if MIC is being used, and the Advanced Statistics window provides MIC statistics.

Temporal Key Integrity Protocol (TKIP)

This feature, also referred to as WEP key hashing, defends against an attack on WEP in which the intruder uses the initialization vector (IV) in encrypted packets to calculate the WEP key. TKIP removes the predictability that an intruder relies on to determine the WEP key by exploiting IVs. It protects both unicast and broadcast WEP keys.

Note TKIP is enabled automatically when WPA is enabled, and it is disabled when WPA is disabled.

Broadcast Key Rotation

When you enable broadcast WEP key rotation, the access point provides a dynamic broadcast WEP key and changes it at the interval you select.

Synchronizing Security Features

In order to use any of the security features discussed in this section, both your client adapter and the access point to which it will associate must be set appropriately. Table 5-4indicates the client and access point settings required for each security feature. This chapter provides specific instructions for enabling the security features on your client adapter. Refer to the documentation for your access point for instructions on enabling any of these features on the access point.

 

 

 

 

Table 5-4

Client and Access Point Security Settings

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Security Feature

Client Setting

Access Point Setting

 

 

 

 

 

 

 

 

 

 

 

 

Static WEP with open

Choose Open authentication and

Set up and enable WEP and enable

 

 

 

 

authentication

 

Pre-Shared Key (Static WEP) and

Open Authentication for the SSID

 

 

 

 

 

 

create a WEP key

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Static WEP with shared key

Choose Shared authentication and

Set up and enable WEP and enable

 

 

 

 

authentication

 

Pre-Shared Key (Static WEP) and

Shared Key Authentication for the

 

 

 

 

 

 

create a WEP key

SSID

 

 

 

 

 

 

 

 

 

 

 

Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide

 

 

 

 

5-20

 

 

 

 

 

OL-4211-03

 

 

 

 

 

 

 

 

Page 86
Image 86
Cisco Systems CB21AG manual Synchronizing Security Features, Additional WEP Key Security Features, Ssid