5-23
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide
OL-4211-03
Chapter5 Configuring the Client Adap ter Setting Security Parameters
PEAP authentication with WPA or WPA2
If using ADU to
configure card Choose WPA/WPA2/CCKM and
PEAP (EAP-GTC) or PEAP
(EAP-MSCHAP V2); then set
PEAP settings
For WPA, choose a cipher suite that
includes TKIP; then enable WPA
and Open with EAP Authentication
for the SSID
For WPA2, choose a cipher suite
that includes AES-CCMP; then
enable WPA and Open with EAP
Authentication for the SSID
Note To allow both WPA and
non-WPA clients to use the
SSID, enable optional
WPA.
If using Windows XP
to configure card Enable WPA and choose Enable
network access control using IEEE
802.1X and PEAP as the EAP Type
Note WPA2 is not yet available
in the Microsoft Wireless
Configuration Manager in
Windows XP.
For WPA, choose a cipher suite that
includes TKIP; then enable WPA
and Open with EAP Authentication
for the SSID
Note To allow both WPA and
non-WPA clients to use the
SSID, enable optional
WPA.
CCKM fast secure roaming Choose WPA/WPA2/CCKM and
LEAP, EAP-FAST, EAP-TLS,
PEAP (EAP-GTC), or PEAP (EAP
MSCHAP V2); then set the EAP
authentication settings
Note If you want to enable
CCKM, you must choose
WPA/WPA2/CCKM,
regardless of whether you
want the client adapter to
use WPA or WPA2. The
configuration of the access
point to which your client
adapter associates
determines whether CCKM
will be used with 802.1x,
WPA, or WPA2.
Use Cisco IOS Release 12.2(11)JA
or later, choose a cipher suite that is
compatible with CCKM, enable
both Network-EAP and Open with
EAP Authentication and CCKM
for the SSID, and configure for
participation in wireless domain
services (WDS)
Note To allow both 802.1X
clients and non-802.1X
clients to use the SSID,
enable optional CCKM.
Reporting access points
that fail LEAP
authentication
No settings required; automatically
enabled No settings required; automatically
enabled in the firmware versions
listed on page 5-19.
MIC No settings required; automatically
enabled Set up and enable WEP with full
encryption, set MIC to MMH or
check the Enable MIC check box,
and set Use Aironet Extensions to
Yes
Table5-4 Client and Access Point Security Settings (continued)
Security Feature Client Setting Access Point Setting