Chapter 5 Configuring Encryption Types

Configure Encryption Types

 

Command

Purpose

Step 3

 

 

encryption

Enable a cipher suite containing the encryption you need.

 

[vlan vlan-id]

Table 5-3lists guidelines for selecting a cipher suite that

 

mode ciphers

matches the type of authenticated key management you

 

{[aes-ccm tkip]} {[wep128

configure.

 

wep40]}

(Optional) Select the VLAN for which you want to enable

 

 

 

 

WEP and WEP features.

 

 

Set the cipher options and WEP level. You can combine

 

 

TKIP with 128-bit or 40-bit WEP.

 

 

Note You can also use the encryption mode wep command

 

 

to set up static WEP. However, you should use

 

 

encryption mode wep only if no clients that associate

 

 

to the access point are capable of key management. See

 

 

the Cisco IOS Command Reference for Cisco Access

 

 

Points and Bridges for a detailed description of the

 

 

encryption mode wep command.

 

 

Note When you configure the cipher TKIP and AES-CCM

 

 

(not TKIP + WEP 128 or TKIP + WEP 40) for an

 

 

SSID, the SSID must use WPA key management. Client

 

 

authentication fails on an SSID that uses the cipher

 

 

TKIP without enabling WPA key management.

Step 4

 

 

end

Return to privileged EXEC mode.

Step 5

 

 

copy running-config startup-config

(Optional) Save your entries in the configuration file.

 

 

 

Use the no form of the encryption command to disable a cipher suite.

This example sets up a cipher suite for VLAN 22 that enables AES-CCM, and 128-bit WEP.

router# configure terminal

router(config)# interface dot11radio 0

router(config-if)#encryption vlan 22 mode ciphers aes-ccm wep128

router(config-if)# exit

Cipher Suites Compatible with WPA

If you configure your access point to use WPA authenticated key management, you must select a cipher suite compatible with the authenticated key management type. Table 5-3lists the cipher suites that are compatible with WPA.

Cisco Wireless ISR and HWIC Access Point Configuration Guide

5-6

OL-6415-04

 

 

Page 82
Image 82
Cisco Systems OL-6415-04 manual Cipher Suites Compatible with WPA