set dap security 327

„require — Require all Distributed MAPs to have encryption keys that have been verified in the CLI by an administrator. If a MAP does not have an encryption key or the key has not been verified, the WX does not establish a management session with the MAP.

„optional — Allows MAPs to be managed by the switch even if they do not have encryption keys or their keys have not been verified by an administrator. Encryption is used for MAPs that support it.

„none — Encryption is not used, even for MAPs that support it.

Defaults — The default setting is none.

Access — Enabled.

History —Introduced in MSS 4.0.

Usage — This parameter applies to all Distributed MAPs managed by the switch. If you change the setting to required, the switch requires Distributed MAPs to have encryption keys. The switch also requires their fingerprints to be verified in MSS. When MAP security is required, a MAP can establish a management session with the WX only if its fingerprint has been verified by you in MSS.

A change to MAP security support does not affect management sessions that are already established. To apply the new setting to an MAP, restart the MAP.

Examples — The following command configures an WX to require Distributed MAPs to have encryption keys:

WX-1200#set dap security require

See Also

„set dap fingerprint on page 312

„display {ap dap} config on page 277

„display {ap dap} status on page 287