Configuring User Encryption 217

Configuring Encryption for MAC Clients

The following example shows how to configure WSS Software to provide PSK authentication and TKIP or 40-bit WEP encryption for MAC clients:

1Create an authentication rule that sends all MAC users of SSID voice to the local database for authentication and authorization. Type the following command:

23x0# set authentication mac ssid voice * local success: configuration saved.

2Configure a MAC user group named wpa-for-macthat assigns all MAC users in the group to VLAN blue. Type the following command:

23x0# set mac-usergroup wpa-for-mac attr vlan-name blue success: configuration saved.

3Add MAC users to MAC user group wpa-for-mac. Type the following commands:

23x0# set mac-user aa:bb:cc:dd:ee:ff group wpa-for-mac success: configuration saved.

23x0# set mac-user a1:b1:c1:d1:e1:f1 group wpa-for-mac success: configuration saved.

4Verify the AAA configuration changes. Type the following command:

23x0# show aaa

Default Values

authport=1812 acctport=1813 timeout=5 acct-timeout=5 retrans=3 deadtime=0 key=(null) author-pass=(null)

Radius Servers

 

 

Server

Addr

Ports T/o Tries Dead

State

 

 

---------------------------------------------------------------

----

Server groups

set authentication mac ssid voice * local

mac-usergroup wpa-for-mac vlan-name = blue

mac-user aa:bb:cc:dd:ee:ff Group = wpa-for-mac

mac-user a1:b1:c1:d1:e1:f1 Group = wpa-for-mac

5Create a service profile named wpa-wep-for-macfor SSID voice. Type the following command:

23x0# set service-profile wpa-wep-for-mac

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 217
Image 217
Nortel Networks 2300 manual Configuring Encryption for MAC Clients, 23x0# set service-profile wpa-wep-for-mac