240Configuring AP access points

Service Profiles

A service profile controls advertisement and encryption for an SSID. You can specify the following:

Whether SSIDs that use the service profile are beaconed

Whether the SSIDs are encrypted or clear (unencrypted)

For encrypted SSIDs, the encryption settings to use

The fallthru authentication method for users that are not authenticated with 802.1X or MAC authentication Table 8 lists the parameters controlled by a service profile and their default values.

Table 8:

Defaults for Service Profile Parameters

 

 

 

 

 

 

 

 

 

Default

Radio Behavior When

 

Parameter

Parameter Set To Default

 

Value

 

 

 

Value

 

 

 

 

 

 

 

 

 

auth-dot1x

enable

When the Wi-Fi Protected Access

 

 

 

 

(WPA) information element (IE) is

 

 

 

 

enabled, uses 802.1X to authenticate

 

 

 

 

WPA clients.

 

 

 

 

 

auth-fallthru

web-portal

Uses Web-based AAA for users who do

 

 

 

 

not match an 802.1X or MAC

 

 

 

 

authentication rule for the SSID

 

 

 

 

requested by the user.

 

 

 

 

 

auth-psk

disable

Does not support using a preshared key

 

 

 

 

(PSK) to authenticate WPA clients.

 

 

 

 

 

beacon

enable

Sends beacons to advertise the SSID

 

 

 

 

managed by the service profile.

 

 

 

 

 

cipher-ccmp

disable

Does not use Counter with Cipher

 

 

 

 

Block Chaining Message

 

 

 

 

Authentication Code Protocol (CCMP)

 

 

 

 

to encrypt traffic sent to WPA clients.

 

 

 

 

 

cipher-tkip

enable

When the WPA IE is enabled, uses

 

 

 

 

Temporal Key Integrity Protocol

 

 

 

 

(TKIP) to encrypt traffic sent to WPA

 

 

 

 

clients.

 

 

 

 

 

cipher-wep104

disable

Does not use Wired Equivalent Privacy

 

 

 

 

(WEP) with 104-bit keys to encrypt

 

 

 

 

traffic sent to WPA clients.

 

 

 

 

 

cipher-wep40

disable

Does not use WEP with 40-bit keys to

 

 

 

 

encrypt traffic sent to WPA clients.

 

 

 

 

 

psk-phrase

No passphrase

Uses dynamically generated keys rather

 

 

 

defined

than statically configured keys to

 

 

 

 

authenticate WPA clients.

 

 

 

 

 

psk-raw

No preshared

Uses dynamically generated keys rather

 

 

 

key defined

than statically configured keys to

 

 

 

 

authenticate WPA clients.

 

 

 

 

 

320657-A

Page 240
Image 240
Nortel Networks 2300 manual Service Profiles