Configuring user encryption 385
Nortel WLAN—Security Switch 2300 Series Configuration Guide

Enabling dynamic WEP in a WPA network

The following example shows how to configure WSS Software to provide authentication and encryption for
801.X dynamic WEP clients, and for 801.X WPA clients using TKIP. This example assumes that pass-through
authentication is used for all users. The commands are the same as those in “Enabling WPA with TKIP” on
page 383, with the addition of a command to enable a WEP cipher suite. The WEP cipher suite allows authen-
tication and encryption for both WPA and non-WPA clients that want to authenticate using dynamic WEP.
1Create an authentication rule that sends all 802.1X users of SSID mycorp in the EXAMPLE
domain to the server group shorebirds for authentication. Type the following command:
WSS# set authentication dot1x ssid thiscorp EXAMPLE\* pass-through
shorebirds
2Create a service profile named wpa-wep for the SSID. Type the following command:
WSS# set service-profile wpa-wep
success: change accepted.
3Set the SSID in the service profile to thiscorp. Type the following command:
WSS# set service-profile wpa-wep ssid-name thiscorp
success: change accepted.
4Enable WPA in service profile wpa-wep. Type the following command:
WSS# set service-profile wpa-wep wpa-ie enable
success: change accepted.
5Enable the WEP40 cipher suite in service profile wpa-wep. Type the following command:
WSS# set service-profile wpa-wep cipher-wep40 enable
success: change accepted.
TKIP is already enabled by default when WPA is enabled.
6Display the service profile wpa-wep to verify the changes. Type the following command:
WSS# show service-profile sp1
ssid-name: mycorp ssid-type: crypto
Beacon: yes Proxy ARP: no
DHCP restrict: no No broadcast: no
Short retry limit: 5 Long retry limit: 5
Auth fallthru: none Sygate On-Demand (SODA): no
Enforce SODA checks: yes SODA remediation ACL:
Custom success web-page: Custom failure web-page:
Custom logout web-page: Custom agent-directory:
Static COS: no COS: 0
CAC mode: none CAC sessions: 14
User idle timeout: 180 Idle client probing: yes
Keep initial vlan: no Web Portal Session Timeout: 5
Web Portal ACL:
WEP Key 1 value: <none> WEP Key 2 value: <none>
WEP Key 3 value: <none> WEP Key 4 value: <none>
WEP Unicast Index: 1 WEP Multicast Index: 1
Shared Key Auth: NO
WPA enabled: