Configuring user encryption 387
Nortel WLAN—Security Switch 2300 Series Configuration Guide

Configuring encryption for MAC clients

The following example shows how to configure WSS Software to provide PSK authentication and TKIP or 40-bit WEP
encryption for MAC clients:
1Create an authentication rule that sends all MAC users of SSID voice to the local database for
authentication and authorization. Type the following command:
WSS# set authentication ma c ssid voice * local
success: configuration saved.
2Configure a MAC user group named wpa-for-mac that assigns all MAC users in the group to VLAN blue.
Type the following command:
WSS# set mac-usergroup wpa-for-mac attr vlan-name blue
success: configuration saved.
3Add MAC users to MAC user group wpa-for-mac. Type the following commands:
WSS# set mac-user aa:bb:cc:dd:ee:ff group wpa-for-mac
success: configuration saved.
WSS# set mac-user a1:b1:c1:d1:e1:f1 group wpa-for-mac
success: configuration saved.
4Verify the AAA configuration changes. Type the following command:
WSS# show aaa
Default Values
authport=1812 acctport=1813 timeout=5 acct-timeout=5
retrans=3 deadtime=0 key=(null) author-pass=(null)
Radius Servers
Server Addr Ports T/o Tries Dead
State
---------------------------------------------------------------
----
Server groups
Web Portal:
enabled
set authentication mac ssid voice * local
mac-usergroup wpa-for-mac
vlan-name = blue
mac-user aa:bb:cc:dd:ee:ff
Group = wpa-for-mac
mac-user a1:b1:c1:d1:e1:f1
Group = wpa-for-mac