Huawei quidway s7700 Configuration Manual page 182

Smart routing switch
Hide thumbs Also See for quidway s7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - SPU
l
Issue 01 (2011-07-15)
2.
Run:
{ wpa | wpa2 } authentication-method dot1x { peap | tls } encryption-
method { tkip | ccmp }
The dot1x authentication and corresponding encryption mode are configured for the
WPA/WPA2 policy.
NOTE
If WPA/WPA2 dot1x authentication is configured, run the dot1x-authentication enable
command on a WLAN-ESS interface.
3.
Run:
{ wpa | wpa2 } authentication-method psk { pass-phrase | hex } key
encryption-method { tkip | ccmp }
The shared key authentication and corresponding encryption mode are configured for
the WPA/WPA2 policy.
WAPI authentication
1.
Run:
security-policy wapi
The WAPI security policy is configured.
2.
Run:
wapi authentication-method { certificate | psk { pass-phrase | hex } key }
The authentication mode is set for the WAPI security policy.
WAPI supports two authentication modes: certificate authentication and pre-shared
key authentication. When pre-shared key authentication is used, the shared key must
be configured.
3.
Run:
wapi import certificate { ac | asu | issuer } file-name file_name
The AC certificate file, certificate of the AC certificate issuer, and ASU certificate
file are imported.
4.
Run:
wapi import private-key file-name file_name
The AC private key file is imported.
5.
Run:
wapi asu ip ip-address
The ASU server's IP address is configured.
If WAPI certificate authentication is configured, an AC will send the certificate to the
ASU server at the configured IP address.
6.
(Optional) Run the following commands to modify WAPI parameters:
– Run:
wapi { bk-threshold bk-threshold | bk-update-interval bk-interval }
The interval for updating a base key (BK) and the BK lifetime percentage are set.
By default, the interval for updating a BK is 43200s, and the BK lifetime percentage
is 70%.
– Run:
wapi { msk-update-interval msk-interval | msk-update-packet msk-packet
| msk-retrans-count msk-count }
The interval for updating an MBMS service key (MSK), the number of packets
that will trigger MSK update, and the number of retransmissions of MSK
negotiation packets are set.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
5 WLAN Configuration
171

Advertisement

Table of Contents
loading

Table of Contents