SMC Networks EliteConnect SMCE21011 User Manual page 223

802.11b/g/n ap
Hide thumbs Also See for EliteConnect SMCE21011:
Table of Contents

Advertisement

S
YNTAX
multicast-cipher <aes-ccmp | tkip >
aes-ccmp - Use AES-CCMP encryption for the unicast and multicast
cipher.
tkip - Use TKIP encryption for the multicast cipher. TKIP or AES-
CCMP can be used for the unicast cipher depending on the capability
of the client.
D
S
EFAULT
ETTING
None
C
M
OMMAND
ODE
Interface Configuration (Wireless-VAP)
C
U
OMMAND
SAGE
WPA enables the access point to support different unicast encryption
keys for each client. However, the global encryption key for multicast
and broadcast traffic must be the same for all clients.
TKIP provides data encryption enhancements including per-packet key
hashing (i.e., changing the encryption key on each packet), a message
integrity check, an extended initialization vector with sequencing rules,
and a re-keying mechanism. Select TKIP if there are clients in the
network that are not WPA2 compliant.
TKIP defends against attacks on WEP in which the unencrypted
initialization vector in encrypted packets is used to calculate the WEP
key. TKIP changes the encryption key on each packet, and rotates not
just the unicast keys, but the broadcast keys as well. TKIP is a
replacement for WEP that removes the predictability that intruders
relied on to determine the WEP key.
AES-CCMP (Advanced Encryption Standard Counter-Mode/CBCMAC
Protocol): WPA2 is backward compatible with WPA, including the same
802.1X and PSK modes of operation and support for TKIP encryption.
The main enhancement is its use of AES Counter-Mode encryption with
Cipher Block Chaining Message Authentication Code (CBC-MAC) for
message integrity. The AES Counter-Mode/CBCMAC Protocol (AES-
CCMP) provides extremely robust data confidentiality using a 128-bit
key. The AES-CCMP encryption cipher is specified as a standard
requirement for WPA2. However, the computational intensive
operations of AES-CCMP requires hardware support on client devices.
Therefore to implement WPA2 in the network, wireless clients must be
upgraded to WPA2-compliant hardware.
E
XAMPLE
AP(if-wireless g: VAP[0])#multicast-cipher TKIP
AP(if-wireless g)#
– 223 –
| Wireless Security Commands
C
27
HAPTER

Advertisement

Table of Contents
loading

Table of Contents