Configuring The Gtk Rekey Method - H3C MSR Series Configuration Manual

Comware 5 wlan
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

To configure the PTK lifetime:
Step
1.
Enter system view.
2.
Enter WLAN service
template view.
3.
Configure the PTK lifetime.

Configuring the GTK rekey method

A fat AP generates a group temporal key (GTK) and sends the GTK to a client during the
authentication process between an AP and the client through group key handshake or the 4-way
handshake. The client uses the GTK to decrypt broadcast and multicast packets. The Robust
Security Network (RSN) negotiates the GTK through the 4-way handshake or group key handshake,
and Wi-Fi Protected Access (WPA) negotiates the GTK only through group key handshake.
Two GTK rekey methods can be configured:
Time-based GTK rekey—After the specified interval elapses, GTK rekey occurs.
Packet-based GTK rekey—After the specified number of packets is sent, GTK rekey occurs.
By default, time-based GTK rekey is adopted, and the rekey interval is 86400 seconds.
Configuring a new GTK rekey method overwrites the previous one. For example, if time-based GTK
rekey is configured after packet-based GTK rekey is configured, time-based GTK rekey takes effect.
You can also configure the device to start GTK rekey when a client goes offline.
Configuring GTK rekey based on time
Step
1.
Enter system view.
2.
Enter WLAN service
template view.
3.
Enable GTK rekey.
4.
Configure the GTK rekey
interval.
5.
Configure the device to
start GTK rekey when a
client goes offline.
Configuring GTK rekey based on packet
Step
1.
Enter system view.
2.
Enter WLAN service
template view.
Command
system-view
wlan service-template
service-template-number crypto
ptk-lifetime time
Command
system-view
wlan service-template
service-template-number crypto
gtk-rekey enable
gtk-rekey method time-based
[ time ]
gtk-rekey client-offline enable
Command
system-view
wlan service-template
service-template-number crypto
37
Remarks
N/A
N/A
Optional.
By default, the PTK lifetime is
43200 seconds.
Remarks
N/A
N/A
By default, GTK rekey is
enabled.
By default, the interval is 86400
seconds.
Optional.
By default, the device does not
start GTK rekey when a client
goes offline.
This command takes effect only
when you execute the
gtk-rekey enable command.
Remarks
N/A
N/A

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents