Assigning Encryption Types To Wireless Users; Assigning And Clearing Encryption Types Locally - Nortel 2360 Configuration Manual

Wlan-security switch 2300 series
Hide thumbs Also See for 2360:
Table of Contents

Advertisement

532 Configuring AAA for network users

Assigning encryption types to wireless users

When a user turns on a wireless laptop or PDA, the device attempts to find an access point and form an association with
it. Because APs support the encryption of wireless traffic, clients can choose an encryption type to use. You can
configure APs to use the encryption algorithms supported by the Wi-Fi Protected Access (WPA) security enhancement
to the IEEE 802.11 wireless standard. (For details, see
If you have configured APs to use specific encryption algorithms, you can enforce the type of encryption a user or group
must have to access the network. When you assign the Encryption-Type attribute to a user or group, the encryption type
or types are entered as an authorization attribute into the user or group record in the local WSS database or on the
RADIUS server. Encryption-Type is a Nortel vendor-specific attribute (VSA).
Clients who attempt to use an unauthorized encryption method are rejected.

Assigning and clearing encryption types locally

To restrict wireless uses or groups with user profiles in the local WSS database to particular encryption algorithms for
accessing the network, use one of the following commands:
set user username attr encryption-type value
set usergroup groupname attr encryption-type value
set mac-user username attr encryption-type value
set mac-usergroup groupname attr encryption-type value
WSS Software supports the following values for Encryption-Type, listed from most secure to least secure. (For user
encryption details, see
"Configuring user encryption" (page
Encryption-type value
1
2
4
8
16
32
64
For example, the following command restricts the MAC user group mac-fans to access the network by using only TKIP:
WSS# set mac-usergroup mac-fans attr encryption-type 4
NN47250-500 (320657-F Version 02.01)
"Configuring user encryption" (page
291).)
Encryption algorithm assigned
Advanced Encryption Standard using Counter
with Cipher Block Chaining Message
Authentication Code (CBC-MAC)—or
AES_CCM.
Reserved.
Temporal Key Integrity Protocol (TKIP).
Wired-Equivalent Privacy protocol using
104 bits of key strength (WEP_104). This is the
default.
Wired-Equivalent Privacy protocol using 40 bits
of key strength (WEP_40).
No encryption.
Static WEP
291).)

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

23502361Wlan 2382

Table of Contents