User Guide

Wireless Security Commands
7-115
7
wpa2-psk - Clients using WPA2 with a Pre-shared Key are accepted for
authentication.
wpa-wpa2-mixed - Clients using WPA or WPA2 are accepted for
authentication.
wpa-wpa2-psk-mixed - Clients using WPA or WPA2 with a Pre-shared
Key are accepted for authentication
required - Clients are required to use WPA or WPA2.
supported - Clients may use WPA or WPA2, if supported.
Default Setting
open-system
Command Mode
Interface Configuration (Wireless-VAP)
Command Usage
To use WEP, set the authentication method to either “open-system” or
“shared-key.” Shared key authentication can only be used when WEP is
enabled with the encryption command, and at least one static WEP key
has been defined with the key command.
When any WPA or WPA2 option is selected, clients are authenticated using
802.1X via a RADIUS server. Each client must be WPA-enabled or support
802.1X client software. The 802.1X settings (see “802.1X Authentication”
on page 7-66) and RADIUS server details (see “RADIUS Client” on
page 7-60) must be configured on the access point. A RADIUS server must
also be configured and be available in the wired network.
If a WPA/WPA2 mode that operates over 802.1X is selected (WPA, WPA2,
WPA-WPA2-mixed, or WPA-WPA2-PSK-mixed), the 802.1X settings (see
“802.1X Authentication” on page 7-66) and RADIUS server details (see
“RADIUS Client” on page 7-60) must be configured. Be sure you have also
configured a RADIUS server on the network before enabling authentication.
Also, note that each client has to be WPA-enabled or support 802.1X client
software. A RADIUS server must also be configured and be available in the
wired network.
If a WPA/WPA2 Pre-shared Key mode is selected (WPA-PSK, WPA2-PSK
or WPA-WPA2-PSK-mixed), the key must first be generated and distributed
to all wireless clients before they can successfully associate with the access
point. Use the wpa-preshared-key command to configure the key (see “key”
on page 7-118 and “transmit-key” on page 7-119).
WPA2 defines a transitional mode of operation for networks moving from
WPA security to WPA2. WPA2 Mixed Mode allows both WPA and WPA2
clients to associate to a common VAP interface. When the encryption
cipher suite is set to TKIP, the unicast encryption cipher (TKIP or
AES-CCMP) is negotiated for each client. The access point advertises it’s
supported encryption ciphers in beacon frames and probe responses. WPA
and WPA2 clients select the cipher they support and return the choice in the