User's Manual

Table Of Contents
4/1/05 Local MAC Filter
OL-7426-02
>config wlan security wpa encryption tkip <wlan id>
>config wlan security wpa encryption wep <wlan id> [40/104/128]
where <wlan id> = 1 through 16, and [40/104/128] = 40/64, 104/128, or 128/156 encryption
bits (default = 104).
Use the show wlan command to verify that you have WPA enabled.
Layer 3 SecurityLayer 3 Security
IPSecIPSec
IPSec (Internet Protocol Security) supports many Layer 3 security protocols.
Use the show wlan command to show the current IPSec configuration.
Use the following command to enable IPSec on a WLAN:
>config wlan security ipsec [enable/disable] <WLAN id>
where <WLAN id> = 1 through 16.
Use the show wlan command to verify that you have IPSec enabled.
IPSec AuthenticationIPSec Authentication
IPSec uses hmac-sha-1 authentication as the default for encrypting WLAN data, but can also use
hmac-md5, or no authentication.
Use the show wlan command to view the current IPSec authentication protocol.
Use the following command to configure the IPSec IP authentication:
>config wlan security ipsec authentication [hmac-md5/hmac-sha-1/none] <WLAN
id>
where <WLAN id> = 1 through 16.
Use the show wlan command to verify that you have correctly set the IPSec authentication.
IPSec EncryptionI
IPSec Encryption
IPSec uses 3DES encryption as the default for encrypting WLAN data, but can also use AES, DES, or no
encryption.
Use the show wlan command to view the current IPSec encryption.
Use the following command to configure the IPSec encryption:
>config wlan security ipsec encryption [3des/aes/des/none] <WLAN id>
where aes= AES-CBC, and where <WLAN id> = 1 through 16.
Use the show wlan command to verify that you have correctly set the IPSec encryption.
Note: WLANs are created in disabled mode; leave them disabled until you have
finished configuring them.
Note: Using Layer 3 security requires that the Cisco 4100 Series Wireless LAN
Controller be equipped with a VPN/Enhanced Security Module (Crypto Module). The
ESM plugs into the rear of the Cisco 4100 Series Wireless LAN Controller, and
provides the extra processing power needed for processor-intensive security
algorithms.