User's Manual

Table Of Contents
4/1/05 Local MAC Filter
OL-7426-02
IKE AuthenticationIKE Authentication
IPSec IKE (Internet Key Exchange) uses pre-shared key exchanges, x.509 (RSA Signatures) certifi-
cates, and XAuth-psk for authentication.
Use the show wlan command to see if IPSec IKE is enabled.
Use the following commands to configure IKE authentication on a WLAN with IPSec enabled:
>config wlan security ipsec ike authentication certificates <wlan id>
>config wlan security ipsec ike authentication xauth-psk <wlan id> <key>
>config wlan security ipsec ike authentication pre-shared-key <wlan id> <key>
where <wlan id> = 1 through 16, certificates = RSA signatures, xauth-psk = XAuth pre-shared
key, and <key> = Preshared Key (Eight to 255 ASCII characters, case sensitive).
Use the show wlan command to verify that you have IPSec IKE enabled.
IKE Diffie-Hellman Group
IKE Diffie-Hellman Group
IPSec IKE uses Diffie-Hellman groups to block easily decrypted keys.
Use the show wlan command to verify whether or not the Cisco Wireless LAN Controller has
IPSec IKE DH Groups properly set.
Use the following command to configure the IKE Diffie-Hellman group on a WLAN with IPSec
enabled:
>config wlan security ipsec ike DH-Group <WLAN id> <group-id>
where <WLAN id> = 1 through 16; <group-id> = group-1, group-2 (default), or group-5.
Use the show wlan command to verify that the Cisco Wireless LAN Controller has IPSec IKE DH
Groups properly set.
IKE Phase 1 Aggressive and Main Modes
IKE Phase 1 Aggressive and Main Modes
IPSec IKE uses the Phase 1 Aggressive (faster) or Main (more secure) mode to set up encryption
between clients and the Cisco Wireless LAN Controller.
Use the show wlan command to see if the Cisco Wireless LAN Controller has IPSec IKE
Aggressive mode enabled.
If necessary, use the following command to configure the IKE Aggressive or Main mode on a
WLAN with IPSec enabled:
>config wlan security ipsec ike phase1 [aggressive/main] <WLAN id>
where <WLAN id> = 1 through 16.
Use the show wlan command to verify that you have IPSec IKE Aggressive or Main mode
enabled.
IKE Lifetime Timeout
IKE Lifetime Timeout
IPSec IKE uses its timeout to limit the time that an IKE key is active.
Use the show wlan command to see the current IPSec IKE lifetime timeout.
Use the following command to configure the IKE lifetime on a WLAN with IPSec enabled:
>config wlan security ipsec ike lifetime <WLAN id> <seconds>
where <WLAN id> = 1 through 16, and <seconds> = 1800 through 345600 seconds (default =
28800 seconds).
Use the show wlan command to verify that you have IPSec IKE timeout properly set.