MSM7xx Controllers Configuration Guide v6.4.0

WPA
This option enables support for users with WPA / WPA2 client software.
Mode
Support is provided for:
WPA (TKIP): (Not supported on the HP 517.) WPA with TKIP encryption. When you enable
this option, the VSC can only support legacy a/b/g traffic. All 802.11n features on a radio
are disabled for this VSC..
WPA2 (AES/CCMP): WPA2 (802.11i) with AES/CCMP encryption.
WPA or WPA2: Mixed mode supports both WPA (version 1) and WPA2 (version 2) at the
same time. Some legacy WPA clients may not work if this mode is selected. This mode is
slightly less secure than using the pure WPA2 (AES/CCMP) option. Note: On radios that have
Client restriction set to 802.11n only or 802.11ac only, WPA2 is always used instead of
WPA.
Key source
This option determines how the TKIP keys are generated.
Dynamic: This is a dynamic key that changes each time the user logs in and is authenticated.
The MPPE key is used to generate the TKIP keys that encrypt the wireless data stream. The key
is generated via the configured 802.1X authentication method. Therefore, when you enable
this option, the 802.1X authentication feature is automatically enabled.
Authentication can occur via the local user accounts and a remote authentication server (Active
Directory, or third-party RADIUS server). If both options are enabled, the local accounts are
checked first.
Preshared Key: The controller uses the key you specify in the Key field to generate the TKIP
keys that encrypt the wireless data stream. Since this is a static key, it is not as secure as the
RADIUS option. Specify a key that is between 8 and 63 alphanumeric characters in length.
HP recommends that the preshared key be at least 20 characters long, and be a mix of letters
and numbers. The double quote character (") should not be used.
128 Working with VSCs