
GLOBAL CONFIGURATION COMMANDS 4 - 151
Parameters
Example
rfs7000-37FABE(config-wlan-wlan1)#wpa-wpa2 tkip-countermeasures hold-time 2
rfs7000-37FABE(config-wlan-1)#show context
wlan 1
ssid Test1
vlan 2
bridging-mode tunnel
exclude-wpa2-tkip Excludes the WPA2 version of TKIP, support only WPA-TKIP
handshake [attempts <1-
5>|init-wait <5-1000000>|
priority|timeout <10-5000>]
Configures the parameters related to the WPA/WPA2 handshake
• attempts <1-5> – Configures the total number of times a message is
transmitted towards a non-responsive client
• init-wait <5-1000000> – Configure a wait-time before the first message
of the handshake is transmitted from the AP
• priority [high|normal] – Configure the relative priority of the handshake
messages compared to other data traffic
• high – Treats handshake messages as high priority packets in the ra-
dio
• normal – Treats handshake messages as normal priority packets in
the radio
• timeout <10-5000> – Configures the timeout for a handshake message,
before it is retried
key-rotation
[broadcast|unicast] <30-
86400>
Configures parameters related to periodic rotation of encryption keys
• broadcast – Sets the rotation of keys used for broadcast and multicast
traffic
• unicast – Sets the rotation of keys used for unicast traffic
• <30-86400> – Specify the time in seconds when the keys are rotated
opp-pmk-caching Enables the use of opportunistic key caching (same PMK across APs for
fast roaming with EAP.802.1x)
pmk-caching Enables the use of cached pairwise master keys (fast roaming with eap/
802.1x)
preauthentication Enables preauthentication usage (WPA2 fast roaming)
psk[0|2|<LINE>] <LINE>
• psk – Configures a pre-shared key
The following parameters are common for the above:
• 0 – Enter a clear text key
• 2 – Enter an encrypted key
• <LINE> – Enter pre-shared key either as a passphrase between 8 and
63 characters long, or as a 64 character (256bit) hexadecimal value
• <LINE> – Enter pre-shared key either as a passphrase between 8
and 63 characters long, or as a 64 character (256bit) hexadecimal
value
tkip-countermeasures
holdtime <0-65535>
Configures TKIP countermeasures related parameters
• <holdtime <0-65535> – Configures the amount of time a WLAN is
disabled when TKIP counter measures are invoked
• <0-65535> – Enter the hold-time in seconds
Comentarios a estos manuales