Cisco 7921G Administration Guide - Page 45

Cisco AP Configuration, Cisco Unified Wireless, IP Phone 7921G Security Mode, Configuration - wpa2

Page 45 highlights

Chapter 2 Overview of the VoIP Wireless Network Security for Voice Communications in WLANs Some authentication schemes require specific types of encryption. With Open authentication, you have the option to use static WEP for encryption for added security. But if you are using Shared Key authentication, you must set static WEP for encryption, and you must configure a WEP key on the phone. When using Authenticated Key Management (AKM) for the Cisco Unified Wireless IP Phone 7921G, several choices for both authentication and encryption can be set up on the APs with different SSIDs. When the phone attempts to authenticate, it chooses the AP that advertises the authentication and encryption scheme that the phone can support. Auto (AKM) mode can authenticate by using WPA, WPA2, WPA Pre-shared key, or CCKM. Note • When using WPA Pre-shared key or WPA2 Pre-shared key, the pre-shared key must be statically set on the phone. These keys must match the keys configured on the AP. • When using Auto (AKM), encryption options are automatically configured for WPA, WPA2, WPA Pre-shared key, WPA2 Pre-shared key, or CCKM. • In AKM mode, the phone will authenticate with LEAP if it is configured with WPA, WPA2, or CCKM key management. • The Cisco Unified Wireless IP Phone 7921G does not support auto EAP negotiation; to use EAP-FAST mode, you must specify it. • If AKM and 802.1x are used, the authentication method is LEAP. • The Cisco Unified Wireless IP Phone 7921G uses network EAP for 802.1x. Open EAP is also available. Table 2-6 provides a list of authentication and encryption schemes configured on the Cisco Aironet APs supported by the Cisco Unified Wireless IP Phone 7921G. The table shows the network configuration option for the phone that corresponds to the AP configuration. Table 2-6 Authentication and Encryption Schemes Cisco AP Configuration Authentication Open Open (Static WEP) Shared key (Static WEP) LEAP 802.1x LEAP WPA LEAP WPA2 EAP-FAST 802.1x EAP-FAST WPA EAP-FAST WPA2 EAP-TLS 802.1x Key Management Optional CCKM WPA with Optional CCKM WPA2 Optional CCKM WPA with Optional CCKM WPA2 Optional CCKM Common Encryption None WEP WEP WEP TKIP AES WEP TKIP AES WEP Cisco Unified Wireless IP Phone 7921G Security Mode Configuration Authentication Open Open+WEP Shared+WEP LEAP or Auto (AKM) LEAP or Auto (AKM) LEAP or Auto (AKM) EAP-FAST EAP-FAST EAP-FAST EAP-TLS OL-15985-01 Cisco Unified Wireless IP Phone 7921G Administration Guide for Cisco Unified Communications Manager Release 7.0 2-17

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234

2-17
Cisco Unified Wireless IP Phone 7921G Administration Guide for Cisco Unified Communications Manager Release 7.0
OL-15985-01
Chapter 2
Overview of the VoIP Wireless Network
Security for Voice Communications in WLANs
Some authentication schemes require specific types of encryption. With Open authentication, you have
the option to use static WEP for encryption for added security. But if you are using Shared Key
authentication, you must set static WEP for encryption, and you must configure a WEP key on the phone.
When using Authenticated Key Management (AKM) for the Cisco Unified Wireless IP Phone 7921G,
several choices for both authentication and encryption can be set up on the APs with different SSIDs.
When the phone attempts to authenticate, it chooses the AP that advertises the authentication and
encryption scheme that the phone can support. Auto (AKM) mode can authenticate by using WPA,
WPA2, WPA Pre-shared key, or CCKM.
Note
When using WPA Pre-shared key or WPA2 Pre-shared key, the pre-shared key must be statically
set on the phone. These keys must match the keys configured on the AP.
When using Auto (AKM), encryption options are automatically configured for WPA, WPA2, WPA
Pre-shared key, WPA2 Pre-shared key, or CCKM.
In AKM mode, the phone will authenticate with LEAP if it is configured with WPA, WPA2, or
CCKM key management.
The Cisco Unified Wireless IP Phone 7921G does not support auto EAP negotiation; to use
EAP-FAST mode, you must specify it.
If AKM and 802.1x are used, the authentication method is LEAP.
The Cisco Unified Wireless IP Phone 7921G uses network EAP for 802.1x. Open EAP is also
available.
Table 2-6
provides a list of authentication and encryption schemes configured on the Cisco Aironet APs
supported by the Cisco Unified Wireless IP Phone 7921G. The table shows the network configuration
option for the phone that corresponds to the AP configuration.
Table 2-6
Authentication and Encryption Schemes
Cisco AP Configuration
Cisco Unified Wireless
IP Phone 7921G Security Mode
Configuration
Authentication
Key
Management
Common
Encryption
Authentication
Open
None
Open
Open (Static WEP)
WEP
Open+WEP
Shared key (Static WEP)
WEP
Shared+WEP
LEAP 802.1x
Optional CCKM
WEP
LEAP or Auto (AKM)
LEAP WPA
WPA with
Optional CCKM
TKIP
LEAP or Auto (AKM)
LEAP WPA2
WPA2
AES
LEAP or Auto (AKM)
EAP-FAST 802.1x
Optional CCKM
WEP
EAP-FAST
EAP-FAST WPA
WPA with
Optional CCKM
TKIP
EAP-FAST
EAP-FAST WPA2
WPA2
AES
EAP-FAST
EAP-TLS 802.1x
Optional CCKM
WEP
EAP-TLS