Cisco 7925G Administration Guide - Page 49

Cisco AP Configuration, Cisco Unified Wireless, IP Phone 7925G Configuration, Authentication - wpa2

Page 49 highlights

Chapter 2 Overview of the VoIP Wireless Network Security for Voice Communications in WLANs Some authentication schemes require specific types of encryption. With Open authentication, you have the option to use static WEP for encryption for added security. But if you are using Shared Key authentication, you must set static WEP for encryption, and you must configure a WEP key on the phone. When using Authenticated Key Management (AKM) for the Cisco Unified Wireless IP Phone 7925G, several choices for both authentication and encryption can be set up on the APs with different SSIDs. When the phone attempts to authenticate, it chooses the AP that advertises the authentication and encryption scheme that the phone can support. Auto (AKM) mode can authenticate by using WPA, WPA2, WPA Pre-shared key, or CCKM. Note • When using WPA Pre-shared key or WPA2 Pre-shared key, the pre-shared key must be statically set on the phone. These keys must match the keys configured on the AP. • When using Auto (AKM), encryption options are automatically configured for WPA, WPA2, WPA Pre-shared key, WPA2 Pre-shared key, or CCKM. • In AKM mode, the phone will authenticate with LEAP if it is configured with WPA, WPA2, or CCKM key management. • The Cisco Unified Wireless IP Phone 7925G does not support auto EAP negotiation; to use EAP-FAST mode, you must specify it. • If AKM and 802.1x are used, the authentication method is LEAP. • The Cisco Unified Wireless IP Phone 7925G uses network EAP for 802.1x but you can enable open EAP. Table 2-7 provides a list of authentication and encryption schemes configured on the Cisco Aironet APs supported by the Cisco Unified Wireless IP Phone 7925G. The table shows the network configuration option for the phone that corresponds to the AP configuration. Table 2-7 Authentication and Encryption Schemes Cisco AP Configuration Authentication Open Open (Static WEP) Shared key (Static WEP) LEAP 802.1x LEAP WPA LEAP WPA2 EAP-FAST 802.1x EAP-FAST with WPA Key Management Optional CCKM Common Encryption None WEP WEP WEP WPA with TKIP Optional CCKM WPA2 AES Optional CCKM WEP WPA TKIP Optional CCKM Cisco Unified Wireless IP Phone 7925G Configuration Authentication Open Open+WEP Shared+WEP LEAP or Auto (AKM) LEAP or Auto (AKM) LEAP or Auto (AKM) EAP-FAST EAP-FAST OL-15984-01 Cisco Unified Wireless IP Phone 7925G Administration Guide for Cisco Unified Communications Manager 7.0(1) 2-19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244

2-19
Cisco Unified Wireless IP Phone 7925G Administration Guide for Cisco Unified Communications Manager 7.0(1)
OL-15984-01
Chapter 2
Overview of the VoIP Wireless Network
Security for Voice Communications in WLANs
Some authentication schemes require specific types of encryption. With Open authentication, you have
the option to use static WEP for encryption for added security. But if you are using Shared Key
authentication, you must set static WEP for encryption, and you must configure a WEP key on the phone.
When using Authenticated Key Management (AKM) for the Cisco Unified Wireless IP Phone 7925G,
several choices for both authentication and encryption can be set up on the APs with different SSIDs.
When the phone attempts to authenticate, it chooses the AP that advertises the authentication and
encryption scheme that the phone can support. Auto (AKM) mode can authenticate by using WPA,
WPA2, WPA Pre-shared key, or CCKM.
Note
When using WPA Pre-shared key or WPA2 Pre-shared key, the pre-shared key must be statically
set on the phone. These keys must match the keys configured on the AP.
When using Auto (AKM), encryption options are automatically configured for WPA, WPA2, WPA
Pre-shared key, WPA2 Pre-shared key, or CCKM.
In AKM mode, the phone will authenticate with LEAP if it is configured with WPA, WPA2, or
CCKM key management.
The Cisco Unified Wireless IP Phone 7925G does not support auto EAP negotiation; to use
EAP-FAST mode, you must specify it.
If AKM and 802.1x are used, the authentication method is LEAP.
The Cisco Unified Wireless IP Phone 7925G uses network EAP for 802.1x but you can enable open
EAP.
Table 2-7
provides a list of authentication and encryption schemes configured on the Cisco Aironet APs
supported by the Cisco Unified Wireless IP Phone 7925G. The table shows the network configuration
option for the phone that corresponds to the AP configuration.
Table 2-7
Authentication and Encryption Schemes
Cisco AP Configuration
Cisco Unified Wireless
IP Phone 7925G Configuration
Authentication
Key
Management
Common
Encryption
Authentication
Open
None
Open
Open (Static WEP)
WEP
Open+WEP
Shared key (Static WEP)
WEP
Shared+WEP
LEAP
802.1x
Optional CCKM
WEP
LEAP or Auto (AKM)
LEAP
WPA
WPA with
Optional CCKM
TKIP
LEAP or Auto (AKM)
LEAP
WPA2
WPA2
AES
LEAP or Auto (AKM)
EAP-FAST
802.1x
Optional CCKM
WEP
EAP-FAST
EAP-FAST with WPA
WPA
Optional CCKM
TKIP
EAP-FAST