Cisco AIR-AP1242AG-E-K9 Hardware Installation Guide - Page 47

Understanding Express Security Settings, Using VLANs, Express Security Types

Page 47 highlights

Chapter 3 Configuring the Access Point for the First Time Configuring Basic Security Settings Understanding Express Security Settings When the access point configuration is at factory defaults, the first SSID that you create by using the Express Security page overwrites the default SSID (tsunami), which has no security settings. The SSIDs that you create appear in the SSID table at the bottom of the page. You can create up to 16 SSIDs on the access point. Note In Cisco IOS Release 12.3(4)JA and later, there is no default SSID. You must configure an SSID before client devices can associate to the access point. Using VLANs If you use VLANs on your wireless LAN and assign SSIDs to VLANs, you can create multiple SSIDs by using any of the four security settings on the Express Security page. However, if you do not use VLANs on your wireless LAN, the security options that you can assign to SSIDs are limited because on the Express Security page encryption settings and authentication types are linked. Without VLANs, encryption settings (WEP and ciphers) apply to an interface, such as the radio, and you cannot use more than one encryption setting on an interface. For example, when you create an SSID with static WEP with VLANs disabled, you cannot create additional SSIDs with WPA authentication because they use different encryption settings. If you find that the security setting for an SSID conflicts with another SSID, you can delete one or more SSIDs to eliminate the conflict. If any VLANs are defined on the access point, the trunk port on the switch must be limited to allow only the VLANs defined on the access point. Express Security Types Table 3-2 describes the four security types that you can assign to an SSID. Table 3-2 Security Types on Express Security Setup Page Security Type No Security Static WEP Key Description Security Features Enabled This is the least secure option. You should use this option only for SSIDs used in a public space and assign it to a VLAN that restricts access to your network. None. This option is more secure than no security. However, static WEP keys are vulnerable to attack. If you configure this setting, you should consider limiting association to the bridge based on MAC address (refer to the Cisco IOS Software Configuration Guide for Cisco Aironet Access Points). Mandatory WEP. Client devices cannot associate using this SSID without a WEP key that matches the bridge's key. OL-4310-05 Cisco Aironet 1200 Series Access Point Hardware Installation Guide 3-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

3-11
Cisco Aironet 1200 Series Access Point Hardware Installation Guide
OL-4310-05
Chapter 3
Configuring the Access Point for the First Time
Configuring Basic Security Settings
Understanding Express Security Settings
When the access point configuration is at factory defaults, the first SSID that you create by using the
Express Security page overwrites the default SSID (tsunami), which has no security settings. The SSIDs
that you create appear in the SSID table at the bottom of the page. You can create up to 16 SSIDs on the
access point.
Note
In Cisco IOS Release 12.3(4)JA and later, there is no default SSID. You must configure an SSID before
client devices can associate to the access point.
Using VLANs
If you use VLANs on your wireless LAN and assign SSIDs to VLANs, you can create multiple SSIDs
by using any of the four security settings on the Express Security page. However, if you do not use
VLANs on your wireless LAN, the security options that you can assign to SSIDs are limited because on
the Express Security page encryption settings and authentication types are linked. Without VLANs,
encryption settings (WEP and ciphers) apply to an interface, such as the radio, and you cannot use more
than one encryption setting on an interface. For example, when you create an SSID with static WEP with
VLANs disabled, you cannot create additional SSIDs with WPA authentication because they use
different encryption settings. If you find that the security setting for an SSID conflicts with another
SSID, you can delete one or more SSIDs to eliminate the conflict.
If any VLANs are defined on the access point, the trunk port on the switch must be limited to allow only
the VLANs defined on the access point.
Express Security Types
Table 3-2
describes the four security types that you can assign to an SSID.
Table 3-2
Security Types on Express Security Setup Page
Security Type
Description
Security Features Enabled
No Security
This is the least secure option. You should
use this option only for SSIDs used in a
public space and assign it to a VLAN that
restricts access to your network.
None.
Static WEP Key
This option is more secure than no security.
However, static WEP keys are vulnerable to
attack. If you configure this setting, you
should consider limiting association to the
bridge based on MAC address (refer to the
Cisco IOS Software Configuration Guide
for Cisco Aironet Access Points)
.
Mandatory WEP. Client devices
cannot associate using this SSID
without a WEP key that matches
the bridge
’s
key.