Cisco C3230ENC-1WMIC-K9 Software Guide - Page 31

Features

Page 31 highlights

Overview of the Cisco WMIC Features Features The WMIC running Cisco IOS offers these software features: • VLANs-Allow VLAN trunking on both wireless and Ethernet interfaces. • QoS-Use this feature to support quality of service (QoS) for prioritizing traffic on the wireless interface. The WMIC supports required elements of Wi-Fi Multimedia (WMM) for QoS, which improves the user experience for audio, video, and voice applications over a Wi-Fi wireless connection and is a subset of the IEEE 802.11e QoS standard. WMM supports QoS prioritized media access through the Enhanced Distributed Channel Access (EDCA) method. • Multiple Basic SSIDs-Support up to 8 basic service set identifiers (SSIDs) in access point mode. • RADIUS Accounting-Enable accounting on the WMIC to send accounting data about wireless client devices to a RADIUS server on your network. • TACACS+ administrator authentication-Enable TACACS+ for server-based, detailed accounting information and flexible administrative control over authentication and authorization processes. It provides secure, centralized validation of administrators attempting to gain access to your WMIC. • Enhanced security-Enable three advanced security features to protect against sophisticated attacks on your wireless network's WEP keys: Message Integrity Check (MIC) and WEP key hashing. Enhanced security for Wi-Fi Protected Access (WPA) with AES and Temporal Key Integrity Protocol (TKIP) encryption is also available. • Enhanced authentication services-Set up non-root bridges or workgroup bridges to authenticate to the network like other wireless client devices. After a network username and password for the non-root bridge or workgroup bridge are set, it authenticates to the network using Cisco Light Extensible Authentication Protocol (LEAP), and receives and uses dynamic WEP keys. • 802.1x supplicant-Support 802.1x, the standardized framework defined by the IEEE to provide port-based network access using information unique to the client and with credentials known only to the client. The supplicant refers to the client software that supports the 802.1x and EAP protocols. The 802.1x supplicant provides a secure method for accomplishing this authentication. Transport Layer Security (TLS) is an enhancement to SSL and provides data encryption in conjunction with EAP. • EAP-TLS and EAP-FAST-Support EAP-TLS and EAP-FAST in workgroup bridge and non-root device mode. • Advanced Encryption Standard (AES) -This feature supports Advanced Encryption Standard-Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (AES-CCMP). AES-CCMP is required for Wi-Fi Protected Access 2 (WPA2) and IEEE 802.11i wireless LAN security. • Enhanced authentication for Cisco Centralized Key Management (CCKM). • Roaming-Support fast, secure roaming of client devices, and radio management through wireless domain services (WDS) (See the "WDS, Fast Secure Roaming, and Radio Management" document for more information. • Universal workgroup bridge-Support interoperability with non-Cisco devices. • Prioritized Multiple Client Profiles. • Any SSID- May associate to any root device as long the encrption and authentication settings match. • Management Frame Protection (MFP)-Support management frame protection version 1 and 2. Cisco 3200 Series Wireless MIC Software Configuration Guide 7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314

Overview of the Cisco WMIC
Features
7
Cisco 3200 Series Wireless MIC Software Configuration Guide
Features
The WMIC running Cisco IOS offers these software features:
VLANs—Allow VLAN trunking on both wireless and Ethernet interfaces.
QoS—Use this feature to support quality of service (QoS) for prioritizing traffic on the wireless
interface. The WMIC supports required elements of Wi-Fi Multimedia (WMM) for QoS, which
improves the user experience for audio, video, and voice applications over a Wi-Fi wireless
connection and is a subset of the IEEE 802.11e QoS standard. WMM supports QoS prioritized media
access through the Enhanced Distributed Channel Access (EDCA) method.
Multiple Basic SSIDs—Support up to 8 basic service set identifiers (SSIDs) in access point mode.
RADIUS Accounting—Enable accounting on the WMIC to send accounting data about wireless
client devices to a RADIUS server on your network.
TACACS+ administrator authentication—Enable TACACS+ for server-based, detailed accounting
information and flexible administrative control over authentication and authorization processes. It
provides secure, centralized validation of administrators attempting to gain access to your WMIC.
Enhanced security—Enable three advanced security features to protect against sophisticated attacks
on your wireless network’s WEP keys: Message Integrity Check (MIC) and WEP key hashing.
Enhanced security for Wi-Fi Protected Access (WPA) with AES and Temporal Key Integrity
Protocol (TKIP) encryption is also available.
Enhanced authentication services—Set up non-root bridges or workgroup bridges to authenticate to
the network like other wireless client devices. After a network username and password for the
non-root bridge or workgroup bridge are set, it authenticates to the network using Cisco Light
Extensible Authentication Protocol (LEAP), and receives and uses dynamic WEP keys.
802.1x supplicant—Support 802.1x, the standardized framework defined by the IEEE to provide
port-based network access using information unique to the client and with credentials known only
to the client. The supplicant refers to the client software that supports the 802.1x and EAP protocols.
The 802.1x supplicant provides a secure method for accomplishing this authentication. Transport
Layer Security (TLS) is an enhancement to SSL and provides data encryption in conjunction with
EAP.
EAP-TLS and EAP-FAST—Support EAP-TLS and EAP-FAST in workgroup bridge and non-root
device mode.
Advanced Encryption Standard (AES) —This feature supports Advanced Encryption
Standard-Counter Mode with Cipher Block Chaining Message Authentication Code Protocol
(AES-CCMP). AES-CCMP is required for Wi-Fi Protected Access 2 (WPA2) and IEEE 802.11i
wireless LAN security.
Enhanced authentication for Cisco Centralized Key Management (CCKM).
Roaming—Support fast, secure roaming of client devices, and radio management through wireless
domain services (WDS) (See the
“WDS, Fast Secure Roaming, and Radio Management”
document
for more information.
Universal workgroup bridge—Support interoperability with non-Cisco devices.
Prioritized Multiple Client Profiles.
Any SSID— May associate to any root device as long the encrption and authentication settings
match.
Management Frame Protection (MFP)—Support management frame protection version 1 and 2.