<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WPA Key Rotation Question in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wpa-key-rotation-question/m-p/2301991#M143570</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All dot1x clients have a unique key but share a seperate broadcast key that is derived through the dot1x process. To rotate that key use this command ( broadcast-key vlan # change #) on the radio interface. . but the WPA cypher key which keeps on changing after some interval is to encrypt the data with different differnt keys so that it wil be difficult to be cracked/decrypt and not for reauthentication of clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/routers/access/1800/1801/software/configuration/guide/wireless.pdf"&gt;http://www.cisco.com/en/US/docs/routers/access/1800/1801/software/configuration/guide/wireless.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Oct 2013 19:01:02 GMT</pubDate>
    <dc:creator>Abha Jha</dc:creator>
    <dc:date>2013-10-01T19:01:02Z</dc:date>
    <item>
      <title>WPA Key Rotation Question</title>
      <link>https://community.cisco.com/t5/wireless/wpa-key-rotation-question/m-p/2301990#M143569</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In an AP, the broadcast-key change &amp;lt;value&amp;gt; command tells the AP how often to rotate the WPA key.&amp;nbsp; &lt;STRONG&gt;My question: How do clients remain connected to the Wireless LAN when the key rotates?&amp;nbsp; If the client authenticates (via Radius in my example below), then I would think the key challenge would need to be met. However, if in 5 minutes the key rotates, for example, isn't the client going to lose connection since the challenge value is now different?&lt;/STRONG&gt;&amp;nbsp; The only thing I can think of is that Radius handles this dynamically once a client is authenticated, thus avoiding any disruption.&amp;nbsp; Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config, if interested:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa new-model&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa group server radius employee-clients&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; server 10.255.255.250 auth-port 1645 acct-port 1646&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa authentication login console local&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa authentication login net-admin local&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa authentication login eap_methods group employee-clients&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa authorization exec default local &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa session-id common&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;dot11 ssid WLAN-Local&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; vlan 20&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; authentication open eap eap_methods &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; authentication network-eap eap_methods &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; authentication key-management wpa&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Dot11Radio0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; no ip address&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; no ip route-cache&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; encryption vlan 20 mode ciphers aes-ccm &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; broadcast-key vlan 1 change 300&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;radius-server host 10.255.255.250 auth-port 1645 acct-port 1646 key &amp;lt;key&amp;gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-key-rotation-question/m-p/2301990#M143569</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2021-07-04T07:59:05Z</dc:date>
    </item>
    <item>
      <title>WPA Key Rotation Question</title>
      <link>https://community.cisco.com/t5/wireless/wpa-key-rotation-question/m-p/2301991#M143570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All dot1x clients have a unique key but share a seperate broadcast key that is derived through the dot1x process. To rotate that key use this command ( broadcast-key vlan # change #) on the radio interface. . but the WPA cypher key which keeps on changing after some interval is to encrypt the data with different differnt keys so that it wil be difficult to be cracked/decrypt and not for reauthentication of clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/routers/access/1800/1801/software/configuration/guide/wireless.pdf"&gt;http://www.cisco.com/en/US/docs/routers/access/1800/1801/software/configuration/guide/wireless.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 19:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa-key-rotation-question/m-p/2301991#M143570</guid>
      <dc:creator>Abha Jha</dc:creator>
      <dc:date>2013-10-01T19:01:02Z</dc:date>
    </item>
  </channel>
</rss>

