<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x/PEAP and dynamic WEP-keys  in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215267#M26098</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't actually tried this but I've read about it so you'll have to try it out and let us know if it works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two "encryption" commands that you have above are used to configure static WEP keys. EAP authentication also allows for dynamic WEP key management. To do this, you have to turn on a "key management" function. Cisco offers 2: CCKM and WPA. CCKM is used with Cisco's WDS. WPA is the WiFi implementation that uses TKIP for encryption. Under each the RADIUS server should create the WEP keys dynamically and pass them to the AP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With CCKM, configure "encryption mode ciphers wep128" under the radio interface and "authentication key-management cckm" under the SSID. Other ciphers such as CKIP+CMIC are available. Configure this on top of the auth command you already have. You can remove your 2 encryption commands. The broadcast-key command will take care of rotating your broadcast WEP keys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For WPA &amp;amp; TKIP it's similar. Use "encryption mode ciphers tkip" and "authentication key-management wpa".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Feb 2004 18:55:46 GMT</pubDate>
    <dc:creator>s.vautour</dc:creator>
    <dc:date>2004-02-27T18:55:46Z</dc:date>
    <item>
      <title>dot1x/PEAP and dynamic WEP-keys</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215263#M26094</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a test with an ACS 3.2, 1100 AP and run PEAP for authentication. I have read that it is possible to deliver dynamic WEP-keys from the aaa-server to the client but not sure how and how to verify..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS with PEAP enabled (works fine)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client &lt;/P&gt;&lt;P&gt;- XP with 350-card&lt;/P&gt;&lt;P&gt;- PEAP conf&lt;/P&gt;&lt;P&gt;- Data encr. WEP&lt;/P&gt;&lt;P&gt;- Key is provided for me autom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AP&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; encryption key xxxx size 40bitxxxxxtransmit-key&lt;/P&gt;&lt;P&gt; encryption mode wep mandatory &lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; broadcast-key capability-change&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid testssid&lt;/P&gt;&lt;P&gt;    authentication open eap peap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the question is, perhaps stupid!,,, is the key that´s configured in the AP the only WEP-key and there is no dynamic key-delivery from the ACS. Belive so...:-) How to enable the automatic key/rotating key from the ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need some help on this one, haven's found any good stuff on CCO. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Fred&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215263#M26094</guid>
      <dc:creator>walruspro</dc:creator>
      <dc:date>2021-07-04T16:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/PEAP and dynamic WEP-keys</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215264#M26095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure "Broadcast WEP Key rotation interval " under the radio's advanced properties to enable WEP key rotation LEAP currently. This is not supported for PEAP currently.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2004 15:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215264#M26095</guid>
      <dc:creator>b.speltz</dc:creator>
      <dc:date>2004-02-03T15:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/PEAP and dynamic WEP-keys</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215265#M26096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I understand it, there are two types of key rotation, bradcast and unicast.  Broadcast key rotation rotates ONLY the keys that are manually entered into the AP to protect the AP's broadcast traffic.  Unicast keys (as in TKIP's per packet keying) are unique to each client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sorry I can't remember the command to actually see verification of unicast key rotation but one of the debug commands will log a message when the keys are changed.  Look through some of the debug choices on the AP at the CLI.  Hope some of this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Feb 2004 03:23:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215265#M26096</guid>
      <dc:creator>sdesforges</dc:creator>
      <dc:date>2004-02-04T03:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/PEAP and dynamic WEP-keys</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215266#M26097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using PEAP as EAP method authentication on WLAN are you sure that Dynamic WEP Key is not currently supported???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using a 3rd party EAP supplicant configured for PEAP with automatic WEP key. On my AP I've not defined a WEP Key but my client is still be able to be authenticated and associated...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2004 10:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215266#M26097</guid>
      <dc:creator>oguarisco</dc:creator>
      <dc:date>2004-02-09T10:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/PEAP and dynamic WEP-keys</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215267#M26098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't actually tried this but I've read about it so you'll have to try it out and let us know if it works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two "encryption" commands that you have above are used to configure static WEP keys. EAP authentication also allows for dynamic WEP key management. To do this, you have to turn on a "key management" function. Cisco offers 2: CCKM and WPA. CCKM is used with Cisco's WDS. WPA is the WiFi implementation that uses TKIP for encryption. Under each the RADIUS server should create the WEP keys dynamically and pass them to the AP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With CCKM, configure "encryption mode ciphers wep128" under the radio interface and "authentication key-management cckm" under the SSID. Other ciphers such as CKIP+CMIC are available. Configure this on top of the auth command you already have. You can remove your 2 encryption commands. The broadcast-key command will take care of rotating your broadcast WEP keys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For WPA &amp;amp; TKIP it's similar. Use "encryption mode ciphers tkip" and "authentication key-management wpa".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Feb 2004 18:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-peap-and-dynamic-wep-keys/m-p/215267#M26098</guid>
      <dc:creator>s.vautour</dc:creator>
      <dc:date>2004-02-27T18:55:46Z</dc:date>
    </item>
  </channel>
</rss>

