10-30-2002 03:10 PM - edited 07-04-2021 11:29 PM
I am configuring a number of Cisco AP 350s for Cisco LEAP. If "Rotate Broadcast Key" is enabled, is it necessary to enter a static WEP key to be used to encrypt broadcast/multicast packets? If Cisco LEAP only is required (Network EAP is enabled as an authentication method), is it recommended to disable "open" authetication. With a static WEP key and "open" authentication enabled, it did occur to me that a user could connect to the AP using the static WEP key as opposed to Cisco LEAP.
10-31-2002 04:21 PM
You can leave open auth enabled, but you should then check "require EAP" on the radio hardware advanced setup page.
You would do this (and some other things) to allow non-Leap capable clients to authenticate to the ACS via MAC-address, and then use static WEP, which is better than nothing.
11-01-2002 09:21 AM
If only Cisco LEAP is required, disable/uncheck the open authentication. Here is the step-by-step config guide for LEAP
http://www.cisco.com/warp/public/cc/pd/witc/ao1200ap/prodlit/wrsec_an.htm
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide