6-8
Cisco Wireless ISR and HWIC Access Point Configuration Guide
OL-6415-04
Chapter 6 Configuring Authentication Types
Understand Authentication Types
Software and Firmware Requirements for WPA and WPA-TKIP
Table 6-1 lists the firmware and software requirements required on access points and Cisco client
devices to support WPA key management and WPA-TKIP encryption protocols.
To support the security combinations in Table 6-1, your access points and client devices must run the
following software and firmware versions:
• Cisco IOS Release 12.4(2)T or later on access points
• Install Wizard version 1.2 for 340, 350, and CB20A client devices, which includes these
components:
–
PC, LM, and PCI card driver version 8.4
–
Mini PCI and PC-cardbus card driver version 3.7
–
Aironet Client Utility (ACU) version 6.2
–
Client firmware version 5.30.13
Note When you configure AES-CCM and TKIP-only cipher encryption (not TKIP + WEP 128 or TKIP +
WEP 40) on any radio interface or VLAN, every SSID on that radio or VLAN must be set to use WPA
key management. If you configure TKIP on a radio or VLAN but you do not configure key management
on the SSIDs, client authentication fails on the SSIDs.
Ta b l e 6-1 Software and Firmware Requirements for WPA and WPA-TKIP
Key Management and Encryption
Protocol
Third Party Host Supplicant
1
Required?
1. Such as Funk Odyssey Client supplicant version 2.2 or Meetinghouse Data Communications Aegis Client version 2.1.
Supported Platform Operating
Systems
LEAP with WPA-TKIP No Windows XP and 2000
LEAP with WPA No Windows XP and 2000
Host-based EAP (such as PEAP,
EAP-SIM, and EAP-TLS) with
WPA
No
2
2. Windows XP does not require a third-party supplicant, but you must install Windows XP Service Pack 1 and Microsoft support
patch 815485.
Windows XP
Host-based EAP (such as PEAP,
EAP-SIM, and EAP-TLS) with
WPA
Yes Windows 2000
WPA-PSK Mode No
2
Windows XP
WPA-PSK Mode Yes Windows 2000