The AP certificate file, certificate of the AP certificate issuer, and ASU certificate file
are imported.
4. Run:
wapi import private-key file-name file_name
The AP private key file is imported.
5. Run:
wapi asu ip ip-address
The ASU server's IP address is configured.
6. (Optional) Run the following commands to modify WAPI parameters:
– Run:
wapi { bk-threshold bk-threshold | bk-update-interval bk-interval }
The interval for updating a BK and the BK lifetime percentage are set.
By default, the interval for updating a BK is 43200s, and the BK lifetime percentage
is 70%.
– Run:
wapi { msk-update-interval msk-interval | msk-update-packet msk-packet
| msk-retrans-count msk-count }
The interval for updating an MSK, number of packets that will trigger MSK update,
and number of retransmissions of MSK negotiation packets are set.
By default, the interval for updating an MSK is 86400s; the number of packets that
will trigger MSK update is 10000; the number of retransmissions of MSK
negotiation packets is 3.
– Run:
wapi cert-retrans-count cert-count
The number of retransmissions of certificate authentication packets is set.
By default, the number of retransmissions is 3.
– Run:
wapi { usk | msk } key-update { disable | time-based | packet-based |
timepacket-based }
The unicast session key (USK) or MSK update mode is set.
By default, USKs and MSKs are updated on the basis of time.
----End
Checking the Configuration
Run the display security-profile { all | { id profile-id | name profile-name } [ detail ] } command
to view information about security profiles.
Check detailed information about a single security profile.
<Huawei> display security-profile id 0 detail
------------------------------------------------------------
Profile name : lw
Profile ID : 0
Authentication : Share key
Encryption : WEP-40
------------------------------------------------------------
Service-set ID SSID
0 l00129796_9300
1 l00129796_93002
------------------------------------------------------------
WEP's configuration
Authentication : Share key
Huawei AR1200 Series Enterprise Routers
Configuration Guide - WLAN 2 WLAN Security Configuration
Issue 03 (2012-01-06) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
30