1310 wireless outdoor bridge - strong Encryption configuration - high priority

Hi All,
Below  is bridge configration .  I would like to know with this below   configuration data traffic will get compelete encrytion ?? any better  encryption configuration  ?? as I read wpa will not provide complete  encryption. please help
network topology
R1--------------SW1<----------------->  root bride-1 <---------------------------> Non-root bridge-1  <------------------------ >SW2( remote office)--------LAN  hosts                   
SW1- Gi0/0- 10.200.32.1/29             BVI- 32.2/29                               BVI -  32.3/29                                   SW2-GI0/0 - 32.4/29
network setup :  SW1 - LAN port to root bridge connection --  Gi 0/0 - ip address configured -10.200.32.1/29
                         Root-brdge -------------------------------------------- BVI  10.200.32.2/29 -----
                         Non root bridge----------------------------------------BVI 10.200.32.3/29
                         SW2 LAN port-Non root bridge ----------------- Gi0/0  10.200.32.4/29
both bridge have only BVI configured and no VLAN or subniterface on the both bridge .
SW1 and SW2 port connected to bridges are not part of vlan  , ports configured with specfic IP address
dot11 ssid
   authentication open
   authentication key-management wpa
   wpa-psk ascii 7 123456
bridge irb
interface Dot11Radio0
no ip address
no ip route-cache
encryption mode ciphers aes-ccm
station-role root bridge
bridge-group 1
bridge-group 1 spanning-disabled
interface FastEthernet0
no ip address
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
hold-queue 80 in
interface BVI1
ip address 10.200.32.2 255.255.255.248
no ip route-cache
ip default-gateway 10.200.32.1
ip http server
no ip http secure-server
control-plane
bridge 1 route ip
************************************Configuration  on non root  bridge.******************************************************************
dot11 ssid
   authentication open
   authentication key-management wpa
   wpa-psk ascii 7 123456
bridge irb
interface Dot11Radio0
no ip address
no ip route-cache
encryption mode ciphers aes-ccm
bridge-group 1
bridge-group 1 spanning-disabled
interface FastEthernet0
no ip address
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
hold-queue 80 in
interface BVI1
ip address 10.200.32.3 255.255.255.248
no ip route-cache
ip default-gateway 10.200.32.2
ip http server
no ip http secure-server
control-plane
bridge 1 route ip

Hi there ..
I want to make sure I understand. You are concerned about the encryption of the wireless tranmission over the bridge correct ? I see based on your config you are using WPA/AES. This isnt standard based, if you wanted to be more stnadards based you should use WPA/TKIP or WPA/AES. Both are very secure. I would lease with WPA/AES. Again this is only for the encryption.
If you want stronger authentcation you might consider 802.1X.
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin

Similar Messages

  • Wireless Outdoor Bridge Distance

    I have a customer that wants to use a 1532I bridge to connect two buildings.  The buildings are about 700 feet apart with a clear LoS between the two points.  Would the 1532I reach this distance?

    The 1532 is rated at 32 dBm - spec sheet
    http://www.cisco.com/en/US/prod/collateral/wireless/ps5679/ps12831/data_sheet_c78-728356.html
    if you get the E series you can better shape the RF perhaps.
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

  • Need Assistence Configuring 2 Aironet 1310s as a Bridge

    I'm just starting to setup 2 1310s as a bridge for the first time. I've setup some basic settings through the web interface: IP settings on the BVIs, single SSID, and no security (yet). Also, I've set one as a root-bridge and the other as a non-root bridge. Things seem to look good so far on the root bridge, but when I try to enable the the dot11 interface on the non-root bridge, I keep getting the following message in the log:
    %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    %DOT11-4-CANT_ASSOC: Interface Dot11Radio0, cannot associate: No Response
    I guess the first obvious question is: should I be able to establish a wireless signal without the external antennas? I don't have the external antennas yet, but my understanding is that I can establish a wireless signal without them as long as the 2 1310s are fairly close together; right now they are in my lab only a couple feet apart.
    If my assumption is correct, what am I missing here?
    Thanks,
    Sean

    Thanks for the response, I do have the internal antennas enabled. Unfortunately, I don't have rubber duck antennas to work with, but it sounds like the internal antennas should work for testing. I also have the TNC connectors facing each other. I'm still getting the same error. Here, let me include the configurations, maybe someone will notice my mistake:
    The root bridge:
    version 12.4
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname mosj141wbr31
    enable secret xxx
    no aaa new-model
    resource policy
    ip subnet-zero
    dot11 ssid mosj141lab
    authentication open
    infrastructure-ssid optional
    username Cisco password xxx
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    ssid mosj141lab
    speed basic-1.0 basic-2.0 basic-5.5 basic-11.0 basic-6.0 basic-9.0 basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0
    station-role root bridge
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface BVI1
    ip address 10.16.1.53 255.255.255.224
    no ip route-cache
    ip http server
    no ip http secure-server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    bridge 1 route ip
    line con 0
    line vty 0 4
    login local
    end
    The non-root bridge:
    version 12.4
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname mosj141wbrlab1
    enable secret xxx
    no aaa new-model
    resource policy
    ip subnet-zero
    dot11 ssid mosj141lab
    authentication open
    infrastructure-ssid optional
    username Cisco password xxx
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    ssid mosj141lab
    speed basic-1.0 basic-2.0 basic-5.5 basic-11.0 basic-6.0 basic-9.0 basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0
    station-role non-root bridge
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface BVI1
    ip address 10.16.1.55 255.255.255.224
    no ip route-cache
    ip default-gateway 10.16.1.33
    ip http server
    no ip http secure-server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    bridge 1 route ip
    line con 0
    line vty 0 4
    login local
    end
    Thanks again for your responses.

  • "Restart Now" IOS command for 1310 Wireless Bridge

    I have 2 Cisco Aironet 1310 wireless bridges setup, line-of-sight, 3/4 mile apart, one as Root, the other as Non-Root.  Occasionally they drop their connection but a hard restart of either or both bridges will reestablish the connection.  What is the equivalent IOS command to the
    "GUI > System Software > System Configuration > Restart Now" command?  I would like to be able to telnet to either/both units and issue/script the appropriate command.

    the command is "reload"
    BRIDGE# reload
    Regards
    Surendra

  • 1310 Wireless Bridge problems

    I have a 1310 wireless bridge....when I power it up, it sometimes does not boot up. The I LED will just sit there and blink and the R and E LEDs will blink in unison with it. After a while just the I LED blinks. I cannot find any literature that tells me if this is an error code or not.
    Also, when the thing does boot up, it tells me that the Radio interface is down and disabled, when in fact if you go into the settings of the radio interface, it is selected to be enabled.
    What might be going on here?
    Thank you.

    No, there is nothing on the console port when the thing is in the condition described above.
    If I do get a successful boot, I can then access via a console port. I may try to reinstall firmware and see if that fixes the problem.
    So you are saying the radio link will show as disabled/down until it actually tries to associate/authenticate with another bridge unit? That is normal?

  • WRT160N wireless routher, wireless signal not strong within apartment

    I have had the wrt54g for a while now and just recently it stopped working and I had no choice but to get the wrt160n and with lots of difficulty was able to get that going. The wireless signal, on a wpa2personal is fine when I am close to the box which is in the basement of our apartment but upstairs the signal is never as strong as the older linksys wireless router was.
    I am really at a loss and the customer service was absolutely no help.  I have tried several devices and same result on all of them, max maybe 4 bars for a few min, moslty 1-2 bars.
    What is the issue? What other info do you need? any suggestions?
    I am a day from returning the box and moving onto another brand or buying the old school one again if I can find it.
    Please let me know anyone, you are my only hope!
    Mo 

    Try to readjust the wireless settings on your Router...
    Open an Internet Explorer browser page on your wired computer(desktop).In the address bar type - 192.168.1.1 and press Enter...Leave Username blank & in Password use admin in lower case...
    For Wireless Settings, please do the following : -
    Click on the Wireless tab
    - Here select manual configuration...Wireless Network mode should be mixed...
    - Provide a unique name in the Wireless Network Name (SSID) box in order to differentiate your network from your neighbours network...
    - Set the Radio Band to Standard-20MHz and change the Standard channel to 11-2.462GHz...Wireless SSID broadcast should be Enabled and then click on Save Settings...
    Please make a note of Wireless Network Name (SSID) as this is the Network Identifier...
    For Wireless Security : -
    Click on the Sub tab under Wireless > Wireless Security...
    Change the Wireless security mode to WEP, Encryption should be 64 bit.Leave the passphrase blank, don't type in anything...Under WEP Key 1 type in any 10 numbers please(numbers only and no letters eg: your 10 digit phone number) and click on save settings...Please make a note of WEP Key 1 as this is the Security Key for the Wireless Network...
    Click on Advanced Wireless Settings
    Change the Beacon Interval to 75 >>Change the Fragmentation Threshold to 2304, Change the RTS Threshold to 2304 >>Click on "Save Settings"...
    Now see if you can locate your Wireless Network and attempt to connect...

  • Can some one translate these instructions D-Link DI-524: installation as wireless HUB/Bridge   General  ON ALL TYPES OF ROUTERS DHCP SERVER HAS TO BE DISABLED ON ALL TYPES OF ROUTERS UPnP ALSO HAS TO BE DISABLED OTHERWISE YOU CAN SEVERELY HINDER OTHER USE

    D-Link DI-524: installation as wireless HUB/Bridge
    General
    ON ALL TYPES OF ROUTERS DHCP SERVER HAS TO BE DISABLED
    ON ALL TYPES OF ROUTERS UPnP ALSO HAS TO BE DISABLED
    OTHERWISE YOU CAN SEVERELY HINDER OTHER USERS IN YOUR NEIGHBOURHOOD!
    Practical example: D-Link DI-524
    The DI-524 is a wireless router.Although the manufacturer doesn't mention this, you can also install this device as a wireless hub.Of course this is not supported by the manufacturer. Therefor you have nowhere to go in case of any problems Plug in the power cord of the DI-524. Do not yet connect the network cable!Search for existing wireless networks with your computer. Connect with the router.This can for example be done like this:
    Click the start-button (at the bottom in the left corner of your screen).
    Go to control panel
    Go to internet connections (you may have to choose classic representation first)
    You can now see your wireless network card, among other things. Right-click and 'View available Wireless networks'.
    Connect to the router. In most cases the router will be called 'default'.Check your IP-address: you get an IP address from the DI-524
    Go to the start-button
    Go to 'Run'
    Type 'cmd' and press enter
    type 'ipconfig' and press enter
    your IP address starts with 192.
    Surf to your router with your regular browser. For this you need the address and a password, which you can find in the documentation.
    In this case the address is 192.168.0.1
    Now you must secure the router. For this it is best to use WPA-PSK
    Your key is a randomly chosen sentence. Don't make this sentence too short.
    Warning: Case sensitive!
    You cannot reach the router anymore now.
    Go back to your network card via "make connection". Search for your wireless network again and make a new connection
    You are asked for a key. Supply this key the way you configured it in your router.
    Surf back to the router.
    Disable the DHCP server.
    !! YOU HAVE TO DISABLE UPnP ON ALL TYPES OF ROUTERS
    OTHERWISE YOU CAN SEVERELY HINDER OTHER USERS IN YOUR NEIGHBOURHOOD!
    for this, go to Tools, Misc and switch off UPnP
    Save these settings.
    If you do not have a D-link router, look up in the manual or somewhere else where you can disable UPnP
    Now you cannot reach the router anymore again.
    It is only from this moment that you can connect the router to the modem.
    Important: Use one of the 4 LAN ports. Never use the WAN port!
    Go to your network card via the control panel. Right-click and "Repair"
    Now you should get an IP-address in the range of 10.nnn.nnn.nnn
    If you still don't have 192... you've made an error. The DI-524 still functions as a router and this is not allowed!

    There are no Mac based instructions. The router is accessed and adjusted the same way whether you are using a Mac OS X, Windows or Linux. As noted in the other post it is done through your web browser which works the same from any computer. Even a Chrome Book.
    akertrav wrote:
    Thank you for that what I have been trying to do is extend the range of my wifi witha second dilink router. I was hoping for some mac based directions to achive this rather than the PC based as presented. Thank you for your ireply Paul

  • About Aironet 1300 Outdoor Bridge.

    Hi,
    I have a question about Aironet 1300 series Outdoor Bridge.
    in case of 1300 series, it is supporting with 802.11g protocol. BTW, I wanna use it with 802.11a protocol on Aironet 1310 series. Is it possible ?
    If so, how to do I have to it ?
    I wait your good answer.
    Thanks.
    Best Regards.

    1310 only support 11b/g, not support 11a.
    1410 support 11a

  • Is there an up to date version of the Outdoor Bridge Range Calculation Utility?

    I have found this: Outdoor Bridge Range Calculation Utility
    but it dates back to 2007. Brilliant tool but is there an up to date version with the details of current kit?
    Cheers,
    Andy

    The spreadsheet seems to only rate up to 54mbps. I would have thought we could get more than that by now...
    I have a requirement to replace a laser point to point with a wireless bridge, (dont know why the powers that be have decided laser isnt appropriate anymore). I would need at least a gb, preferably more. The link is only 150m.
    Surely with the right kit there is a way to achieve the data rate needed at that distance without laser?
    Cheers,
    Andy

  • Change to User Mapping Strong encryption to weak encryption

    HI Floks,
    we have EP 5.0 and want to change the Branding Images on the Logon Page.
    However, Direct Editing is not available.But User Mapping is availble
    The path in EP 5.0 was :
    "System Administration -> System Configuration -> UME Configuration -> User Mapping".
    its strongly encrypted
    am looking this info "Encryption of User Mapping Data: Strong encryption ". Ihave to change brading image
    Does anyone know why or if there is another way to modify the UME property ume.logon.branding_image. how to convert this encryption or another way is there to change logo .\
    if any links or suggestions are provide me
    thanks
    Preethi

    Hi Preethi,
    I'm wondering about your message. It seems you mismatch EP5 and EP6 with each other.
    In EP5 the logon screen can be found at the IIS. There are 2 different logon screens: form logon or HTTP logon. The branding image is only available for form logon. In the admin guide for EP5 you can find the following information:
    'You can customize the form-based logon to reflect your companyu2019s branding or other special
    requirements. The dialog is located at Inetpub\wwwroot\SAPPortal\FormLogon.asp.'
    see also
    http://help.sap.com/saphelp_ep50sp6/helpdata/en/a2/297c55fa2f5447973d25825c1a665b/frameset.htm
    Furthermore there was no strong encryption possible for EP5.
    The path you mentioned in your message reflects only for EP6 and onwards. And I'm wondering why you talk of strong encryption in this context. The way of encryption has nothing to do with the branding image.
    Regards,
    Anja

  • Suggestions on a wireless client bridge unit running MIMO 5ghz

    I have replaced my main router WRT300N running dd-wrt with the a stock E4200 and an old WRT54G aslo running dd-wrt configured for wireless client bridge. Now that I'm learning more about 802.11N, I was wondering what client can I use to achieve 5ghz simultaneously radio transmission since my current setup cannot do this in the 5ghz band. Can the E3000 be ran in wireless client bridge mode, if not what product can provide this? On the other thought am I understanding MIMO?
    Old setup: 802.11G 2.4ghz
    WRT54G ))) ((( WRT300N ->ISP
    Current Setup: 802.11N 2.4ghz MIMO?
    WRT300N ))) ((( E4200 ->ISP
    Wanted Setup: 802.11N 5ghz MIMO
    ??????? ))) ((( E4200 ->ISP
    Thanks,

    There are various router models available which works on 5GHz frequency (E300, E3200 etc.). However, its not sure whether the third party firmware (dd-wrt) would be compatible with it or not?
    Secondly, warranty of your product becomes void if  you update any third party firmware on your product. Anything goes wrong with the product, it is not eligible for the replacement.

  • Labview 2011 always disconnecting over wireless Ethernet bridge!

    Hello, we recently upgraded from labview 2009 to labview 2011. We use a Labview cRio-9014 and FPGA backplane 9114. For connecting the cRio to our laptop we use Digi XPress Ethernet Bridge: Multipoint 900MHz industrial wireless part# XEB09. This program worked over our wireless link running labview 2009 with the old cRio software.
    After upgrading the desktop, upgrading the cRio's software and recompiling the FPGA code we tested our setup via a wired ethernet connection and ran it all day with no problems. However once we switched to using our wireless ethernet bridges the cRio disconnects always 2-3 minutes after starting. It also does not allow us to reconnect without powercycling the cRio. The radio modems show a solid connect and no problems the whole time. Now I've searched through known issues and all over the forums without finding anyone having a similar issue so I hope someone can chime in and let me know if something else in LV2011 changed or what.
    My current hypothesis is that labview 2011 uses UDP packets for status/keep-alive and our radio modems are not guaranteed to recieve all UDP packets. Please correct me since this is only a guess and I don't know what's going on under the hood on the cRio side.
    P.S. I've captured the packet data using WireShark on the laptops side from deployment until disconnection but can't find any obvious problems. It's a fairly large file so let me know if it's needed and I'll try to find a way to upload it.
    Hopefully someone can help.
    Best Regards,
    Sam Bingham
    Great Lakes WATER Institute

    Our host OS is WIn7-64Bit, and XP-32bit but they all display the same behavior.
    cRIO hardware: cRio-9014 and FPGA backplane 9114
    Our system is has 4 modules installed NI-9205, NI-9401, NI-9401, NI-9870, although we are only using the serial ports on NI-9870.
    I looked for the NI TimeSync to remove but it isn't listed in our installation
    Contents of current installation:
    CompactRIO Support 4.0.0
    DataSocket for LabVIEW Real-Time 4.9.0
    HTTP Client 1.2.0
    HTTP Client with SSL Support 1.2.0
    I/O Variable Remote Configuration Web Service 1.0
    LabVIEW 2011 Adaptive Filter Toolkit 11.0.0
    LabVIEW PID and Fuzzy Logic Toolkit 11.0.0
    LabVIEW Real-Time 11.0
    Language Support for LabVIEW RT 1.0.0.4
    NI Application Web Server 2.0
    NI System Configuration 5.0.0
    NI System Configuration Network Support 5.0.0
    NI Web-based Configuration and Monitoring 2.0.0
    NI-RIO 4.0.0
    NI-Serial RT 3.8.0
    NI-VISA 5.1
    NI-VISA ENET Passport 5.1
    NI-VISA ENET-ASRL Passport 5.1
    NI-VISA Remote Passport 5.1
    NI-VISA Server 5.1
    NI-VISA USB Passport 5.1
    Network Streams 1.1
    Network Variable Engine 1.8.0
    Remote Panel Server for LabVIEW RT 4.0.0
    Run-Time Engine for Web Services 4.0.0
    SSL Support for LabVIEW RT 4.0.0
    System State Publisher 2.0.0
    Variable Client Support for LabVIEW RT 1.8.0

  • Transparent Data Encryption Configuration

    Hi,
    I want to configure Transparent Data Encryption on a Database which is protected with Database Vault.
    Is there any document which talks about the integration of Database Vault with Transparent Data Encryption.
    I want to create a common security administrator user (other than sys/system users) for Transparent Data Encryption configuration.
    If i create a new administrator from Enterprise Manager console i am getting the following error:
    SQL Error ORA-47401: Realm violation for grant system privilege on SELECT ANY DICTIONARY. ORA-06512: at "SYSMAN.MGMT_USER", line 9316 ORA-06512
    How to avoid this error.
    Any pointers on this is appreciated.
    Thanks & regards,
    Srikanth

    Turning off DBVault is not needed to turn on TDE ... the DB user who wants to manage the DB through Enterprise Manager, needs to have the SELECT ANY DICTIONARY privilege (I think I remember this is done by logging into EM (not DVA) as DBV_OWNER, or DV_ACCT_MNGR if you have configured one).
    If then the creation of the wallet fails, make the user an OWNER of the DATA DICTIONARY realm in DBVault. Note that the directory that you plan to use to store the wallet needs to exist before you create the wallet and master key for TDE.
    Peter
    Edited by: Peter Wahl on 03.07.2010 02:20

  • Error: Your browser is unable to perform strong encryption.

    I received the following message while trying to log onto my credit union:
    Your browser is unable to perform strong encryption. For your protection, we require 128 bit encryption in order to secure your banking session.
    Please upgrade your browser to Internet Explorer 5.5+ or Netscape Navigator 4.73+
    Anyone have any suggestions?

    Hi,
    Try enabling the 'Develop menu' via Safari preferences > Advanced. Once the menu is available, try selecting a different User Agent setting such as Internet Explorer.
    It sounds like your credit union is doing some kind of basic browser checking and their checks don't recognise Safari. If that change does work make sure you notify them of the problem and hopefully they'll add Safari as a recognised browser.

  • Configure higher resolution on youtube app

    Hi,
    I wonder whether we can configure higher resolution for video on youtube app on apple tv.
    I upload an 1920x1080 video and when I play on apple TV, the resolution is very bad, it isn't 1920x1080.
    Thanks,
    Khuong

    You mean resolutions over 480*320 (the current resolution over Wi-Fi)? Do you plan to play back them on an external TV / monitor? Otherwise, it's pretty useless to try to watch them on a 480*320 screen.
    Nevertheless, on WinMo, CorePlayer is able to stream even HD content from YouTube. I can only hope Apple finally lets CorePlayer into the AppStore.

Maybe you are looking for

  • What are the Master Table validations required for below fields

    Hi, I have created a selection screen with following fields. Can anybody tell me what are the exact master table vaidation i can do for the same! <b>Order Type[VBAK-AUART], Order Number[VBAK-VBELN], Customer PO #[VBKD-BSTKD], Sold-to Party No[VBPA-PA

  • Audio and AppleTV

    Can't get any sound out of my audio system using apple tv! No sound through the surround sound system.

  • B2B using Oracle BPEL

    Hello, What are the different options of publishing a BPEL process on internet ? what will be suitable approach for B2B using the Oracle BPEL PM. Please provide pointers to pros n cons of different architectures. We want to integrate a partners with

  • Send mail without abap

    Hello, I want create a job that execute all days 1 of months. The job has to send a mail. The mail is always the same and to the same users. Can I have this without abap program? Can the job trigger the mail directly? Thanks.

  • Bizarre finder alphabetization behavior

    Aside from possibly butchering a made-up word, I am having a bit of an issue. I am finding that screenshots taken in the AM are showing up /after/ screenshots taken in the PM. I thought I had correctly determined and solved this issue with the help o