Need CLI commands for WPA2 Personal Mode

I've seen this example, but I need the CLI the gui generates. Can anyone help out please?
https://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008054339e.shtml#pers
This is what I need to accomplish w/o the gui interface on an 1142N running 12.4
Configure in Personal Mode
The term personal mode refers to products that are       tested to be interoperable in the PSK-only mode of operation for       authentication. This mode requires manual configuration of a PSK on the AP and       clients. PSK authenticates users via a password, or identification code, on       both the client station and the AP. No authentication server is necessary. A       client can gain access to the network only if the client password matches the       AP password. The password also provides the keying material that TKIP or AES       uses to generate an encryption key for the encryption of the data packets.       Personal mode is targeted to SOHO environments and is not considered secure for       enterprise environments. This section provides the configuration that you need       to implement WPA 2 in the personal mode of operation.

/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Table Normal";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:"";
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin-top:0in;
mso-para-margin-right:0in;
mso-para-margin-bottom:10.0pt;
mso-para-margin-left:0in;
line-height:115%;
mso-pagination:widow-orphan;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-ascii-font-family:Calibri;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:"Times New Roman";
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Calibri;
mso-hansi-theme-font:minor-latin;}
Hi,
Below are the CLI commands for WPA2 personal mode
Configure terminal
interface dot11Radio 0
encryption mode ciphers aes-ccm
  or
  encryption vlan mode ciphers aes-ccm < --- If you have multiple vlans
exit
dot11 ssid
    authentication open
    authentication key-management wpa version 2
    wpa-psk ascii
Regards,
Madhuri

Similar Messages

  • Xbox live not working in WPA/WPA2 personal mode.

    Xbox Live is not working in WPA/WPA2 personal mode. It does, however, work in WEP mode. I have 2 windows laptops on my wireless network. when I am on WEP, the laptop is stuck in a perpetual "Acquiring Network Address" state. When I have WPA/WPA2 enabled, my laptops work fine, but xbox live cuts in and out of detecting my network, and I cant even get close to connecting at all.
    So until I figure this out, I have to choose between WEP (xbox live working, and not PCs) WPA(PCs working, not xbox live) or unsecured (risky). what should I do?

    Thats strange topcat, i have exactly the same problem as you except that when i am in WEP encryption my xbox cant even see the extreme on the network and i cant even get it it to connect at all. In WPA mode the xbox sees the network but will not connect. I have rang xbox and they say that it should work and that the problem lies with Apple, although i dont believe this personally. In the meantime ive had to hardwire the xbox to the router which isnt why i bought the router. Disappointed
    Regards
    Stu

  • 1142 Autonomous Cli commands for 40MhZ bonding DFS

    Does anyone know of a command that I can issue from the CLI that will inform me of the two channels that the AP is using to bond for the 40MhZ width when I select DFS.  I know I can choose either above or below.  Does it just use the next channel ?  So if DFS selects 36 does it just automatically the next channel up if I have 40Mhz Above selected?
    I have autonomous 1142's and I would like to know what the 2nd Channel.  Keep in mind these are Autonomous AP's.
    Also would like to know a CLI command to find out what the channel currently is for either radio if DFS is selected?
    Any docs on CLI commands for the 1142 would be appreciated.
    Thank you!

    Yes, if you configure 40MHz above it will just use the next channel.  Same with 40MHz below, it will just use the next channel down.
    To see which channel the AP is currently using you can look under "show controller d1"

  • CLI commands for remote network

    I have a 800 router connected to our HQ via site-to-site vpn.
    I have commands i wish to run from the CLI but cannot get them to work.
    Pings fails from the CLI if using 'ping x.x.x.x' but are successful if using 'ping x.x.x.x source x.x.x.x'
    I am guessing all local CLI commands are trying to direct via the WAN as default, how can I resolve this for commands i wish to direct via the VPN.
    The command I really want to run is 'logging host x.x.x.x', with the syslog host being in HQ via the vpn tunnel

    IOS is always choosing interface which is closest to destination (i.e. consults routing table), when sourcing traffic from the box. 
    There are several commands (usually one-two per feature to override this behavior). 
    For the command you're looking for.
    Spoke1(config)#logging source-interface ?
    Async Async interface
    Auto-Template Auto-Template interface
    BVI Bridge-Group Virtual Interface
    CDMA-Ix CDMA Ix interface
    CTunnel CTunnel interface
    Dialer Dialer interface
    Ethernet IEEE 802.3
    GMPLS MPLS interface
    LISP Locator/ID Separation Protocol Virtual Interface
    LongReachEthernet Long-Reach Ethernet interface
    Loopback Loopback interface
    MFR Multilink Frame Relay bundle interface
    Multilink Multilink-group interface
    Null Null interface
    Serial Serial
    Tunnel Tunnel interface
    Vif PGM Multicast Host interface
    Virtual-PPP Virtual PPP interface
    Virtual-Template Virtual Template interface
    Virtual-TokenRing Virtual TokenRing
    vmi Virtual Multipoint Interface

  • Need FNDLOAD command for request group

    I need FNDLOAD command to download seed data of a Request Group with a particular concurrent program. I do not want to download the whole request group will all associated concurrent programs with it. can some one help?

    sounds to me like you want to download just a specific Concurrent Program...use the following command...
    FNDLOAD apps/<APPS_PWD> O Y DOWNLOAD $FND_TOP/patch/115/import/afcpprog.lct <File_name>.ldt PROGRAM APPLICATION_SHORT_NAME=<APPL_SHORT_NAME> CONCURRENT_PROGRAM_NAME=<SHORT_NAME>
    FNDLOAD apps/<APPS_PWD> O Y UPLOAD $FND_TOP/patch/115/import/afcpprog.lct <File_name>.ldt

  • HOWTO: Example CLI commands for CS4 ARD install from a network volume

    So, I have been meaning to post up now I've done a couple of successful installs using this command set.
    After following the instructions to build a Manual Enterprise Deployment, Adobe recommends that you copy your completed package to the machine and execute it from there. But I found it much easier to just create a network volume that could be accessed by an authorized installer user and mount that and run the install from there instead.
    For this example I've assumed:
    A server called "server.local"
    An install user called "adobeinstaller" with passwd "installerpasswd"
    A network share that only the above user can access called "cs4stdvol", containing just the contents of the folder that contains "Setup" off the Adobe Design std Install DVD
    A folder called "/Volumes/cs4stdvol" to mount the network share to (if you have a bunch, you may want to consider one mount point with a bunch of subfolder installers)
    The actual Unix commands to issue are as follows (make sure to execute as root!):
    mkdir /Volumes/cs4stdvol; mount_afp afp://adobeinstaller:[email protected]/cs4stdvol /Volumes/cs4stdvol/; /Volumes/cs4stdvol/Setup.app/Contents/MacOS/Setup --mode=silent --deploymentFile=/Volumes/cs4stdvol/install.xml; umount /Volumes/cs4stdvol/
    Basically, the gist of it is:
    Make a folder in /Volumes to mount the network share at.
    Mount the network share using whatever username and passwd you created.
    Run the Adobe Setup app as root in silent mode with the deployment file you created by reading through the setup instructions in the Manual Enterprise Deployment Help.
    Unmount the network share (which also automatically deletes the folder from /Volumes).
    Hope this helps others,
    Eric.

    So, I have been meaning to post up now I've done a couple of successful installs using this command set.
    After following the instructions to build a Manual Enterprise Deployment, Adobe recommends that you copy your completed package to the machine and execute it from there. But I found it much easier to just create a network volume that could be accessed by an authorized installer user and mount that and run the install from there instead.
    For this example I've assumed:
    A server called "server.local"
    An install user called "adobeinstaller" with passwd "installerpasswd"
    A network share that only the above user can access called "cs4stdvol", containing just the contents of the folder that contains "Setup" off the Adobe Design std Install DVD
    A folder called "/Volumes/cs4stdvol" to mount the network share to (if you have a bunch, you may want to consider one mount point with a bunch of subfolder installers)
    The actual Unix commands to issue are as follows (make sure to execute as root!):
    mkdir /Volumes/cs4stdvol; mount_afp afp://adobeinstaller:[email protected]/cs4stdvol /Volumes/cs4stdvol/; /Volumes/cs4stdvol/Setup.app/Contents/MacOS/Setup --mode=silent --deploymentFile=/Volumes/cs4stdvol/install.xml; umount /Volumes/cs4stdvol/
    Basically, the gist of it is:
    Make a folder in /Volumes to mount the network share at.
    Mount the network share using whatever username and passwd you created.
    Run the Adobe Setup app as root in silent mode with the deployment file you created by reading through the setup instructions in the Manual Enterprise Deployment Help.
    Unmount the network share (which also automatically deletes the folder from /Volumes).
    Hope this helps others,
    Eric.

  • Need TP command for Add  Transport Request to import Queue all at a time

    Hi SAP gurus,
    Can you tell the o/s  or  TP  command  to  Add   Transport Request to import Queue all at a time which are available in co files directory   ,
    Because I have to add 500- 600 request .  For every request I canu2019t  do like this  STMS_IMPORT  -- Extras=> other requests -add--
    Thanks and regards
    babu

    Hi,
    You can export list of all transport requests from your DEV system in one shot, from SE09-> Display (provide your required selection criteria) -> Goto -> "Display as List"
    You can export these all Transport Requests as Spreadsheet. Then Filter out all your required 400 to 500 Transport Requests.
    Now,use another excel sheet to create a file with the list of required transport request Nos only, then concatenate all of them to generate the required TP commands as mentioned below.
    The syntax will become as follows:
    column1           column2         column3
    tp addtobuffer DEVK900123 <SID> pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp addtobuffer DEVK900124 <SID> pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp addtobuffer DEVK900125 <SID> pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp addtobuffer DEVK900126 <SID> pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp addtobuffer DEVK900127 <SID> pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp import          DEVK900123 <SID> client=### pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp import          DEVK900124 <SID> client=### pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp import          DEVK900125 <SID> client=### pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp import          DEVK900126 <SID> client=### pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    tp import          DEVK900127 <SID> client=### pf=<Drive>:\usr\sap\trans\bin\TP_DOMAIN_<SID>.PFL
    -> Open Notepad and Copy+Paste these three columns & save the text file in the <Drive>:\usr\sap\trans\bin\ folder.
    -> Then rename this .txt file to *.bat.
    -> open a command prompt and change to the <Drive>:\usr\sap\trans\bin\ folder and run the .bat batch file.
    Make sure that object lists of all the Trans. Requests are checked and confirmed for the transport to avoid data incosistency in target system. (e.g. Number Range Object)
    Regards,
    Bhavik G. Shroff

  • Need terminal command for setting display colors ASAP!!!!!

    Hello everyone,
    I was being dumb and figured, oh what will this do?
    I know, I know one of those button pushers...anyway I set the Display colors to 256 on my Xserve, which has no video card in it, and now all I see in Chicken of the VNC is a black screen. Im sure there is a terminal command out there where
    I can ssh into the Xserve, and change the colors back, but I can't find it...could someone post it up here or point me in the right direction please?
    Thanx in advance!!!!!!!

    didn't even think of that...seems to be the most obvious things, seem to be the first to be overlooked.
    Will let you know.

  • [SOLVED] Mac OS X-like 'view' CLI command for Linux?

    On the Mac, you can type 'view example.doc' to have OpenOffice open it, or 'view image.png' to have the image viewer open it, etc.
    Is there something similar on Linux?
    (I've searched but can't find anything.)
    Last edited by chrispoole (2009-05-13 11:52:19)

    Aprz wrote:
    Agent69 wrote:
    chimeric wrote:
    In case you're using zsh as your shell of choice you could also use alias -s style aliases:
    alias -s doc=openoffice
    alias -s cpp=gvim
    Typing the filename and hitting enter should then open it in the defined application.
    Damn that's slick. I've always stuck with Bash but I might have to reconsider (unless Bash 4 has this feature).
    It does except without the "-s". :s By default, in your ~/.bashrc, it already has "alias ls='ls --color=auto'".
    Read it again.  These aren't ordinary aliases.  I interpret chimeric as saying that  in zsh the -s option allows you to associate file extensions with commands, not simple text replacement like your example.

  • MacBook Pro - 802.11n, WPA2-Personal and Time Capsules

    I recently moved to using 802.11n (5GHZ) mode on my Time Capsule using WPA2-Personal security. I am unable to connect to the wireless network which is extremely frustrating since this is all Apple hardware. I have no problem connecting to the 802.11n 5GZ network using one of my PCs.
    My MacBook Pro has the latest software updates available and does have 802.11n enabled.
    I have been looking for similar issues on the forum and have tried a few things that were suggested by others, but nothing works. I've reset the router. Reset the SMU. Haven't reset NVRAM yet.
    I have a mix of Apple and PC hardware that is connecting to this network. My 24" Intel iMac (Core 2 Duo) connects just fine.
    I'm hoping there is a GURU on this forum that can assist me.
    Thanks,
    J.d.

    I would try:
    1. Examine your system.log for the error you are getting, if you cannot authenticate with the router it will say why. Go to the Apple icon, select "About this Mac", select "more info" button in the center, select "Log" under Software on the left panel side, select "system.log" then scroll to the bottom, look for errors in the log related to "airport" or 802.11...
    2. Go to Finder/Utilities, pull up keychain access.app, click on System on the left, you should see an entry for your WIFI network, delete that entry, close Keychain access.
    3. Try removing, reboot then re-add your Aiport entry. Go to System Parameters, Network, highlight "Airport" click on the minus button and remove it. Reboot your computer. When it comes back up go back to System Parameters, Network, then click on the button and re-add the Airport, when it says Airport 2, over write that with just "Airport", then click on Advanced, click on button to add the Preferred Network back in, type the name of the SSID on your router, then select WPA2 Personal from the drop down menu type. You can also display the password to confirm it matches what you input in the router for the password for WPA2 Personal.
    Under TCP/IP, if you are getting a private IP address from the router via DHCP, then set IPv4 to DHCP. I would not use IPv6 for time being, set that to Off. Next click on your DNS and input your DNS if not automatically filled in by the router with DHCP, I always like to add a DNS not provided by the router that way if it fails or you go to Starbucks you will always have a DNS entry that works, I would input OpenDNS's entries, so those would be under IPv4:
    208.67.222.222 and other is
    208.67.220.220
    So to connect, your computer needs to have an IP address, either DHCP or manually input (like 192.168.1.xxx) etc.
    Next you need a DNS entry if not provided for by your router (should be if it is dishing out DHCP client addresses).
    WINS and Proxies are only used in corporate environments where they are using a windows domain and/or proxy servers as a gateway to the WAN.
    WPA2 Personal offers much better security than WPA or WEP shared, if you use a password make it at least 8 characters in length 10 is better. The longer you make it the higher the security, but it must match exactly what the password was set for WPA2 on the router.
    TO make sure you are not having signal/noise problems get as close to your router as you can to establish the connection once that is done you can move farther away.

  • Help with EEM TCL / CLI scripting for re-direction/wccp counters

    Being new with EEM scripting I wanted to see if I was on the right track and get some help to finish my idea.
    Our problem I am trying to fix is our remote sites utilize pairs of Cat3650's for some routing and WCCP redirection.  We are encountering ACL denial issues causing slow down and access issues.  The fix for the issue we remove the WCCP service groups to break peering with our wan optimizers and re-insert the configuration thus re-establishing peering and restoring service.
    My idea is to use a TCL scipt on a watchdog timer to parse the "sh ip wccp | inc denied (or unassign)" output for denial and unassignable error counters.  If a counter is found I wanted to create a syslog message that would then kick off a simple EEM CLI script to remove the service groups, wait 10 seconds, then re-add the service groups.  Please point me in the right direction if I am off track as I am not sure if I can use the EEM CLI for all this or since I want to retreive specific info from the sh ip wccp output if I do need to utilize TCL.  I am also unsure if the "total denied" ascii string pulled via the "sh ip wccp | inc denied" will cause issues when attempting to just pull the counter information.
    sh ip wccp | inc Denied Red
            Total Packets Denied Redirect:       0
            Total Packets Denied Redirect:       0
    Script thus far :
    TCL
    if [catch {context_retrieve "EEM_WCCP_ERROR_COUNTER" "count"} result] {
    set wccpcounter 0
    } else {
    set wccpcounter $result
    } if [catch {cli_open} result] {
    error $result
    } else {
    array set cli $result
    } if [catch {cli_exec $cli(fd) "show ip wccp | incl Denied"} result] {
    error $result
    } else {
    set cmd_output $result
    set count ""
    catch [regexp {receive ([0-9]+),} $cmd_output} ignore count]
    set count
    set diff [expr $count - $wccpcounter]
    if {$diff != 0} {
    action_syslog priority emergencies msg "WCCP counters showing incremental Denied packet counts"
    if [catch {cli_close $cli(fd) $cli(tty_id)} result] {
    error $result
    context_save EEM_WCCP_ERROR_COUNTER count
    CLI
    event manager applet WCCP_COUNTER_WATCH
    event syslog priority emergencies pattern "WCCP counters showing incremental Denied packet counts"
    action 001 cli command "enable"
    action 002 cli command "config t"
    action 003 cli command "no ip wccp 61"
    action 004 cli command "no ip wccp 62"
    action 005 wait 10
    action 006 cli command "ip wccp 61"
    action 007 cli command "ip wccp 62"
    action 008 wait 15
    action 009 cli command "clear ip wccp"
    action 010 cli command "end"
    Thanks for all the help

    This won't work as EEM cannot intercept its own syslog messages.  However, I'm not sure why you need this form of IPC anyway.  Why not just make the Tcl script perform the needed CLI commands?
    And, yes, you could use all applets here.  But since you've written the hard stuff in Tcl already, it might be best just to add the missing calls to reconfigure WCCP to that script.

  • Command for view i/o rate cisco nexus

    Hi
    I need a command for view input and output rate on all interface for device nexus 7000 and nexus 5000
    The command sh interface show more information, I only need view rx and tx
    on switch 3750, 2960 i use sh interface summary and in nexus do not exist
    Regards

    Hi,
    Show interface xxx | inc rate will give you in /out rate.
    For example -sh int e1/1 | i rate
    For show interface summary you can use grep feature on nexus multiple Include and exclude are possible.
    show interface E1/1 | inc rate|MTU | exclude pps
    Just to see interface counters -
    show interface counters detailed all
    Hope this helps.
    Thanks
    Ajay

  • Print-control commands for dotmatrix printer

    dear all,
    Here my requirement is we are using datamax printer ( dotmatrix printer) for printing script and i need some commands for that.
    please reply soon.
    thanx inadvance

    Hi Don
    Thank's for your reply.
    That's excactly what we want to do: within the same report we'll use different trays and/or number of copies.
    In the meantime, we talked to the manufacturer of the ELP module. They told us that the print stream contains parts of the correct sequence, but unfortunately the trailing two closing paranthesis are missing. For that reason, the command string is not recognized as valid command and is therefore printed "as is".
    We tried to add additional characters after the trailing paranthesis, again no success...
    The next step is to use the newer CR runtime, as Nikhil suggested in his answer.
    Weird problem...
    Regards
    Daniel

  • A command for finding an application's version number?

    Hello,
    I need a command for finding the version number of a specific application installed in OS X, and I need to be able to run it via the UNIX feature of Apple Remote Desktop, so that I can run it on hundreds of computers. First I tried this:
    system_profiler -detailLevel full
    It works, but it takes a long time to produce the output, because it's gathering and outputting all of the information that System Profiler provides. I don't know if there's a way to narrow it down so that it only gives me the version number of the specific application I need to know about. This is an example of what the output looks like for each application listed.
        iPhoto:
          Version: 9.2.1
          Last Modified: 10/27/11 10:05 AM
          Kind: Intel
          64-Bit (Intel): No
          App Store: No
          Location: /Applications/iPhoto.app
    Copying that to TextEdit and searching for the application's name takes way too long, especially for hundreds of computers. Are there any arguments or regular expressions I could add to the command to narrow it down, and make it only output the information I need?
    Someone suggested this command, which takes the information from Spotlight:
    mdls -name kMDItemVersion <path to file>
    That works for apps in the Applications folder, but the application I need the version number for is in the /usr/bin folder and I'm guessing that's not indexed by Spotlight, because it returns:
    kMDItemVersion = (null)
    Any help would be greatly appreciated!
    -Mike

    You rock! I'm definitely on the right track now. Yes, it's a regular application package, not a UNIX executable. Ok, so I use this command to display the Info.plist file inside that package:
    cat /usr/bin/uc/UndercoverRegistration.app/Contents/Info.plist
    And it outputs this:
    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
    <plist version="1.0">
    <dict>
        <key>CFBundleDevelopmentRegion</key>
        <string>English</string>
        <key>CFBundleExecutable</key>
        <string>UndercoverRegistration</string>
        <key>CFBundleIconFile</key>
        <string>Undercover</string>
        <key>CFBundleIdentifier</key>
        <string>com.orbicule.UndercoverRegistration</string>
        <key>CFBundleInfoDictionaryVersion</key>
        <string>6.0</string>
        <key>CFBundlePackageType</key>
        <string>APPL</string>
        <key>CFBundleShortVersionString</key>
        <string>4.5</string>
        <key>CFBundleSignature</key>
        <string>????</string>
        <key>CFBundleVersion</key>
        <string>4.5</string>
        <key>NSMainNibFile</key>
        <string>MainMenu</string>
        <key>NSPrincipalClass</key>
        <string>NSApplication</string>
    </dict>
    </plist>
    So can I add arguments to that command to have it only display the version number, which is on line 18 (the value is 4.5 here)? So would I be able to display only line 18, or display whatever is below the line that reads "<key>CFBundleShortVersionString</key>"? Thanks!

  • Command for buld signature retirement on non-IOS devices..

    Anyone know the CLI commands for buld signature retirement on IDSMs or other non-IOS devices? Thanks...

    Assuming you asking about how to retire/remove a signature using the CLI, here's how:
    On routers
    ip ips signature-definition 
    signature 5733 0
    status
    enabled false
    retired true
    end
    On sensors
    configure terminal
    service signature-definition sig1
    signatures 12000 0
    status
    enabled false
    retired true

Maybe you are looking for