protected-mgmt-frames
Configures the WLAN's frame protection
mode and
security association (SA) query parameters.
The IEEE 802.11w
Protected management frames (PMF) standard provides protection for the
following robust management frame types: de-authentication, disassociation, action and
channel switch announcement unicast frames forwarded to a client. Robust management frame
protection is achieved by using CCMP for unicast management frames, broadcast/multicast
integrity protocol for broadcast/multicast management frames and SA query protocol for
protection against (re)association attacks.
Supported in the following platforms:
- Access Points — AP505i, AP510i/e,
AP560i/h, AP7522, AP7532, AP7562, AP7612, AP7632, AP7662, AP8432, AP8533
- Service Platforms
— NX5500, NX7500, NX9500, NX9600, VX9000
Syntax
protected-mgmt-frames [mandatory|optional|sa-query [attempts <1-10>|timeout <100-1000>]
Parameters
protected-mgmt-frames [mandatory|optional|sa-query [attempts <1-10>|timeout <100-1000>]
protected-mgmt-frames |
Enables and configures WLAN's frame protection mode and SA query parameters.
Use this command to specify whether management frame protection is mandatory or
optional. |
mandatory |
Enforces PMF on this WLAN (management frames are always protected). This option
requires clients to negotiate PMF when joining a WLAN. Note: This option does not allow non-PMF
capable clients to associate.
|
optional |
Provides PMF only for PMF-capable clients (that is, management frame protection
is optional). Note: This option
allows both PMF-capable and non-PMF capable wireless clients to associate.
However, only the management frames of PMF-capable clients is
protected.
Note: This is the default setting. By default, PMF is
enabled and set to the 'optional' mode.
|
sa-query [attempts <1-10>| timeout
<100-1000>] |
Configures the following SA parameters:
- attempts <1-10> – Configures the number of SA query attempts from 1 - 10.
The default is 5.
- timeout <100-1000> –
Configures the interval, in milliseconds, used to timeout association requests
that exceed the defined interval. This setting is required to determine if a
client is a real and not a rogue. If the client response is timed out the client
association is deleted from the controller. Specify a value from 100 - 1000
milliseconds. The default value is 201 milliseconds.
|
|
Examples
nx9500-6C8809(config-wlan-test)#protected-mgmt-frames mandatory
nx9500-6C8809(config-wlan-test)#show context
wlan test
ssid test
bridging-mode tunnel
encryption-type none
authentication-type none
protected-mgmt-frames mandatory
nx9500-6C8809(config-wlan-test)#
Related Commands
no (wlan-config-mode) |
Disables enforcement of protected management frames on this WLAN. And reverts
protected management frames sa-query timeout and attempts to 201 milliseconds and 5
respectively. |
|