10-16-2014 05:12 AM - edited 07-05-2021 01:44 AM
I have setup wireless in camp as following:
One AP1532E connected to wired network, three AP1532E configured as wireless bridges on Dot11Radio1 (5 MHz) interfaces and as root APs on Dot11Radio0 (2.4 MHz) interfaces.
Some clients have trouble connecting to wireless and I see the following messages on all APs including wired one:
Capri: acif_ath_crypto_vlan_key_get Invalid key type 0
I have enable the same encryption on Dot11Radio0 and Dot11Radio1 interfaces:
encryption vlan 2 mode ciphers aes-ccm tkip wep128.
As I mentioned some wireless clients have trouble and others work fine.
Any suggestion will be appreciated.
Solved! Go to Solution.
10-18-2014 08:47 AM
Only enable AES-CCM & check. If you still have only TKIP supported clients, then you can enable it, but at least get rid of WEP if that is the case. Encryption config should be like this under radio interface.
encryption vlan 2 mode ciphers aes-ccm
Also make sure WPA version 2 selected as authentication key management under SSID configuration.
HTH
Rasika
**** Pls rate all useful responses ****
10-18-2014 08:47 AM
Only enable AES-CCM & check. If you still have only TKIP supported clients, then you can enable it, but at least get rid of WEP if that is the case. Encryption config should be like this under radio interface.
encryption vlan 2 mode ciphers aes-ccm
Also make sure WPA version 2 selected as authentication key management under SSID configuration.
HTH
Rasika
**** Pls rate all useful responses ****
10-18-2014 08:47 AM
Thank you Manannalage, unfortunately I can't take off other encryption options right now. In order to remove wep encryption I will need to remove SSID binding to Radio interface and it will disconnect the bridge. I will need to be on the location and connect through console to those bridges to do the changes. It probably wont happen soon. I have changed wep to version 2 so.
Thank you for you suggestions.
10-25-2014 05:50 AM
Thank you for your suggestion. It worked!
Also I was able to take wep encryption off from wireless bridges without connecting to the console of each bridge. I used TFTP server to download current configs, made a change with notepad, and uploaded modified configs to sartup-config on the bridges, then rebooted them. Worked pretty well.
10-25-2014 01:50 PM
Good to hear that.
Thanks for the follow up & update on how you did it.
Rasika
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide