Solved

Best Practices of Converting from WEP to WPA

Posted on 2009-05-07
8
527 Views
Last Modified: 2013-12-27
I am looking for some configuration guidelines, discussion, or a whitepaper to convert my Cisco ap's from WEP with 128bit keys over to WPA or something better. Is WPA the way to go at this point? I am concerned on how to convert my current wireless over which has about 50 access points spread out across the country. Currently, we use the same wep key thoughout the organization. How would I do this with minimal downtime toward the users. How much configuration would there be? I am using Cisco 1200's and 1242ag wap's currently. They are all standalone configs.
0
Comment
Question by:canatechguy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 

Author Comment

by:canatechguy
ID: 24329906
I also have a bunch of Cisco 1100's as well. Specifically 1121G's.
0
 
LVL 32

Accepted Solution

by:
Kamran Arshad earned 200 total points
ID: 24333162
Hi,

I suggest that you change the configuration on one of your APs in your local office and then make a template. This template then can be uploaded to all your APs across different sites using a configuration management tool like Solarwinds Orion NCM or Rancid;

Rancid      www.shrubbery.net/rancid
Solarwinds NCM      www.solarwinds.com
0
 
LVL 10

Assisted Solution

by:lanboyo
lanboyo earned 200 total points
ID: 24335925
Good advice on the rancid or solarwinds above. Change the AP names when you make the change. Push out a wireless connection profile with your desired security profiles and NEW ACCESS POINT NAMES to the user stations so they can select the "new" access point as it gets converted. Otherwise more workstations will require visitation than you will like.

If all devices support it, use WPA2 over WPA. It seems we are talking about WPA Pre-Shared-Key, this si similiar to WEP in that you may well have a single passphrase for your entire network. 802.1x is better, but it requires infrastructure and significant work on the end stations.

0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 

Assisted Solution

by:here_t0_share
here_t0_share earned 100 total points
ID: 24340987
Hello,

First please make sure that all the intended user's have a Laptop/PC with WPA compatible W-Fi adapter.
As WPA is fairly new( as compared to WEP).
some Wi-Fi adapters may not even support you and then you will have bigger/different set of problems to solve.
0
 

Author Comment

by:canatechguy
ID: 24357524
It looks like I have the options of TKIP, WEP, CKIP, and CMIC of available for ciphers in the 1100 ap's. Maybe I cannot go to WPA with some of these older ap's.
0
 
LVL 10

Expert Comment

by:lanboyo
ID: 24359439
Tkip with preshared key is a wpa encryption.
0
 

Author Comment

by:canatechguy
ID: 24375166
Ok, I can easily convert over to WPA-TKIP and even use the same key with these devices. That would give me a more secured connection. Has anyone done this and is there a way to programatically change the WPA key. Is that something that you can push down. Maybe a registry edit?
Lanboyo, What is the differences in wpa2 vs wpa?
0
 

Author Closing Comment

by:canatechguy
ID: 31579178
I was hoping to get more info on the subject of deployment but good info still the same. Thanks for your help.
0

Featured Post

SharePoint Admin?

Enable Your Employees To Focus On The Core With Intuitive Onscreen Guidance That is With You At The Moment of Need.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month8 days, 13 hours left to enroll

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question