Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Recommended Security settings for Cisco 7925 on VC

This thread has been viewed 1 times
  • 1.  Recommended Security settings for Cisco 7925 on VC

    Posted Jan 23, 2019 04:08 PM

    I am assisting a k12 district in configuring a number of Cisco 7925 wireless hand sets to connect to their Aruba VC. I am unclear if we should use enterprise or personal security and what the corresponding configuration would be on the handset. The phone has the following options: Open, Open+WEP, Shared+WEP, LEAP, EAP-FAST, EAP-TLS, PEAP, Auto(AKM). I would like to keep things as quick and simple as possible without running "Open" and would like to be sure of a solution before making a road-trip to the school. I have already confirmed the phone can connect to the VOIP VLAN, using 128 bit WEP but would like to make it simpler for the end user to configure.

     

    Appreciate any guidance or a document that provides the best answer.

     



  • 2.  RE: Recommended Security settings for Cisco 7925 on VC

    EMPLOYEE
    Posted Jan 24, 2019 04:33 AM

    You probably should avoid WEP as is it inherently insecure and by some considered even worse than open. And also your SSID will drop to legacy rates (54Mbps max) as the 802.11n standard does not allow WEP to be used on 11n SSIDs.

     

    If you don't want to go for strong authentication with EAP-TLS, I would check if you can configure WPA2-PSK (pre-shared key, aka WPA2 Personal) That is what I see deployed many times for wireless VoIP phones if TLS is not an option or desirable. 



  • 3.  RE: Recommended Security settings for Cisco 7925 on VC

    Posted Jan 24, 2019 10:01 AM

    I probably should have stated this in my original post: I don't see options on the Aruba VC that corrilate with what I have available on the Cisco phone, outside of wep and open. I was hoping there was a way to implement wpa or wpa-2 but neither are an option on the phone.



  • 4.  RE: Recommended Security settings for Cisco 7925 on VC
    Best Answer

    EMPLOYEE
    Posted Jan 28, 2019 07:48 AM

    I don't have such a phone, but found this page that suggests putting the security mode to auto for WPA2.

     

    Can you try that?



  • 5.  RE: Recommended Security settings for Cisco 7925 on VC

    Posted Jan 28, 2019 10:03 AM

    That's almost comical... Thank you! it worked!