Open as PDF
158 CHAPTER 8: CONFIGURING AND MANAGING MOBILITY DOMAIN ROAMING
You can enhance security on your network by enabling WX-WX security.
WX-WX security encrypts management traffic exchanged by WX switches
in a Mobility Domain.
When WX-WX security is enabled, management traffic among WX
switches in the Mobility Domain is encrypted using AES. The keying
material is dynamically generated for each session and passed among
switches using public keys that you configure.
To configure WX-WX security:
Set Mobility Domain security on each switch to required. The default
setting is none. WX-WX security can be disabled or enabled on a
Mobility Domain basis. The feature must have the same setting
(required or none) on all switches in the Mobility Domain. Use the
following command on the seed and on each member to enable
set domain security required
This command also creates a certificate.
On the Mobility Domain seed, specify the public key for each member.
Use the following command:
set mobility-domain member ip-addr key hex-bytes
Specify the key as 16 hexadecimal bytes, separated by colons. Here is
On each member switch, specify the seed’s IP address and its public
key. Use the following command:
set mobility-domain mode member seed-ip ip-addr key
This command does not need to be entered on the seed switch.
On the seed and on each member, generate a private key. Use the
crypto generate key domain 128