Management Frames Protection
Aruba Central supports the Management Frame Protection (MFP) feature in networks that include Aruba Instant 8.5.0.0 firmware version and later. This feature protects networks against forged management frames spoofed from other devices that might otherwise disrupt a valid user session.
The MFP increases the security by providing data confidentiality of management frames. MFP uses 802.11i802.11i provides improved encryption for networks that use 802.11a, 802.11b, and 802.11g standards. It requires new encryption key protocols, known as Temporal Key Integrity Protocol (TKIP) and Advanced Encryption Standard (AES). framework that establishes encryption keys between the client and Instant AP.
Enabling Management Frames Protection Feature for Wireless Networks in Aruba Central
To enable the MFP feature, complete the following steps:
1. In the app, set the filter to a group that contains at least one AP.
The dashboard context for the group is displayed.
2. Under , click > .
A list of access points is displayed in the
view.3. Click the icon.
The tabs to configure the access points are displayed.
4. Click the tab.
The WLANsWireless Local Area Network. WLAN is a 802.11 standards-based LAN that the users access through a wireless connection. details page is displayed.
5. In the page, click . To modify an existing SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network., select a wireless SSID from the table and then click the edit icon.
6. In the tab, click .
7. Expand .
8. Turn on the toggle switch to enable the MFP feature.
9. Click .
10. Click .
The MFP configuration is a per-SSID configuration. The MFP feature can be enabled only on WPA2Wi-Fi Protected Access 2. WPA2 is a certification program maintained by IEEE that oversees standards for security over wireless networks. WPA2 supports IEEE 802.1X/EAP authentication or PSK technology, but includes advanced encryption mechanism using CCMP that is referred to as AES.-PSKPre-shared key. A unique shared secret that was previously shared between two parties by using a secure channel. This is used with WPA security, which requires the owner of a network to provide a passphrase to users for network access. and WPA2-Enterprise SSIDs. The 802.11r802.11r is an IEEE standard for enabling seamless BSS transitions in a WLAN. 802.11r standard is also referred to as Fast BSS transition. fast roaming option will not take effect when the MFP is enabled.