<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WPA2/AES and WPA/TKIP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629221#M143561</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;for compatiility reasons I was used to enable both protocols on all the access points I prepared for&amp;nbsp;customers of mine, both as regards on lightweight ones that&amp;nbsp;standalone,&lt;/P&gt;&lt;P&gt;Now, as you all know, not only it's not best practice, but on&amp;nbsp;the latest cisco products enabling both aes and tkip on the same ssid brings a lot of troubles.&lt;/P&gt;&lt;P&gt;I'm educating customers to get rid of old tkip only devices in order to remove it from&amp;nbsp;configurations on wlc's and standalone ap's, but it's not always that easy, customers need time.&lt;/P&gt;&lt;P&gt;I read that a solution on wlc coud be&amp;nbsp;to create two wlans with same ssid, one aes and the other tkip, but on latest releases seems&amp;nbsp;not allowed to create any ssid with wpa1&amp;nbsp;only encyption.&lt;/P&gt;&lt;P&gt;On standalone ap's creating two ssid's on same vlan/interface is not allowed historically.&lt;/P&gt;&lt;P&gt;Did you find any solution for that?&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 09:42:03 GMT</pubDate>
    <dc:creator>Massimo Baschieri</dc:creator>
    <dc:date>2021-07-05T09:42:03Z</dc:date>
    <item>
      <title>WPA2/AES and WPA/TKIP</title>
      <link>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629221#M143561</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;for compatiility reasons I was used to enable both protocols on all the access points I prepared for&amp;nbsp;customers of mine, both as regards on lightweight ones that&amp;nbsp;standalone,&lt;/P&gt;&lt;P&gt;Now, as you all know, not only it's not best practice, but on&amp;nbsp;the latest cisco products enabling both aes and tkip on the same ssid brings a lot of troubles.&lt;/P&gt;&lt;P&gt;I'm educating customers to get rid of old tkip only devices in order to remove it from&amp;nbsp;configurations on wlc's and standalone ap's, but it's not always that easy, customers need time.&lt;/P&gt;&lt;P&gt;I read that a solution on wlc coud be&amp;nbsp;to create two wlans with same ssid, one aes and the other tkip, but on latest releases seems&amp;nbsp;not allowed to create any ssid with wpa1&amp;nbsp;only encyption.&lt;/P&gt;&lt;P&gt;On standalone ap's creating two ssid's on same vlan/interface is not allowed historically.&lt;/P&gt;&lt;P&gt;Did you find any solution for that?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629221#M143561</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2021-07-05T09:42:03Z</dc:date>
    </item>
    <item>
      <title>On a single WLAN, you can</title>
      <link>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629222#M143562</link>
      <description>&lt;P&gt;On a single WLAN, you can allow WPA1 and WPA2clients to join,TKIP is the default value for WPA1, and AES is the default value for WPA2.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 11:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629222#M143562</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2015-03-13T11:39:42Z</dc:date>
    </item>
    <item>
      <title>Sure, but I've got a lot of</title>
      <link>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629223#M143563</link>
      <description>&lt;P&gt;Sure, but I've got a lot of issues&amp;nbsp;enabling both protocols on recent cisco AP's, as soon as I remove wpa1 tkip on wlc or standalone ap configuration troubles disappear, that way&amp;nbsp;old tkip devices no longer can connect to wireless.&lt;/P&gt;&lt;P&gt;I was wondering if there is a workaround that allows old tkip devices to connect to wifi without disrupting new AES devices connections, possibly using same ssid.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 12:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629223#M143563</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2015-03-13T12:42:20Z</dc:date>
    </item>
    <item>
      <title>I know your pain first hand.</title>
      <link>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629224#M143564</link>
      <description>&lt;P&gt;I know your pain first hand. Ive tested this and seen the issue even did packet traces. This is a big pickle. 8.0 no longer allows just TKIP, but it does allow transitional TKIP and AES.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using a WLC.&amp;nbsp;Here is my suggestion. I haven't tried it but it may work. Down grade to 7.6 config your 2 network TKIP and AES then upgrade to 8.0. I think it will preserve the already existing network. Its worth a try.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 19:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629224#M143564</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-03-13T19:03:44Z</dc:date>
    </item>
    <item>
      <title>In fact the environment it's</title>
      <link>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629225#M143565</link>
      <description>&lt;P&gt;In fact the environment it's getting me the worst pain is a recent migration from old 4400 wlc's to&amp;nbsp;a vwlc that started with 8.0.100 release.&lt;/P&gt;&lt;P&gt;But the issue is also related&amp;nbsp;to&amp;nbsp;ap models, since the whole&amp;nbsp;ap pool&amp;nbsp;was of&amp;nbsp;glorious 1242's no issue at all, only after swapping two 1242's with two brand new 1702's the pain started, and gives pain only in the 1702's coverage area.&lt;/P&gt;&lt;P&gt;I'm sure your trick works, but in my case it's better to get rid of the 1702's until&amp;nbsp;tkip devices disappear completely.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2015 06:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wpa2-aes-and-wpa-tkip/m-p/2629225#M143565</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2015-03-14T06:14:46Z</dc:date>
    </item>
  </channel>
</rss>

