<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Queries regarding Fast secure roaming in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941443#M17474</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a few queries related to the FSR:&lt;/P&gt;
&lt;P&gt;1. In AireOS version 8.2.x , if we allow FT with 802.1X , will the non-802.11r clients be able to connect ? &amp;nbsp;The 8.2 config guide is confusing in this regard.&lt;/P&gt;
&lt;P&gt;2. What version of IOS (Apple) support OKC/PKC ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These questions arise from the fact that, the OKC is not working as expected for the HP clients that we have in our environment. Just to be clear, we have ONLY HP clients in the environment:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;C:\Users\E607589&amp;gt;netsh wlan show drivers&lt;/P&gt;
&lt;P&gt;Interface name: Wireless Network Connection&lt;/P&gt;
&lt;P&gt;Driver : Intel(R) Dual Band Wireless-N 7265&lt;BR /&gt; Vendor : Intel Corporation&lt;BR /&gt; Provider : Intel&lt;BR /&gt; Date : 28-01-2016&lt;BR /&gt; Version : 18.33.0.2&lt;BR /&gt; INF file : C:\Windows\INF\oem65.inf&lt;BR /&gt; Files : 3 total&lt;BR /&gt; C:\Windows\system32\DRIVERS\Netwsn02.sys&lt;BR /&gt; C:\Windows\system32\DRIVERS\Netwfw02.dat&lt;BR /&gt; C:\Windows\system32\drivers\vwifibus.sys&lt;BR /&gt; Type : Native Wi-Fi Driver&lt;BR /&gt; Radio types supported : 802.11b 802.11g 802.11n 802.11a&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As per our debugging, the clients are doing a full reauthetication durng roaming to a new AP in the same WLC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Manish&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 13:04:52 GMT</pubDate>
    <dc:creator>Manish Mathur</dc:creator>
    <dc:date>2021-07-05T13:04:52Z</dc:date>
    <item>
      <title>Queries regarding Fast secure roaming</title>
      <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941443#M17474</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a few queries related to the FSR:&lt;/P&gt;
&lt;P&gt;1. In AireOS version 8.2.x , if we allow FT with 802.1X , will the non-802.11r clients be able to connect ? &amp;nbsp;The 8.2 config guide is confusing in this regard.&lt;/P&gt;
&lt;P&gt;2. What version of IOS (Apple) support OKC/PKC ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These questions arise from the fact that, the OKC is not working as expected for the HP clients that we have in our environment. Just to be clear, we have ONLY HP clients in the environment:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;C:\Users\E607589&amp;gt;netsh wlan show drivers&lt;/P&gt;
&lt;P&gt;Interface name: Wireless Network Connection&lt;/P&gt;
&lt;P&gt;Driver : Intel(R) Dual Band Wireless-N 7265&lt;BR /&gt; Vendor : Intel Corporation&lt;BR /&gt; Provider : Intel&lt;BR /&gt; Date : 28-01-2016&lt;BR /&gt; Version : 18.33.0.2&lt;BR /&gt; INF file : C:\Windows\INF\oem65.inf&lt;BR /&gt; Files : 3 total&lt;BR /&gt; C:\Windows\system32\DRIVERS\Netwsn02.sys&lt;BR /&gt; C:\Windows\system32\DRIVERS\Netwfw02.dat&lt;BR /&gt; C:\Windows\system32\drivers\vwifibus.sys&lt;BR /&gt; Type : Native Wi-Fi Driver&lt;BR /&gt; Radio types supported : 802.11b 802.11g 802.11n 802.11a&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As per our debugging, the clients are doing a full reauthetication durng roaming to a new AP in the same WLC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Manish&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941443#M17474</guid>
      <dc:creator>Manish Mathur</dc:creator>
      <dc:date>2021-07-05T13:04:52Z</dc:date>
    </item>
    <item>
      <title>Hi Manish,</title>
      <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941444#M17475</link>
      <description>&lt;P&gt;Hi Manish,&lt;/P&gt;
&lt;P&gt;Instead of 8.2, you may need to go with 8.3 which support adaptive 802.11r, effectively you can have single SSID that support both 802.11r and non-802.11r client connectivity. Refer below post on that feature&lt;/P&gt;
&lt;P&gt;&lt;A href="http://wirelessonthego.postach.io/post/cisco-wlc-8-3-adaptive-11r"&gt;http://wirelessonthego.postach.io/post/cisco-wlc-8-3-adaptive-11r&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 19:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941444#M17475</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2016-11-02T19:16:07Z</dc:date>
    </item>
    <item>
      <title>Are you really sure 8.3 is</title>
      <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941445#M17476</link>
      <description>&lt;P&gt;Are you really sure 8.3 is needed for that&lt;/P&gt;
&lt;P&gt;I'm running 8.2 here and in the same SSID (FT enabled):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Client 1 uses key management "FT-802.1x" (Android Xperia Z5 compact)&lt;/LI&gt;
&lt;LI&gt;Client 2 uses key management "802.1x" (Oooold Android Motorola Razr i - non FT capable)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So obviously a mix within the same SSID works without adaptive FT&lt;/P&gt;
&lt;P&gt;Furthermore, the 8.2 config guide states:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;From Release 8.0, you can create an 802.11r WLAN that is also an WPAv2 WLAN. In earlier releases, you had to create separate WLANs for 802.11r and for normal security. Non-802.11r clients can now join 802.11r-enabled WLANs as the 802.11r WLANs can accept non-802.11r associations. If clients do not support mixed mode or 802.11r join, they can join non-802.11r WLANS.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I couldn't find any information regarding adaptive 802.11r in the release notes. As written in your reference, a Cisco doc is here:&lt;BR /&gt;http://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/technotes/8-3/Optimizing_WiFi_Connectivity_and_Prioritizing_Business_Apps.pdf&lt;/P&gt;
&lt;P&gt;The paper states:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Legacy devices that do not recognize the FT AKM’s beacons and probe responses will not be able to join the WLAN&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As seen in my lab above this is not (always) the case.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think adaptive FT it's pretty sexy, because it eventually interferes less with legacy clients. However, I didn't encounter problems with enabled FT for now.&lt;/P&gt;
&lt;P&gt;So what's the real benefit? Furthermore, is adaptive FT compatible with other clients than iOS 10? Is an Adroid phone or Win10 Client clever enough to respond with FT, if the SSID is configured adaptive (so without FT AKM).&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 14:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941445#M17476</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2016-12-16T14:31:50Z</dc:date>
    </item>
    <item>
      <title>Edit: Saw this post as well</title>
      <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941446#M17477</link>
      <description>&lt;P&gt;Edit: Saw this post as well&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/12314591/8021r-and-fast-roaming&lt;/P&gt;
&lt;P&gt;along with the statement:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Still few supplicants &amp;nbsp;(Mac OSX, Netgear,ect)&amp;nbsp;does not like mixed mode WLAN, so they may have trouble associate if you enable FT&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So here's my personal summary:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Adaptive FT --&amp;gt; Standard WPA2 AKMs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Pro: Less disrupive for "picky" old/bad/etc. clients&lt;/P&gt;
&lt;P&gt;Con: Some 11r capable client join SSID with non-11r AKM (might use classic OKC/PKC)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is my "Con" statement right? Or am I totally wrong by assuming that not all 11r clients honor the adaptive FT capability information?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 14:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941446#M17477</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2016-12-16T14:31:51Z</dc:date>
    </item>
    <item>
      <title>I think we just have to wait</title>
      <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941447#M17478</link>
      <description>&lt;P&gt;I think we just have to wait and see. If this is sent in the beacon and the device doesn't understand it, it can or may cause issue. Until people start implementing this and seeing if adaptive works 100%, I would still believe that some devices will still not connect. I should try it wil a gen 1 iPad and some old devices I have laying around.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Scott&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*** Please rate helpful posts ***&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 14:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941447#M17478</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2016-12-16T14:31:52Z</dc:date>
    </item>
    <item>
      <title>Just a follow up on that. I</title>
      <link>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941448#M17479</link>
      <description>&lt;P&gt;Just a follow up on that. I haven't tested the statements from above yet.&lt;/P&gt;
&lt;P&gt;But the assumtion, that some 11r capable client join SSID with non-11r when adaptive FT is used is correct, regarding this document:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/technotes/8-3/Enterprise_Best_Practices_for_Apple_Devices_on_Cisco_Wireless_LAN.pdf&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;[...] the adaptive 11r feature will only be applied to iOS devices running iOS 10 or later. All other devices will be able to associate using standard WPA2.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 25 Jul 2017 06:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/queries-regarding-fast-secure-roaming/m-p/2941448#M17479</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2017-07-25T06:34:16Z</dc:date>
    </item>
  </channel>
</rss>

