<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974978#M264076</link>
    <description>&lt;P&gt;WPA3 can backward compatibilty with WPA2&lt;/P&gt;
&lt;P&gt;But&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9166-series-access-points/220526-configure-and-verify-wi-fi-6e-band-opera.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9166-series-access-points/220526-configure-and-verify-wi-fi-6e-band-opera.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Mention below&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Wi-Fi 6E uplevels security with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Wi-Fi Protected Access&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;3 (WPA3) and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Opportunistic&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Wireless&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Encryption (&lt;/SPAN&gt;&lt;SPAN&gt;OWE) and there is &lt;STRONG&gt;no&lt;/STRONG&gt; &lt;STRONG&gt;backward&lt;/STRONG&gt; &lt;STRONG&gt;compatibility&lt;/STRONG&gt; with Open and &lt;STRONG&gt;WPA2&lt;/STRONG&gt; security.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So you have only option try two SSID (two wlan wpa2 and other wpa3 6ghz) with one vlan.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Dec 2023 04:23:28 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-12-10T04:23:28Z</dc:date>
    <item>
      <title>Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Ghz?</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4973475#M263981</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We're starting to deploy 9100 series APs. Of course 6GHz requires WPA2 to be disabled. I can't do that yet as we have a number of older laptops with Intel AC8265 adapters that don't support WPA3.&lt;/P&gt;&lt;P&gt;An idea that occurred to me was to leave the existing corporate SSID as is and create another WLAN with the same SSID having WPA3 and 6GHz enabled, but disabled on 2.4 &amp;amp; 5Ghz.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone done this, or is there an obvious reason why it won't work/shouldn't be tried?&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 15:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4973475#M263981</guid>
      <dc:creator>tomab</dc:creator>
      <dc:date>2023-12-07T15:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4973510#M263982</link>
      <description>&lt;P&gt;Yes that is something you can do, but whenever a device that support the 3 bands would connect to either AP and move to another area, it will decide which band to connect to, so expect uncontrolled disconnections.&lt;/P&gt;
&lt;P&gt;Try to configure WPA3 AES-CCMP128 with both SAH1 and SHA256 and PMF optional, that should be allowed by AC8265 adapters as far as I remember. BUT don't setup WPA3 on Windows side, but WPA2-Enterprise. Basically WPA2 with those options and WPA3 are the same suites, but in the later case with all of them CCMP128, SHA256 and PMF mandatory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 15:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4973510#M263982</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2023-12-07T15:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974355#M264012</link>
      <description>&lt;P&gt;And remember the Intel drivers &lt;STRONG&gt;must&lt;/STRONG&gt; be up to date.&lt;/P&gt;
&lt;P&gt;You may also want to have a read through&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 13:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974355#M264012</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-12-08T13:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974964#M264071</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;An idea that occurred to me was to leave the existing corporate SSID as is and create another WLAN with the same SSID having WPA3 and 6GHz enabled, but disabled on 2.4 &amp;amp; 5Ghz&lt;/STRONG&gt;&lt;/EM&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Prior to 17.12.x version, You can use the same SSID name, but SSID profile name should be unique. In that way still it is two different SSID profiles that use same "SSID name".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Starting from IOS-XE 17.12.x onward Cisco is supporting it using single profile and single SSID. Refer below WPA3 deployment guide&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html" target="_self"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;"Starting 17.12.1, this can be used with 1 SSID and 1 Profile and support 6GHz band"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"To support these deployments, the recommendation in pre-17.12.1 SW versions were to use WPA2+WPA3 transition mode with same WLAN with different profiles to support both legacy and latest 6GHz clients. The challenge with this design is roaming. The roaming between bands in this configuration is not supported and it is full roam always which is not preferred.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Starting from 17.12.1, we are supporting transition mode with pure WPA3 for 6GHz band, which allows users to enable WPA2+WPA3 in the same WLAN with 6GHz. This mode eliminates the need to create two different profiles to accommodate legacy and latest 6GHz devices. In this mode, WPA2+WPA3 transition mode can be used in 2.4GHz/5GHz and only WPA3 relevant configs will be pushed on the 6GHz band when wlan has both WPA2 and WPA3 configs&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Specific configuration you can find within the same document&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html#WPA2WPA3Enterprisetransitionmodewith6GHzGUIConfiguration" target="_self"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html#WPA2WPA3Enterprisetransitionmodewith6GHzGUIConfiguration&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;BR /&gt;Rasika&lt;BR /&gt;*** Pls rate all useful responses ***&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2023 23:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974964#M264071</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2023-12-09T23:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974973#M264075</link>
      <description>&lt;P&gt;Not a good idea to use the same name, create a different SSID. May be user number "6" on new SSID, so people know if they have compatible devices then connect to the one ending with "6", at-least until all your devices are 6Ghz compatible. One of my customer tried that it was not a pleasant experience for their help desk.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2023 03:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974973#M264075</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-12-10T03:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974978#M264076</link>
      <description>&lt;P&gt;WPA3 can backward compatibilty with WPA2&lt;/P&gt;
&lt;P&gt;But&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9166-series-access-points/220526-configure-and-verify-wi-fi-6e-band-opera.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9166-series-access-points/220526-configure-and-verify-wi-fi-6e-band-opera.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Mention below&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Wi-Fi 6E uplevels security with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Wi-Fi Protected Access&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;3 (WPA3) and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Opportunistic&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Wireless&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Encryption (&lt;/SPAN&gt;&lt;SPAN&gt;OWE) and there is &lt;STRONG&gt;no&lt;/STRONG&gt; &lt;STRONG&gt;backward&lt;/STRONG&gt; &lt;STRONG&gt;compatibility&lt;/STRONG&gt; with Open and &lt;STRONG&gt;WPA2&lt;/STRONG&gt; security.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So you have only option try two SSID (two wlan wpa2 and other wpa3 6ghz) with one vlan.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2023 04:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4974978#M264076</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-10T04:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4975178#M264093</link>
      <description>&lt;P&gt;I think there are multiple ways to achieve this, but it comes down to what works well for you. &amp;nbsp;What I have done, so I can have telemetry on migration to WPA3, is to create a new SSID, since its 6GHz only and keep the existing as is. &amp;nbsp;GPO would be update to add the WPA3/6GHz as the primary. &amp;nbsp;Your AD has to be up to date to have the WPA3 option. &amp;nbsp;Depends on how your end devices are setup in AD/Intune as an example, you might be able to have separate GPO's for newer devices versus existing which helps as you really don't want to push both SSID's as that can cause issues also, but you would need to test that out.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2023 21:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4975178#M264093</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-12-10T21:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4975310#M264096</link>
      <description>&lt;P&gt;What I'm doing to move forward to WPA3-only is to create a WLAN profile using WPA3-Transition mode and only publishing it on 5-GHz (I'm not a friend of using 2.4-GHz band for corporate devices as users complain about performance a lot).&lt;/P&gt;
&lt;P&gt;I will have this setup for the next 10 months and will monitor conencted clients looking for non-sha256 clients connected (those that do not support WPA3 AKM) with this command:&lt;/P&gt;
&lt;PRE&gt;show wireless client summary detail | exc SHA256&lt;/PRE&gt;
&lt;P&gt;In parallel, using a Python script I'm checking all connected clients security features in use by them to validate they are connecting using SHA256 and PMF.&lt;/P&gt;
&lt;P&gt;What we are looking at are for those laptops that do not support it to replace them (because they have a legacy wireless adapter not supporting it), or fix them (because and outdated driver).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 07:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4975310#M264096</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2023-12-11T07:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4975368#M264101</link>
      <description>&lt;P&gt;Thanks everyone for the useful input.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324872"&gt;@Rasika Nayanajith&lt;/a&gt;&amp;nbsp;suggestion of using 17.12.x (which I see supports our 2700 series APs) looks like the best option.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 09:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/4975368#M264101</guid>
      <dc:creator>tomab</dc:creator>
      <dc:date>2023-12-11T09:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate WLANs with same SSID, one for WPA3/6Ghz one for WPA2 5Gh</title>
      <link>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/5000072#M265434</link>
      <description>&lt;P&gt;Watch out for &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCwh49406" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCwh49406&lt;/A&gt; though it's still affecting 17.12.2. I too want the feature to have WPA2/3 transition mode on a single WLAN profile but this bug is worse than it seems because I got my syslog server spammed with 700mbps of AP junk and you'd think that you could unconfigure a syslog target for the APs but the default on the 9800 is to use the broadcast address for syslog (which is a bad default, it should just disable syslog on APs) so then you're DDoSing your site with broadcast syslog traffic. You'd also think you could change the syslog filter level but this bypasses the syslog filter. Disabling cleanair on 2.4GHz and rebooting affected APs works around it (in my case it was just the 9130s as the bug indicates) , but then I have no cleanair on 2.4GHz which is annoying.&lt;/P&gt;&lt;P&gt;Supposedly an APSP being released soon for 17.12.2 but I've yet to see it and maybe it will just be fixed in 17.12.3 instead. Anyway wow, this is a very annoying bug.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 17:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/duplicate-wlans-with-same-ssid-one-for-wpa3-6ghz-one-for-wpa2/m-p/5000072#M265434</guid>
      <dc:creator>jasonm002</dc:creator>
      <dc:date>2024-01-18T17:44:42Z</dc:date>
    </item>
  </channel>
</rss>

