<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CoA and Fast Roaming in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481601#M295297</link>
    <description>&lt;P&gt;I don't know the answer.&lt;/P&gt;&lt;P&gt;I can tell you 802.11r has fallen out of favour.  I used to use it all the time 5 years ago.  I don't use it at all now.&lt;/P&gt;&lt;P&gt;There was a bunch of non-fixable security issues with the protocol.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Support/802.11r_Vulnerability_(CVE%3A_2017-13082)_FAQ" target="_self" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/General_Administration/Support/802.11r_Vulnerability_(CVE%3A_2017-13082)_FAQ&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 19:57:10 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2022-11-22T19:57:10Z</dc:date>
    <item>
      <title>CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481599#M295295</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I was reading the documentation about CoA  ( &lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points#Enable_Cisco_ISE" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points#Enable_Cisco_ISE&lt;/A&gt; ) &lt;/P&gt;&lt;H3&gt;Roaming with CoA&lt;/H3&gt;&lt;P&gt;There are a number of advantages to CoA and it enables many new use cases. &lt;STRONG&gt;SSIDs that require fast roaming should not use CoA&lt;/STRONG&gt;. Fast roaming mechanisms like &lt;STRONG&gt;PMKsa, OKC, and 802.11r will be disabled on the SSID that is configured for CoA&lt;/STRONG&gt;. &lt;STRONG&gt;Clients are forced to complete EAP on every association which ensures that the RADIUS server will send the CoA to the correct Access Point.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Let's say I have an SSID with WPA2-Enterprise and a Radius server configured. I also have 802.11r enabled AND CoA configured. Does that mean that 802.11r won't work at all since &lt;STRONG&gt;Clients are forced to complete EAP on every association&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Will it cause conflict ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 19:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481599#M295295</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2022-11-22T19:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481600#M295296</link>
      <description>&lt;P&gt;I understood that when you enable CoA the 802.11r will be disabled.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 19:49:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481600#M295296</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2022-11-22T19:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481601#M295297</link>
      <description>&lt;P&gt;I don't know the answer.&lt;/P&gt;&lt;P&gt;I can tell you 802.11r has fallen out of favour.  I used to use it all the time 5 years ago.  I don't use it at all now.&lt;/P&gt;&lt;P&gt;There was a bunch of non-fixable security issues with the protocol.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Support/802.11r_Vulnerability_(CVE%3A_2017-13082)_FAQ" target="_self" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/General_Administration/Support/802.11r_Vulnerability_(CVE%3A_2017-13082)_FAQ&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 19:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481601#M295297</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2022-11-22T19:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481602#M295298</link>
      <description>&lt;P&gt;I would retract that statement &lt;SPAN class="lia-unicode-emoji" title=":winking_face:"&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;802.11r is only out of favor in WPA2-Personal SSID's.&lt;BR /&gt;For 802.1X WPA2-Enterprise it is standard to use 802.11r.&lt;BR /&gt;&lt;BR /&gt;I find this behavior &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/13291"&gt;@Raphletourn&lt;/A&gt; describes disturbing.  In regular Cisco AP's you have flexconnect and there these kinds of details are shared between all AP's in the same flex group(AireOS)/same site tag(IOS-XE) to have 802.11r work perfectly with CoA.  I would only ask if Meraki would do the same for AP's inside the same dashboard network...&lt;/P&gt;&lt;P&gt;So basically as it stands now: the moment you put that CoA button to enabled your SSID will not use 802.11r...&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 21:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481602#M295298</guid>
      <dc:creator>joey.debra</dc:creator>
      <dc:date>2022-11-22T21:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481603#M295299</link>
      <description>&lt;P&gt;Perhaps we should all add a wish that FT should be implemented together with CoA.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 09:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481603#M295299</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-11-23T09:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481604#M295300</link>
      <description>&lt;P&gt;After a year , they re-added the warning : &lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RaphaelL_0-1698252841344.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/270886iABD158888B236F27/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I will be testing if that's true... &lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 16:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481604#M295300</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2023-10-25T16:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481605#M295301</link>
      <description>&lt;P&gt;EDIT :&lt;STRIKE&gt;Pretty sure it now disables 802.11r... &lt;/STRIKE&gt;&lt;/P&gt;&lt;P&gt;According to : &lt;A href="https://mac-wifi.com/how-to-verify-whether-802-11k-and-11r-are-enabled-via-a-capture/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://mac-wifi.com/how-to-verify-whether-802-11k-and-11r-are-enabled-via-a-capture/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If the section Mobility Domain is present , the SSID is supporting 802.11r. Which it goes against the warning... will re-open my case.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RaphaelL_0-1698255233430.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/270887iBA0FD0916776563A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 17:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481605#M295301</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2023-10-25T17:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481606#M295302</link>
      <description>&lt;P&gt;With MR32.1.x and ISE 3.3.0.430-Patch 5 there is support for CoA + 802.11r fast roaming simultaneously.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 15:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481606#M295302</guid>
      <dc:creator>ppurroy</dc:creator>
      <dc:date>2025-07-07T15:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481607#M295303</link>
      <description>&lt;P&gt;Do you &lt;EM&gt;need  &lt;/EM&gt;to have ISE &lt;SPAN&gt;3.3.0.430-Patch 5 or is it just prefered ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 15:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481607#M295303</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2025-07-07T15:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481608#M295304</link>
      <description>&lt;P&gt;Can you elaborate on how it is handled internally? Is there an AP to AP communication for the PMK-R1, or distributed through the cloud ...&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481608#M295304</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2025-07-07T17:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: CoA and Fast Roaming</title>
      <link>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481609#M295305</link>
      <description>&lt;P&gt;You need to have ISE3.3 Patch5 or later release. If you look at the Release Notes, the corresponding bug ID addressing the issue is CSCwk30242, which is available starting from Patch5:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/release_notes/b_ise_33_RN.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/release_notes/b_ise_33_RN.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The fix is also available for ISE 3.4 starting from Patch2:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/release_notes/cisco-identity-services-engine-release-notes-34.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/release_notes/cisco-identity-services-engine-release-notes-34.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2025 14:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-and-fast-roaming/m-p/5481609#M295305</guid>
      <dc:creator>lcaldaro</dc:creator>
      <dc:date>2025-08-12T14:04:26Z</dc:date>
    </item>
  </channel>
</rss>

