<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mesh Security &amp; Association Frequency in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485368#M296439</link>
    <description>&lt;P&gt;Exactly, that is what i could conclude from the packet captures.&lt;/P&gt;&lt;P&gt;There is no authentication at all between the APs. Our company wants to make sure that all wireless authentications are atleast EAP-TLS. And i have been tasked to find this for the authentication between Mesh repeaters &amp;amp; gateways.&lt;/P&gt;&lt;P&gt;How does this work if there is no authentication!&lt;/P&gt;</description>
    <pubDate>Wed, 16 Aug 2023 02:49:04 GMT</pubDate>
    <dc:creator>flyingframes</dc:creator>
    <dc:date>2023-08-16T02:49:04Z</dc:date>
    <item>
      <title>Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485361#M296432</link>
      <description>&lt;P&gt;What security &amp;amp; frequency does the mesh repeater choose to talk to the mesh gateway?&lt;/P&gt;&lt;P&gt;e.g. is it WPA2 PSK &amp;amp; 5GHz?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 16:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485361#M296432</guid>
      <dc:creator>flyingframes</dc:creator>
      <dc:date>2023-08-15T16:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485362#M296433</link>
      <description>&lt;H3 id="toc-hId-1448194753"&gt;Mesh Probes&lt;/H3&gt;&lt;P&gt;Each Meraki AP sends out link probe packets (known as mesh probes) at different bit rates and varying sizes. Because these packets are sent as broadcast frames, no ACK frames are needed from receiving stations. Four different types of probes at different data rates are sent in a batch of 15 seconds on both (2.4 /5 GHz) bands. All APs listen to the mesh probes and depending on the number of mesh probes correctly received, come up with a link quality metric as shown in dashboard.&lt;/P&gt;&lt;H3 id="toc-hId--1103962208"&gt;Mesh Encryption Improvements&lt;/H3&gt;&lt;P&gt;MR 29.1 firmware supports robust WPA3 equivalent encryption with SHA256 key for data packets between the mesh peers in 2.4/5/6GHz bands, while previous MR firmware versions (MR 27.X MR 28.X) support AES-CCM (SHA1) for mesh encryption. &lt;/P&gt;&lt;P&gt;Full doc.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Wi-Fi_Basics_and_Best_Practices/Wireless_Mesh_Networking" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/MR/Wi-Fi_Basics_and_Best_Practices/Wireless_Mesh_Networking&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 16:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485362#M296433</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-08-15T16:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485363#M296434</link>
      <description>&lt;P&gt;Thanks for the kind information.&lt;/P&gt;&lt;P&gt;So the probes are sent on both 2.4 &amp;amp; 5GHz. Does that mean the repeater can send association on any of the two frequencies?&lt;/P&gt;&lt;P&gt;Also, this does not explain the EAP method used. is it WPA2-PSK or based on certificates?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 17:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485363#M296434</guid>
      <dc:creator>flyingframes</dc:creator>
      <dc:date>2023-08-15T17:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485364#M296435</link>
      <description>&lt;P&gt;Mesh is secured via AES.  This has nothing to do with you client serving SSIDs. The mesh entropy depends on model of AP and FW revision, see within the same document further down:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TBHPTL_0-1692134207368.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271944i373AEE303175F676/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 21:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485364#M296435</guid>
      <dc:creator>DainBrammage</dc:creator>
      <dc:date>2023-08-15T21:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485365#M296436</link>
      <description>&lt;P&gt;Great. that helps me understand that the mesh link can happen on any 2.4GHz or 5GHz. But what is the authentication in play here? EAP-TLS, PEAP-MSCHAPv2 or PSK?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 00:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485365#M296436</guid>
      <dc:creator>flyingframes</dc:creator>
      <dc:date>2023-08-16T00:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485366#M296437</link>
      <description>&lt;P&gt;What's the matter the authentication? Can you explain better?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 00:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485366#M296437</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-08-16T00:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485367#M296438</link>
      <description>&lt;P&gt;There is no authentication between APs if that's what you want to know.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 01:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485367#M296438</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-08-16T01:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485368#M296439</link>
      <description>&lt;P&gt;Exactly, that is what i could conclude from the packet captures.&lt;/P&gt;&lt;P&gt;There is no authentication at all between the APs. Our company wants to make sure that all wireless authentications are atleast EAP-TLS. And i have been tasked to find this for the authentication between Mesh repeaters &amp;amp; gateways.&lt;/P&gt;&lt;P&gt;How does this work if there is no authentication!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 02:49:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485368#M296439</guid>
      <dc:creator>flyingframes</dc:creator>
      <dc:date>2023-08-16T02:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485369#M296440</link>
      <description>&lt;P&gt;If your are using EAP TLS for your users that traffic is encapsulated even across the mesh link and yes the MESH link between Merkai devices is proprietary and encrypted.  &lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;The AP's mesh link and &lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;encryption&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt; has nothing to do with end user authentication and encryption.&lt;/STRONG&gt; &lt;/EM&gt;&lt;/U&gt;Read the document again and then set up your cipher and encryption on the SSID.  Ill bet you will see it is encrypted &lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 04:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485369#M296440</guid>
      <dc:creator>DainBrammage</dc:creator>
      <dc:date>2023-08-16T04:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Mesh Security &amp; Association Frequency</title>
      <link>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485370#M296441</link>
      <description>&lt;P&gt;Thanks for the kind help everyone. This has been amazing.&lt;/P&gt;&lt;P&gt;I am assured about the encryption. However the concern is about authenticating the Mesh repeater to the Mesh gateway.&lt;/P&gt;&lt;P&gt;Is there a possibility to upload certificates on the repeater, so that the authentication can be EAP TLS? &lt;/P&gt;&lt;P&gt;When looking into the packets, there are no association or auth frames.&lt;/P&gt;&lt;P&gt;First there are some beacons from both ends&lt;/P&gt;&lt;P&gt;Then some frames of "Meraki Discovery Protocol" 300 bytes in size from the repeater&lt;/P&gt;&lt;P&gt;Finally some unrecognizable frames packets of 1578 bytes sent to broadcast address of ff:ff:ff:ff:ff:ff by both mesh repeater &amp;amp; gateway.&lt;/P&gt;&lt;P&gt;The big size of 1578 bytes makes me think its a certificate.&lt;BR /&gt;&lt;BR /&gt;Is Meraki already using certificates to authenticate the mesh APs in the background?&lt;/P&gt;&lt;P&gt;If yes, we can get pass by the requirement of having them authenticate via EAP-TLS.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 04:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mesh-security-association-frequency/m-p/5485370#M296441</guid>
      <dc:creator>flyingframes</dc:creator>
      <dc:date>2023-08-16T04:32:32Z</dc:date>
    </item>
  </channel>
</rss>

