03-18-2024 09:18 AM
So, this is more a question of what people are using or seeing. We will be replacing all our facilities this year and I plan to go Wi-Fi6E. I have tested having the SSID with mixed, but I have also heard separate doe to if a client shifts frequencies they will go through reauthentication.
So, what have any of you experienced with this. Is it better to split off 6GHz to say Employee and Employee_6G? Or, is the mixed under the 1 SSID fine. I'm just looking at the questions from users and the headaches of splitting.
03-18-2024 10:31 AM
- Because of the different security parameters it is better to split off 6GHz between Employee and Employee_6
M.
03-18-2024 12:07 PM
Hi
As Wifi 6E requires WPA3 security (Protected Management Frame (PMF)) then part of clients may not support it.
With a single SSID in transition mode, you can expect that it will deal with both WPA2 and WPA3 clients but I'm not sure that you can really predict behavior of each type of devices except if you have a limited set of. As you mention, if it happens, switching between WPA2 and WPA3 might introduce a poor experience.
Even Cisco NOC guys prefer to separate WPA2 and WPA3 at Cisco Live
https://blogs.cisco.com/developer/wireless-and-the-ciscolive-network-operations-center
Regards
03-18-2024 06:49 PM - edited 03-18-2024 06:49 PM
Subscribing. I don't have experience with this, just thoughts - maybe someone can correct me if I'm wrong. I can't think of why combining would be a problem if running strictly WPA3 encryption since WPA3 is WPA3 whether it's on 2.4, 5, or 6 GHz... and running 2.4 and 5 GHz with WPA2 is fine... right?
In my institution (large university) with BYOD and everything from 2700s to 9166s in the fleet, splitting would be troublesome in the following scenario: User connects to Employee_6. They move to another building with pre-6 GHz APs and must then connect to Employee. Then they return to the first building and their device has to choose on its own whether to connect to Employee or Employee_6. Regardless of what it chooses, at some point, due to a momentary drop in RSSI or other factor, it may choose to switch SSIDs and re-authenticate at a disruptive time.
Even if they don't move between buildings with or without 6 GHz, if they have trouble with one SSID for whatever reason, they'll try the other SSID, and again, the device is liable to switch SSIDs. This can be helped with communication (or group policy/device management/etc.) but in a university setting, we just can't get everyone to receive/read/obey the message. So, my thought is to combine 5/6 with WPA3 on one SSID and keep eduroam 2.4/5 with WPA2 - depending how this conversation goes!
03-19-2024 12:37 AM
Hi
Everything exposed here clearly :
https://blogs.cisco.com/networking/wlan-ssid-security-migration-into-6ghz-networks
Best option proposed : "Same SSID, two WLAN profiles, no transition". Just add 6Ghz support with WPA3. No change on 2.4/5Ghz security profile.
And the most important information is :
"WPA3 describes transition mode as a kind of hybrid WPA2/WPA3 scenario, with PMF set to optional, and the group key using legacy crypto, but this is not allowed in 6GHz, so we can’t just flip the existing WLAN from WPA2 to transition mode and get it done…it simply can’t be supported in the new band."
Option 4 sounds good to me as it gives the availability of 6Ghz enhancement without hitting your existing deployment.
03-19-2024 07:09 AM
Thanks for the info, Off the blog I think Option2 may be best. 4 seems plausible, but would a device show 2 different SSIDs with the same name causing confusion or not.
We have a few SSIDs, but Employee and Guest are about the only 2 I would need to enable 6GHz as our other SSIDs are more legacy devices.
03-19-2024 07:52 AM
Based on the blog options, I would choose option 4.
So leaving security parameters as it on existing SSID as they are with on 2.4/5Ghz bands.
- Employee using WPA2 Enterprise (I guess)
- Guest with L2 open auth / L3 WebAuth (or I don't know, maybe WPA2 Private PSK on top of WebAuth)
Then add 6GHz band with:
- Employee using WPA3 Enterprise (no choice)
- Guest using enhanced open (OWE)
As it, new devices supporting 6Ghz should work and existing devices won't be impacted on band 2.4/5Ghz. You avoid to deal to transition to WPA3 and OWE on exiting networks but you do add 6Ghz support.
03-19-2024 09:18 AM
I guess my only question on option 4 is will a device that supports 6, see 2 Employees listed in the scan and how do we know what to pick, or will it show just the 1. I'll have to test it, but that is my concern is the device showing the 2.4/5 and 6 as 2 separate listed SSIDs.
03-19-2024 10:26 AM
To my understanding, it is the same problem as choosing between 2.4 or 5Ghz band for the same SSID. It is just extended to a new band 6Ghz.
So you may implement same steering technique to make band selection more efficient :
If it is choosing between two different SSID then it is just a local policy on the client. It is no more an infrastructure choice (but I may be wrong). I suppose that OS or wireless client parameters may offer option to priorize a sequence of SSID or make 6hgz band preempt over 2.4/5Ghz. I don't know.
Regards
03-19-2024 10:42 AM - edited 03-19-2024 11:21 AM
Clients may rely on the probes from 2.4/5Ghz to discover 6Ghz band SSID. So I guess, client would prefer 6Ghz if discovered.
This is an interesting point from this presentation "Architecting Next Generation Wireless Network with Catalyst Wi-Fi 6E Access Points" from Cisco Live (BRKEWN-2024) :
https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2023/pdf/BRKEWN-2024.pdf
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide