11-13-2023 12:42 PM
Hello All,
We recently upgraded our C9800 from 17.6.x to 17.9.4a. Following the upgrade, three of our networks would not turn back up without some security modifications, which was straight forward for two of them. However, for our guest wireless network, this has been more puzzling.
Previously, we were able to use WPA2 with our guest WLAN -- Clients could connect without supplying credentials, and then would get redirected to a web auth screen, where they would enter supplied credentials to get on the network. Web auth is using local authentication. Now, we can't enable WPA2 on this network without selecting an option for AKM:
Do we now have to also configure a PSK or additional credentials for guests to use, before they hit the web auth?
Thanks
11-13-2023 02:46 PM
WebAuth generally has Layer 2 authentication set to none. And then configure layer 3 authentication
11-13-2023 02:52 PM
Starting from 17.9.X, WPA3 is supported. Look at the Security tab in 17.9.X and it will show WPA2 + WPA3. Because the settings are incompatible, the SSID has been disabled.
Change it to WPA + WPA2 and then enable the SSID.
11-14-2023 05:48 AM - edited 11-14-2023 05:53 AM
Thank you for the reply -
This guest SSID is set for WPA + WPA2, but, the WPA2 Policy cannot be enabled without also selecting one of the AKM options. Here is a larger screenshot of what I have:
For now I only have the WPA Policy option enabled, as having only it selected does not require AKM.
I will also run this by TAC and will follow up with what I find out on it.
Thanks
11-19-2023 04:52 AM
Why do you have WPA policy enabled? Do you have any clients which can't support WPA2?
And it's logical that you need a key source for WPA2. If you don't want it encrypted then use Open (None) - like @JPavonM says - that is normal for a web auth SSID.
11-14-2023 07:04 AM - edited 11-14-2023 07:05 AM
For any 802.11i WPA flavour it is required to set a key manager (https://www.cwnp.com/uploads/802-11i_key_management.pdf).
The basic one for a Guest SSID is to select PSK, and then you can use WebAuth or CWA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide