cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
962
Views
3
Helpful
5
Replies

C9800: WPA2 for guest WLAN after upgrade to 17.9.4a

MauryJ
Level 1
Level 1

Hello All,

We recently upgraded our C9800 from 17.6.x to 17.9.4a.   Following the upgrade, three of our networks would not turn back up without some security modifications, which was straight forward for two of them.   However, for our guest wireless network, this has been more puzzling.

Previously, we were able to use WPA2 with our guest WLAN -- Clients could connect without supplying credentials, and then would get redirected to a web auth screen, where they would enter supplied credentials to get on the network.   Web auth is using local authentication.    Now, we can't enable WPA2 on this network without selecting an option for AKM:

MauryJ_0-1699907731973.png

Do we now have to also configure a PSK or additional credentials for guests to use, before they hit the web auth?

Thanks

 

5 Replies 5

Haydn Andrews
VIP Alumni
VIP Alumni

WebAuth generally has Layer 2 authentication set to none. And then configure layer 3 authentication

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***

Leo Laohoo
Hall of Fame
Hall of Fame

Starting from 17.9.X, WPA3 is supported.  Look at the Security tab in 17.9.X and it will show WPA2 + WPA3.  Because the settings are incompatible, the SSID has been disabled. 

Change it to WPA + WPA2 and then enable the SSID.

Thank you for the reply -

This guest SSID is set for WPA + WPA2, but, the WPA2 Policy cannot be enabled without also selecting one of the AKM options.   Here is a larger screenshot of what I have:

MauryJ_1-1699969832466.png

For now I only have the WPA Policy option enabled, as having only it selected does not require AKM.

I will also run this by TAC and will follow up with what I find out on it.

Thanks

 

Why do you have WPA policy enabled?  Do you have any clients which can't support WPA2?
And it's logical that you need a key source for WPA2.  If you don't want it encrypted then use Open (None) - like @JPavonM says - that is normal for a web auth SSID.

JPavonM
VIP
VIP

For any 802.11i WPA flavour it is required to set a key manager (https://www.cwnp.com/uploads/802-11i_key_management.pdf).

The basic one for a Guest SSID is to select PSK, and then you can use WebAuth or CWA.

Review Cisco Networking for a $25 gift card